Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exe

Overview

General Information

Sample name:b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exe
Analysis ID:1581378
MD5:12ac061f02656d9e3d3cfbdd429a6bcf
SHA1:5d6bb219d35a0dd57ddcbdb5950e9307593279e0
SHA256:b1593574e46fb1f30b1da4fa594f43bb52b051a616db390abf23ef45508f8b13
Tags:exeXenoRATuser-abuse_ch
Infos:

Detection

XenoRAT
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Found malware configuration
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Yara detected XenoRAT
.NET source code contains potential unpacker
AI detected suspicious sample
C2 URLs / IPs found in malware configuration
Connects to many ports of the same IP (likely port scanning)
Found potential dummy code loops (likely to delay analysis)
Installs a global keyboard hook
Machine Learning detection for sample
AV process strings found (often used to terminate AV products)
Abnormal high CPU Usage
Allocates memory with a write watch (potentially for evading sandboxes)
Binary contains a suspicious time stamp
Checks if Antivirus/Antispyware/Firewall program is installed (via WMI)
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)
Contains long sleeps (>= 3 min)
Detected TCP or UDP traffic on non-standard ports
Detected potential crypto function
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Internet Provider seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
Potential time zone aware malware
Program does not show much activity (idle)
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info
Uses code obfuscation techniques (call, push, ret)
Yara signature match

Classification

  • System is w10x64
  • cleanup
{"C2 url": "194.59.30.69", "Mutex Name": "Xeno_rat_nd8912d", "Install Folder": "nothingset"}
SourceRuleDescriptionAuthorStrings
b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeJoeSecurity_XenoRATYara detected XenoRATJoe Security
    b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exerat_win_xeno_ratXeno RAT is an open-source RAT, used by Kimsuky in January 2024Sekoia.io
    • 0xb15c:$: Xeno-manager
    • 0x250:$: moom825
    SourceRuleDescriptionAuthorStrings
    00000000.00000000.1643596965.00000000007B2000.00000002.00000001.01000000.00000003.sdmpJoeSecurity_XenoRATYara detected XenoRATJoe Security
      Process Memory Space: b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exe PID: 7308JoeSecurity_XenoRATYara detected XenoRATJoe Security
        SourceRuleDescriptionAuthorStrings
        0.0.b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exe.7b0000.0.unpackJoeSecurity_XenoRATYara detected XenoRATJoe Security
          0.0.b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exe.7b0000.0.unpackrat_win_xeno_ratXeno RAT is an open-source RAT, used by Kimsuky in January 2024Sekoia.io
          • 0xb15c:$: Xeno-manager
          • 0x250:$: moom825
          No Sigma rule has matched
          TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
          2024-12-27T14:37:03.587659+010020584191A Network Trojan was detected194.59.30.6916589192.168.2.449730TCP
          2024-12-27T14:37:06.843864+010020584191A Network Trojan was detected194.59.30.6916589192.168.2.449731TCP
          2024-12-27T14:37:12.268793+010020584191A Network Trojan was detected194.59.30.6916589192.168.2.449732TCP
          2024-12-27T14:37:17.260923+010020584191A Network Trojan was detected194.59.30.6916589192.168.2.449734TCP
          TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
          2024-12-27T14:37:19.853964+010020501101Malware Command and Control Activity Detected194.59.30.6916589192.168.2.449734TCP
          2024-12-27T14:40:04.240627+010020501101Malware Command and Control Activity Detected194.59.30.6916589192.168.2.449731TCP
          2024-12-27T14:40:34.376153+010020501101Malware Command and Control Activity Detected194.59.30.6916589192.168.2.449730TCP
          TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
          2024-12-27T14:37:19.937706+010020501111Malware Command and Control Activity Detected192.168.2.449734194.59.30.6916589TCP
          2024-12-27T14:37:59.991704+010020501111Malware Command and Control Activity Detected192.168.2.449731194.59.30.6916589TCP
          2024-12-27T14:38:24.459236+010020501111Malware Command and Control Activity Detected192.168.2.449731194.59.30.6916589TCP
          2024-12-27T14:39:12.428763+010020501111Malware Command and Control Activity Detected192.168.2.449731194.59.30.6916589TCP
          2024-12-27T14:39:42.912839+010020501111Malware Command and Control Activity Detected192.168.2.449731194.59.30.6916589TCP

          Click to jump to signature section

          Show All Signature Results

          AV Detection

          barindex
          Source: b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeMalware Configuration Extractor: XenoRAT {"C2 url": "194.59.30.69", "Mutex Name": "Xeno_rat_nd8912d", "Install Folder": "nothingset"}
          Source: b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeVirustotal: Detection: 79%Perma Link
          Source: b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeReversingLabs: Detection: 76%
          Source: Submited SampleIntegrated Neural Analysis Model: Matched 100.0% probability
          Source: b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeJoe Sandbox ML: detected
          Source: b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
          Source: Binary string: C:\Users\moom825\Desktop\xeno-rat\xeno-rat\Plugins\KeyLoggerOffline\obj\Release\KeyLoggerOffline.pdbYpsp ep_CorDllMainmscoree.dll source: b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exe, 00000000.00000002.4107606826.0000000002B62000.00000004.00000800.00020000.00000000.sdmp, b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exe, 00000000.00000002.4108815174.00000000055D0000.00000004.08000000.00040000.00000000.sdmp
          Source: Binary string: .pdbYp source: b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exe, 00000000.00000002.4107606826.0000000002B62000.00000004.00000800.00020000.00000000.sdmp, b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exe, 00000000.00000002.4107606826.0000000002B53000.00000004.00000800.00020000.00000000.sdmp
          Source: Binary string: C:\Users\moom825\Desktop\xeno-rat\xeno-rat\Plugins\KeyLoggerOffline\obj\Release\KeyLoggerOffline.pdb source: b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exe, 00000000.00000002.4107606826.0000000002B62000.00000004.00000800.00020000.00000000.sdmp, b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exe, 00000000.00000002.4108815174.00000000055D0000.00000004.08000000.00040000.00000000.sdmp

          Networking

          barindex
          Source: Network trafficSuricata IDS: 2058419 - Severity 1 - ET MALWARE Xenorat Default Handshake Inbound : 194.59.30.69:16589 -> 192.168.2.4:49730
          Source: Network trafficSuricata IDS: 2058419 - Severity 1 - ET MALWARE Xenorat Default Handshake Inbound : 194.59.30.69:16589 -> 192.168.2.4:49732
          Source: Network trafficSuricata IDS: 2058419 - Severity 1 - ET MALWARE Xenorat Default Handshake Inbound : 194.59.30.69:16589 -> 192.168.2.4:49731
          Source: Network trafficSuricata IDS: 2058419 - Severity 1 - ET MALWARE Xenorat Default Handshake Inbound : 194.59.30.69:16589 -> 192.168.2.4:49734
          Source: Network trafficSuricata IDS: 2050110 - Severity 1 - ET MALWARE [ANY.RUN] Xeno-RAT TCP Check-In : 194.59.30.69:16589 -> 192.168.2.4:49734
          Source: Network trafficSuricata IDS: 2050111 - Severity 1 - ET MALWARE [ANY.RUN] Xeno-RAT TCP Keep-Alive : 192.168.2.4:49734 -> 194.59.30.69:16589
          Source: Network trafficSuricata IDS: 2050111 - Severity 1 - ET MALWARE [ANY.RUN] Xeno-RAT TCP Keep-Alive : 192.168.2.4:49731 -> 194.59.30.69:16589
          Source: Network trafficSuricata IDS: 2050110 - Severity 1 - ET MALWARE [ANY.RUN] Xeno-RAT TCP Check-In : 194.59.30.69:16589 -> 192.168.2.4:49731
          Source: Network trafficSuricata IDS: 2050110 - Severity 1 - ET MALWARE [ANY.RUN] Xeno-RAT TCP Check-In : 194.59.30.69:16589 -> 192.168.2.4:49730
          Source: Malware configuration extractorURLs: 194.59.30.69
          Source: global trafficTCP traffic: 194.59.30.69 ports 1,5,6,8,9,16589
          Source: global trafficTCP traffic: 192.168.2.4:49730 -> 194.59.30.69:16589
          Source: Joe Sandbox ViewASN Name: COMBAHTONcombahtonGmbHDE COMBAHTONcombahtonGmbHDE
          Source: unknownTCP traffic detected without corresponding DNS query: 194.59.30.69
          Source: unknownTCP traffic detected without corresponding DNS query: 194.59.30.69
          Source: unknownTCP traffic detected without corresponding DNS query: 194.59.30.69
          Source: unknownTCP traffic detected without corresponding DNS query: 194.59.30.69
          Source: unknownTCP traffic detected without corresponding DNS query: 194.59.30.69
          Source: unknownTCP traffic detected without corresponding DNS query: 194.59.30.69
          Source: unknownTCP traffic detected without corresponding DNS query: 194.59.30.69
          Source: unknownTCP traffic detected without corresponding DNS query: 194.59.30.69
          Source: unknownTCP traffic detected without corresponding DNS query: 194.59.30.69
          Source: unknownTCP traffic detected without corresponding DNS query: 194.59.30.69
          Source: unknownTCP traffic detected without corresponding DNS query: 194.59.30.69
          Source: unknownTCP traffic detected without corresponding DNS query: 194.59.30.69
          Source: unknownTCP traffic detected without corresponding DNS query: 194.59.30.69
          Source: unknownTCP traffic detected without corresponding DNS query: 194.59.30.69
          Source: unknownTCP traffic detected without corresponding DNS query: 194.59.30.69
          Source: unknownTCP traffic detected without corresponding DNS query: 194.59.30.69
          Source: unknownTCP traffic detected without corresponding DNS query: 194.59.30.69
          Source: unknownTCP traffic detected without corresponding DNS query: 194.59.30.69
          Source: unknownTCP traffic detected without corresponding DNS query: 194.59.30.69
          Source: unknownTCP traffic detected without corresponding DNS query: 194.59.30.69
          Source: unknownTCP traffic detected without corresponding DNS query: 194.59.30.69
          Source: unknownTCP traffic detected without corresponding DNS query: 194.59.30.69
          Source: unknownTCP traffic detected without corresponding DNS query: 194.59.30.69
          Source: unknownTCP traffic detected without corresponding DNS query: 194.59.30.69
          Source: unknownTCP traffic detected without corresponding DNS query: 194.59.30.69
          Source: unknownTCP traffic detected without corresponding DNS query: 194.59.30.69
          Source: unknownTCP traffic detected without corresponding DNS query: 194.59.30.69
          Source: unknownTCP traffic detected without corresponding DNS query: 194.59.30.69
          Source: unknownTCP traffic detected without corresponding DNS query: 194.59.30.69
          Source: unknownTCP traffic detected without corresponding DNS query: 194.59.30.69
          Source: unknownTCP traffic detected without corresponding DNS query: 194.59.30.69
          Source: unknownTCP traffic detected without corresponding DNS query: 194.59.30.69
          Source: unknownTCP traffic detected without corresponding DNS query: 194.59.30.69
          Source: unknownTCP traffic detected without corresponding DNS query: 194.59.30.69
          Source: unknownTCP traffic detected without corresponding DNS query: 194.59.30.69
          Source: unknownTCP traffic detected without corresponding DNS query: 194.59.30.69
          Source: unknownTCP traffic detected without corresponding DNS query: 194.59.30.69
          Source: unknownTCP traffic detected without corresponding DNS query: 194.59.30.69
          Source: unknownTCP traffic detected without corresponding DNS query: 194.59.30.69
          Source: unknownTCP traffic detected without corresponding DNS query: 194.59.30.69
          Source: unknownTCP traffic detected without corresponding DNS query: 194.59.30.69
          Source: unknownTCP traffic detected without corresponding DNS query: 194.59.30.69
          Source: unknownTCP traffic detected without corresponding DNS query: 194.59.30.69
          Source: unknownTCP traffic detected without corresponding DNS query: 194.59.30.69
          Source: unknownTCP traffic detected without corresponding DNS query: 194.59.30.69
          Source: unknownTCP traffic detected without corresponding DNS query: 194.59.30.69
          Source: unknownTCP traffic detected without corresponding DNS query: 194.59.30.69
          Source: unknownTCP traffic detected without corresponding DNS query: 194.59.30.69
          Source: unknownTCP traffic detected without corresponding DNS query: 194.59.30.69
          Source: unknownTCP traffic detected without corresponding DNS query: 194.59.30.69
          Source: b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exe, 00000000.00000002.4107606826.0000000002AA1000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name

          Key, Mouse, Clipboard, Microphone and Screen Capturing

          barindex
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeWindows user hook set: 0 keyboard low level C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeJump to behavior

          System Summary

          barindex
          Source: b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exe, type: SAMPLEMatched rule: Xeno RAT is an open-source RAT, used by Kimsuky in January 2024 Author: Sekoia.io
          Source: 0.0.b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exe.7b0000.0.unpack, type: UNPACKEDPEMatched rule: Xeno RAT is an open-source RAT, used by Kimsuky in January 2024 Author: Sekoia.io
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeProcess Stats: CPU usage > 49%
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeCode function: 0_2_02920B120_2_02920B12
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeCode function: 0_2_029223200_2_02922320
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeCode function: 0_2_029290500_2_02929050
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeCode function: 0_2_029299200_2_02929920
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeCode function: 0_2_0292EE480_2_0292EE48
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeCode function: 0_2_0292DE6A0_2_0292DE6A
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeCode function: 0_2_02928D080_2_02928D08
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeCode function: 0_2_055E64C00_2_055E64C0
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeCode function: 0_2_055E64B00_2_055E64B0
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeCode function: 0_2_055EE3BC0_2_055EE3BC
          Source: b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exe, 00000000.00000002.4109365555.00000000063A9000.00000004.00000010.00020000.00000000.sdmpBinary or memory string: OriginalFilenameUNKNOWN_FILET vs b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exe
          Source: b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exe, 00000000.00000002.4107606826.0000000002B62000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameKeyLoggerOffline.dllB vs b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exe
          Source: b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exe, 00000000.00000002.4106900494.0000000000D4E000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameclr.dllT vs b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exe
          Source: b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exe, 00000000.00000002.4108815174.00000000055D0000.00000004.08000000.00040000.00000000.sdmpBinary or memory string: OriginalFilenameKeyLoggerOffline.dllB vs b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exe
          Source: b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exe, 00000000.00000000.1643611700.00000000007BE000.00000002.00000001.01000000.00000003.sdmpBinary or memory string: OriginalFilenameXeno_manager.exe: vs b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exe
          Source: b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeBinary or memory string: OriginalFilenameXeno_manager.exe: vs b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exe
          Source: b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exe, type: SAMPLEMatched rule: rat_win_xeno_rat author = Sekoia.io, description = Xeno RAT is an open-source RAT, used by Kimsuky in January 2024, creation_date = 2024-02-09, classification = TLP:CLEAR, version = 1.0, reference = https://github.com/moom825/xeno-rat/tree/main/xeno%20rat%20client, id = 4be1ff07-8180-42a8-9f51-b5e17bf23442
          Source: 0.0.b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exe.7b0000.0.unpack, type: UNPACKEDPEMatched rule: rat_win_xeno_rat author = Sekoia.io, description = Xeno RAT is an open-source RAT, used by Kimsuky in January 2024, creation_date = 2024-02-09, classification = TLP:CLEAR, version = 1.0, reference = https://github.com/moom825/xeno-rat/tree/main/xeno%20rat%20client, id = 4be1ff07-8180-42a8-9f51-b5e17bf23442
          Source: classification engineClassification label: mal100.troj.spyw.evad.winEXE@1/0@0/1
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeMutant created: NULL
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeMutant created: \Sessions\1\BaseNamedObjects\Xeno_rat_nd8912d-admin
          Source: b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
          Source: b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeStatic file information: TRID: Win32 Executable (generic) Net Framework (10011505/4) 49.83%
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
          Source: b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeVirustotal: Detection: 79%
          Source: b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeReversingLabs: Detection: 76%
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeSection loaded: mscoree.dllJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeSection loaded: apphelp.dllJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeSection loaded: kernel.appcore.dllJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeSection loaded: version.dllJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeSection loaded: windows.storage.dllJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeSection loaded: wldp.dllJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeSection loaded: profapi.dllJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeSection loaded: cryptsp.dllJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeSection loaded: rsaenh.dllJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeSection loaded: cryptbase.dllJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeSection loaded: mswsock.dllJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeSection loaded: sspicli.dllJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeSection loaded: wbemcomn.dllJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeSection loaded: amsi.dllJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeSection loaded: userenv.dllJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeSection loaded: msasn1.dllJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeSection loaded: gpapi.dllJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeSection loaded: uxtheme.dllJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA}\InprocServer32Jump to behavior
          Source: b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR
          Source: b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
          Source: Binary string: C:\Users\moom825\Desktop\xeno-rat\xeno-rat\Plugins\KeyLoggerOffline\obj\Release\KeyLoggerOffline.pdbYpsp ep_CorDllMainmscoree.dll source: b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exe, 00000000.00000002.4107606826.0000000002B62000.00000004.00000800.00020000.00000000.sdmp, b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exe, 00000000.00000002.4108815174.00000000055D0000.00000004.08000000.00040000.00000000.sdmp
          Source: Binary string: .pdbYp source: b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exe, 00000000.00000002.4107606826.0000000002B62000.00000004.00000800.00020000.00000000.sdmp, b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exe, 00000000.00000002.4107606826.0000000002B53000.00000004.00000800.00020000.00000000.sdmp
          Source: Binary string: C:\Users\moom825\Desktop\xeno-rat\xeno-rat\Plugins\KeyLoggerOffline\obj\Release\KeyLoggerOffline.pdb source: b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exe, 00000000.00000002.4107606826.0000000002B62000.00000004.00000800.00020000.00000000.sdmp, b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exe, 00000000.00000002.4108815174.00000000055D0000.00000004.08000000.00040000.00000000.sdmp

          Data Obfuscation

          barindex
          Source: b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exe, DllHandler.cs.Net Code: DllNodeHandler System.Reflection.Assembly.Load(byte[])
          Source: b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exe, DllHandler.cs.Net Code: DllNodeHandler
          Source: b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeStatic PE information: 0xB6F61BA2 [Sat Apr 9 13:44:02 2067 UTC]
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeCode function: 0_2_055E8E10 push es; ret 0_2_055E9290
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeCode function: 0_2_055E928A push es; ret 0_2_055E9290
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeCode function: 0_2_055E9B60 push es; ret 0_2_055E9B76
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeCode function: 0_2_055E9ABA push es; ret 0_2_055E9B56
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeMemory allocated: 28E0000 memory reserve | memory write watchJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeMemory allocated: 2AA0000 memory reserve | memory write watchJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeMemory allocated: 4AA0000 memory reserve | memory write watchJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeThread delayed: delay time: 922337203685477Jump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeWindow / User API: threadDelayed 4948Jump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeWindow / User API: threadDelayed 4892Jump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exe TID: 7344Thread sleep time: -8301034833169293s >= -30000sJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exe TID: 7404Thread sleep count: 4948 > 30Jump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exe TID: 7416Thread sleep count: 4892 > 30Jump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeSystem information queried: CurrentTimeZoneInformationJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeSystem information queried: CurrentTimeZoneInformationJump to behavior
          Source: all processesThread injection, dropped files, key value created, disk infection and DNS query: no activity detected
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeThread delayed: delay time: 922337203685477Jump to behavior
          Source: b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exe, 00000000.00000002.4106900494.0000000000DC1000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeProcess information queried: ProcessInformationJump to behavior

          Anti Debugging

          barindex
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeProcess Stats: CPU usage > 42% for more than 60s
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeCode function: 0_2_0292EE48 LdrInitializeThunk,0_2_0292EE48
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeProcess token adjusted: DebugJump to behavior
          Source: all processesThread injection, dropped files, key value created, disk infection and DNS query: no activity detected
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeMemory allocated: page read and write | page guardJump to behavior
          Source: b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exe, 00000000.00000002.4107606826.0000000002B83000.00000004.00000800.00020000.00000000.sdmp, b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exe, 00000000.00000002.4107606826.0000000002D40000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Program Manager
          Source: b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exe, 00000000.00000002.4107606826.0000000002EEE000.00000004.00000800.00020000.00000000.sdmp, b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exe, 00000000.00000002.4107606826.0000000002B83000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: explorer - Program Manager
          Source: b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exe, 00000000.00000002.4107606826.0000000002B83000.00000004.00000800.00020000.00000000.sdmp, b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exe, 00000000.00000002.4107606826.0000000002D40000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Program Manager@'
          Source: b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exe, 00000000.00000002.4107606826.0000000002E10000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: explorer - Program ManagerP
          Source: b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exe, 00000000.00000002.4107606826.0000000002D40000.00000004.00000800.00020000.00000000.sdmp, b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exe, 00000000.00000002.4107606826.0000000002F68000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Program ManagerlBkq
          Source: b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exe, 00000000.00000002.4107606826.0000000002EEE000.00000004.00000800.00020000.00000000.sdmp, b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exe, 00000000.00000002.4107606826.0000000002B83000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: explorer - Prog@\kq explorer - Program Manager
          Source: b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exe, 00000000.00000002.4107606826.0000000002ADF000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Program Manager@
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeQueries volume information: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exe VolumeInformationJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformationJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformationJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformationJump to behavior
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior
          Source: b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exe, 00000000.00000002.4106900494.0000000000D86000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: %ProgramFiles%\Windows Defender\MsMpeng.exe
          Source: C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exeWMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : SELECT * FROM AntivirusProduct

          Stealing of Sensitive Information

          barindex
          Source: Yara matchFile source: b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exe, type: SAMPLE
          Source: Yara matchFile source: 0.0.b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exe.7b0000.0.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 00000000.00000000.1643596965.00000000007B2000.00000002.00000001.01000000.00000003.sdmp, type: MEMORY
          Source: Yara matchFile source: Process Memory Space: b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exe PID: 7308, type: MEMORYSTR

          Remote Access Functionality

          barindex
          Source: Yara matchFile source: b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exe, type: SAMPLE
          Source: Yara matchFile source: 0.0.b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exe.7b0000.0.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 00000000.00000000.1643596965.00000000007B2000.00000002.00000001.01000000.00000003.sdmp, type: MEMORY
          Source: Yara matchFile source: Process Memory Space: b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exe PID: 7308, type: MEMORYSTR
          ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
          Gather Victim Identity InformationAcquire InfrastructureValid Accounts1
          Windows Management Instrumentation
          1
          DLL Side-Loading
          1
          Process Injection
          1
          Disable or Modify Tools
          11
          Input Capture
          1
          System Time Discovery
          Remote Services11
          Input Capture
          1
          Encrypted Channel
          Exfiltration Over Other Network MediumAbuse Accessibility Features
          CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
          DLL Side-Loading
          132
          Virtualization/Sandbox Evasion
          LSASS Memory121
          Security Software Discovery
          Remote Desktop Protocol1
          Archive Collected Data
          1
          Non-Standard Port
          Exfiltration Over BluetoothNetwork Denial of Service
          Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
          Process Injection
          Security Account Manager2
          Process Discovery
          SMB/Windows Admin SharesData from Network Shared Drive1
          Application Layer Protocol
          Automated ExfiltrationData Encrypted for Impact
          Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
          Obfuscated Files or Information
          NTDS132
          Virtualization/Sandbox Evasion
          Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
          Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
          Software Packing
          LSA Secrets1
          Application Window Discovery
          SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
          Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
          Timestomp
          Cached Domain Credentials13
          System Information Discovery
          VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
          DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items1
          DLL Side-Loading
          DCSyncRemote System DiscoveryWindows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
          Hide Legend

          Legend:

          • Process
          • Signature
          • Created File
          • DNS/IP Info
          • Is Dropped
          • Is Windows Process
          • Number of created Registry Values
          • Number of created Files
          • Visual Basic
          • Delphi
          • Java
          • .Net C# or VB.NET
          • C, C++ or other language
          • Is malicious
          • Internet

          This section contains all screenshots as thumbnails, including those not shown in the slideshow.


          windows-stand
          SourceDetectionScannerLabelLink
          b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exe79%VirustotalBrowse
          b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exe76%ReversingLabsByteCode-MSIL.Backdoor.XenoRAT
          b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exe100%Joe Sandbox ML
          No Antivirus matches
          No Antivirus matches
          No Antivirus matches
          SourceDetectionScannerLabelLink
          194.59.30.690%Avira URL Cloudsafe
          No contacted domains info
          NameMaliciousAntivirus DetectionReputation
          194.59.30.69true
          • Avira URL Cloud: safe
          unknown
          NameSourceMaliciousAntivirus DetectionReputation
          http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameb1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exe, 00000000.00000002.4107606826.0000000002AA1000.00000004.00000800.00020000.00000000.sdmpfalse
            high
            • No. of IPs < 25%
            • 25% < No. of IPs < 50%
            • 50% < No. of IPs < 75%
            • 75% < No. of IPs
            IPDomainCountryFlagASNASN NameMalicious
            194.59.30.69
            unknownGermany
            30823COMBAHTONcombahtonGmbHDEtrue
            Joe Sandbox version:41.0.0 Charoite
            Analysis ID:1581378
            Start date and time:2024-12-27 14:36:08 +01:00
            Joe Sandbox product:CloudBasic
            Overall analysis duration:0h 6m 19s
            Hypervisor based Inspection enabled:false
            Report type:full
            Cookbook file name:default.jbs
            Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
            Number of analysed new started processes analysed:5
            Number of new started drivers analysed:0
            Number of existing processes analysed:0
            Number of existing drivers analysed:0
            Number of injected processes analysed:0
            Technologies:
            • HCA enabled
            • EGA enabled
            • AMSI enabled
            Analysis Mode:default
            Analysis stop reason:Timeout
            Sample name:b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exe
            Detection:MAL
            Classification:mal100.troj.spyw.evad.winEXE@1/0@0/1
            EGA Information:
            • Successful, ratio: 100%
            HCA Information:
            • Successful, ratio: 100%
            • Number of executed functions: 20
            • Number of non-executed functions: 4
            Cookbook Comments:
            • Found application associated with file extension: .exe
            • Override analysis time to 240000 for current running targets taking high CPU consumption
            • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
            • Excluded IPs from analysis (whitelisted): 20.109.210.53, 13.107.246.63
            • Excluded domains from analysis (whitelisted): ocsp.digicert.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
            • Not all processes where analyzed, report is missing behavior information
            • Report size getting too big, too many NtOpenKeyEx calls found.
            • Report size getting too big, too many NtQueryValueKey calls found.
            TimeTypeDescription
            08:37:45API Interceptor11175386x Sleep call for process: b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exe modified
            No context
            No context
            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
            COMBAHTONcombahtonGmbHDESyncing.exeGet hashmaliciousAsyncRATBrowse
            • 185.223.30.86
            l4.exeGet hashmaliciousUnknownBrowse
            • 194.59.30.220
            l4.exeGet hashmaliciousUnknownBrowse
            • 194.59.30.220
            client.exeGet hashmaliciousUnknownBrowse
            • 194.59.30.220
            client.exeGet hashmaliciousUnknownBrowse
            • 194.59.30.220
            Shipping Bill No6239999Dt09122024.PDF.jarGet hashmaliciousCaesium Obfuscator, STRRATBrowse
            • 194.59.30.164
            Shipping Bill No6239999Dt09122024.PDF.jarGet hashmaliciousCaesium Obfuscator, STRRATBrowse
            • 194.59.30.164
            Shipping Bill6239999 dated 13122024.PDF.jarGet hashmaliciousCaesium Obfuscator, STRRATBrowse
            • 194.59.30.164
            Support.ClientSetup.exeGet hashmaliciousScreenConnect ToolBrowse
            • 194.59.31.27
            Counseling_Services_Overview.docmGet hashmaliciousUnknownBrowse
            • 45.147.231.195
            No context
            No context
            No created / dropped files found
            File type:PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
            Entropy (8bit):5.641387758285389
            TrID:
            • Win32 Executable (generic) Net Framework (10011505/4) 49.83%
            • Win32 Executable (generic) a (10002005/4) 49.78%
            • Generic CIL Executable (.NET, Mono, etc.) (73296/58) 0.36%
            • Generic Win/DOS Executable (2004/3) 0.01%
            • DOS Executable Generic (2002/1) 0.01%
            File name:b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exe
            File size:46'592 bytes
            MD5:12ac061f02656d9e3d3cfbdd429a6bcf
            SHA1:5d6bb219d35a0dd57ddcbdb5950e9307593279e0
            SHA256:b1593574e46fb1f30b1da4fa594f43bb52b051a616db390abf23ef45508f8b13
            SHA512:36a8ff30b69343d96b41034330f30ccf00e0bf9f71f58e385bc8c03ffaf23cc23130f7ad705b6d23f51e44810f2438fedcaa7bd0cc57af27de106c54c6b3957a
            SSDEEP:768:ydhO/poiiUcjlJInH7ElmH9Xqk5nWEZ5SbTDa6uI7CPW5F:Uw+jjgnbElmH9XqcnW85SbTPuIN
            TLSH:2223F84C57AC8923E6AF5ABD9832426387B3F3669532E38F08CCD4E9379338555053A7
            File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................."...0.................. ........@.. ....................... ............`................................
            Icon Hash:90cececece8e8eb0
            Entrypoint:0x40cafe
            Entrypoint Section:.text
            Digitally signed:false
            Imagebase:0x400000
            Subsystem:windows gui
            Image File Characteristics:EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE
            DLL Characteristics:HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
            Time Stamp:0xB6F61BA2 [Sat Apr 9 13:44:02 2067 UTC]
            TLS Callbacks:
            CLR (.Net) Version:
            OS Version Major:4
            OS Version Minor:0
            File Version Major:4
            File Version Minor:0
            Subsystem Version Major:4
            Subsystem Version Minor:0
            Import Hash:f34d5f2d4577ed6d9ceec516c1f5a744
            Instruction
            jmp dword ptr [00402000h]
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            NameVirtual AddressVirtual Size Is in Section
            IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
            IMAGE_DIRECTORY_ENTRY_IMPORT0xcab00x4b.text
            IMAGE_DIRECTORY_ENTRY_RESOURCE0xe0000x5d0.rsrc
            IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
            IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
            IMAGE_DIRECTORY_ENTRY_BASERELOC0x100000xc.reloc
            IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
            IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
            IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
            IMAGE_DIRECTORY_ENTRY_TLS0x00x0
            IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
            IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
            IMAGE_DIRECTORY_ENTRY_IAT0x20000x8.text
            IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
            IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x20080x48.text
            IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
            NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
            .text0x20000xab040xac0021922ac4e44669208a28051a461d0c0aFalse0.44933230377906974data5.725579791460193IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
            .rsrc0xe0000x5d00x600413d41ad2a0da7fe255f98970731f053False0.453125data4.404307394530879IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
            .reloc0x100000xc0x2006d873b42f9427714a740f31af0c53c0cFalse0.041015625data0.06116285224115448IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
            NameRVASizeTypeLanguageCountryZLIB Complexity
            RT_VERSION0xe0a00x344data0.4533492822966507
            RT_MANIFEST0xe3e40x1eaXML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators0.5489795918367347
            DLLImport
            mscoree.dll_CorExeMain
            TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
            2024-12-27T14:37:03.587659+01002058419ET MALWARE Xenorat Default Handshake Inbound1194.59.30.6916589192.168.2.449730TCP
            2024-12-27T14:37:06.843864+01002058419ET MALWARE Xenorat Default Handshake Inbound1194.59.30.6916589192.168.2.449731TCP
            2024-12-27T14:37:12.268793+01002058419ET MALWARE Xenorat Default Handshake Inbound1194.59.30.6916589192.168.2.449732TCP
            2024-12-27T14:37:17.260923+01002058419ET MALWARE Xenorat Default Handshake Inbound1194.59.30.6916589192.168.2.449734TCP
            2024-12-27T14:37:19.853964+01002050110ET MALWARE [ANY.RUN] Xeno-RAT TCP Check-In1194.59.30.6916589192.168.2.449734TCP
            2024-12-27T14:37:19.937706+01002050111ET MALWARE [ANY.RUN] Xeno-RAT TCP Keep-Alive1192.168.2.449734194.59.30.6916589TCP
            2024-12-27T14:37:59.991704+01002050111ET MALWARE [ANY.RUN] Xeno-RAT TCP Keep-Alive1192.168.2.449731194.59.30.6916589TCP
            2024-12-27T14:38:24.459236+01002050111ET MALWARE [ANY.RUN] Xeno-RAT TCP Keep-Alive1192.168.2.449731194.59.30.6916589TCP
            2024-12-27T14:39:12.428763+01002050111ET MALWARE [ANY.RUN] Xeno-RAT TCP Keep-Alive1192.168.2.449731194.59.30.6916589TCP
            2024-12-27T14:39:42.912839+01002050111ET MALWARE [ANY.RUN] Xeno-RAT TCP Keep-Alive1192.168.2.449731194.59.30.6916589TCP
            2024-12-27T14:40:04.240627+01002050110ET MALWARE [ANY.RUN] Xeno-RAT TCP Check-In1194.59.30.6916589192.168.2.449731TCP
            2024-12-27T14:40:34.376153+01002050110ET MALWARE [ANY.RUN] Xeno-RAT TCP Check-In1194.59.30.6916589192.168.2.449730TCP
            TimestampSource PortDest PortSource IPDest IP
            Dec 27, 2024 14:37:02.214278936 CET4973016589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:02.333969116 CET1658949730194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:02.334093094 CET4973016589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:03.587658882 CET1658949730194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:03.614049911 CET4973016589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:03.734103918 CET1658949730194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:04.018625975 CET1658949730194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:04.021290064 CET4973016589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:04.141129017 CET1658949730194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:04.425324917 CET1658949730194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:04.474415064 CET4973016589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:04.626535892 CET1658949730194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:04.677548885 CET4973016589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:05.048670053 CET4973016589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:05.168353081 CET1658949730194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:05.462032080 CET1658949730194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:05.471035957 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:05.505676985 CET4973016589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:05.590697050 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:05.590812922 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:06.843863964 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:06.845263958 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:06.964828968 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:07.251355886 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:07.252636909 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:07.253128052 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:07.253592968 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:07.254020929 CET4973016589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:07.372134924 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:07.372498035 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:07.373023987 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:07.373543978 CET1658949730194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:08.992376089 CET1658949730194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:08.992465019 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:08.994517088 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:08.994539022 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:09.037091017 CET4973016589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:09.117060900 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:09.117142916 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:09.117156029 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:12.268793106 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:12.270714998 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:12.390269041 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:13.512017012 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:13.513803959 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:13.633474112 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:13.988416910 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:13.989948034 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:13.990540981 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:13.991234064 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:13.992428064 CET4973016589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:14.109699011 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:14.109952927 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:14.110616922 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:14.111911058 CET1658949730194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:15.205513000 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:15.207196951 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:15.326719999 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:15.842163086 CET1658949730194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:15.843451023 CET4973416589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:15.845012903 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:15.859738111 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:15.896346092 CET4973016589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:15.963052988 CET1658949734194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:15.963126898 CET4973416589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:15.979454041 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:16.867285013 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:16.869493961 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:16.989002943 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:17.260922909 CET1658949734194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:17.262435913 CET4973416589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:17.384689093 CET1658949734194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:17.678076029 CET1658949734194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:17.682389975 CET4973416589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:17.683005095 CET4973416589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:17.683413982 CET4973416589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:17.683809042 CET4973016589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:17.802048922 CET1658949734194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:17.802772999 CET1658949734194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:17.803162098 CET1658949734194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:17.803543091 CET1658949730194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:18.270713091 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:18.270725012 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:18.272099018 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:18.276830912 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:18.392246962 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:18.396862030 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:19.113714933 CET1658949734194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:19.167463064 CET4973416589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:19.323918104 CET1658949734194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:19.325320005 CET4973416589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:19.445197105 CET1658949734194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:19.662015915 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:19.664213896 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:19.783725977 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:19.845499992 CET1658949734194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:19.845525026 CET1658949734194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:19.845535994 CET1658949734194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:19.845566988 CET4973416589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:19.845665932 CET1658949734194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:19.845678091 CET1658949734194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:19.845688105 CET1658949734194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:19.845699072 CET1658949734194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:19.845700026 CET4973416589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:19.845724106 CET4973416589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:19.853964090 CET1658949734194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:19.854015112 CET4973416589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:19.854110956 CET1658949734194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:19.862410069 CET1658949734194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:19.862454891 CET4973416589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:19.862525940 CET1658949734194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:19.870676041 CET1658949734194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:19.870723963 CET4973416589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:19.931332111 CET4973416589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:19.937705994 CET4973416589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:20.051942110 CET1658949734194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:20.057638884 CET1658949734194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:20.480406046 CET1658949734194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:20.521343946 CET4973416589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:20.677830935 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:20.686681032 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:20.806262016 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:20.982974052 CET1658949734194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:20.985258102 CET4973416589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:20.990478039 CET4973416589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:20.993837118 CET4973416589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:21.067425013 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:21.068947077 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:21.110588074 CET1658949734194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:21.110662937 CET4973416589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:21.191941977 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:22.482662916 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:22.484267950 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:22.603883028 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:23.083218098 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:23.088875055 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:23.209640026 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:23.896738052 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:23.898078918 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:24.017728090 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:25.318433046 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:25.320394039 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:25.439918995 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:25.490326881 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:25.496767998 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:25.616563082 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:26.739939928 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:26.741267920 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:26.860904932 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:27.896246910 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:27.943231106 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:28.019431114 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:28.139373064 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:28.162123919 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:28.163515091 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:28.283132076 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:29.552623034 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:29.554773092 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:29.674349070 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:30.428915977 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:30.434187889 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:30.553694963 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:30.976423025 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:30.978060961 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:31.097582102 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:32.395849943 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:32.415988922 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:32.535613060 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:32.833281040 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:32.880866051 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:32.889281034 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:33.010037899 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:33.833810091 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:33.836153030 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:33.955722094 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:35.258297920 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:35.261425972 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:35.286386013 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:35.290627956 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:35.381082058 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:35.410135984 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:36.677098989 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:36.678930044 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:36.798505068 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:37.692953110 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:37.698585987 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:37.818187952 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:38.084124088 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:38.085319996 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:38.205102921 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:39.489856958 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:39.491817951 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:39.802681923 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:40.079895020 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:40.079952955 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:40.079982042 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:40.079993010 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:40.099325895 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:40.107842922 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:40.227351904 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:41.364754915 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:41.368093967 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:41.487654924 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:42.489590883 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:42.494033098 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:42.613720894 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:42.787389040 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:42.788604021 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:42.908205986 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:44.209789038 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:44.211760044 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:44.331482887 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:44.896121979 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:44.906456947 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:45.026170969 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:45.722031116 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:45.723285913 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:45.842835903 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:47.115935087 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:47.117573977 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:47.237449884 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:47.286434889 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:47.292062998 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:47.411832094 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:48.521513939 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:48.522779942 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:48.644695997 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:49.692790031 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:49.714899063 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:49.834595919 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:49.944489002 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:49.945641994 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:50.066382885 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:51.528526068 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:51.530797005 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:51.650434971 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:52.099884033 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:52.123189926 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:52.243159056 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:52.927294970 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:52.928703070 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:53.048346996 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:54.348994017 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:54.350219965 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:54.469731092 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:54.520936966 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:54.525609970 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:54.645275116 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:55.740750074 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:55.742183924 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:55.861869097 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:56.943032980 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:56.948384047 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:57.070391893 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:57.146020889 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:57.147893906 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:57.267388105 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:58.568572998 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:58.569819927 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:58.689327955 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:59.349062920 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:59.354713917 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:37:59.474184990 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:59.990365028 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:37:59.991703987 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:38:00.111985922 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:01.411561012 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:01.413578987 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:38:01.533401966 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:01.739630938 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:01.746169090 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:38:01.865936995 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:02.817845106 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:02.819586992 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:38:02.943845987 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:04.146580935 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:04.151731968 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:38:04.239487886 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:04.241192102 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:38:04.271394014 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:04.360662937 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:05.662164927 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:05.666980982 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:38:05.786639929 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:06.552788019 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:06.558162928 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:38:06.677870989 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:07.068001986 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:07.069500923 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:38:07.189023018 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:08.474817991 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:08.476295948 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:38:08.596735954 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:08.958712101 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:08.964020967 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:38:09.083523035 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:09.896163940 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:09.899274111 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:38:10.018719912 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:11.302376986 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:11.303683996 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:38:11.364608049 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:11.369848013 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:38:11.423597097 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:11.489557028 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:12.708487034 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:12.755903006 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:38:12.762653112 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:38:12.882277966 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:13.755928040 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:13.761053085 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:38:13.881139994 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:14.176815033 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:14.178636074 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:38:14.298784018 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:15.598956108 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:15.649539948 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:38:15.858293056 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:38:15.977864981 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:16.161679029 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:16.167412043 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:38:16.286923885 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:17.270701885 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:17.272629976 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:38:17.393069983 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:18.570739031 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:18.615278959 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:38:18.659002066 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:38:18.677834034 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:18.724673986 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:38:18.753479004 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:38:18.778664112 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:18.873740911 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:20.160866976 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:20.171885967 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:38:20.291383028 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:21.067879915 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:21.074358940 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:38:21.193883896 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:21.583129883 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:21.587579012 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:38:21.707140923 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:23.004921913 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:23.039463043 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:38:23.164902925 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:23.473751068 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:23.479034901 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:38:23.598506927 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:24.457875967 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:24.459235907 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:38:24.578754902 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:25.864831924 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:25.865016937 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:25.866662979 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:38:25.871093035 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:38:25.986397028 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:25.990732908 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:27.270539999 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:27.272660017 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:38:27.392369032 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:28.312345982 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:28.318674088 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:38:28.438170910 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:28.677046061 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:28.678925037 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:38:28.798548937 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:30.099272966 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:30.102591991 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:38:30.222069979 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:30.724070072 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:30.731005907 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:38:30.851092100 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:31.520961046 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:31.522331953 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:38:31.641875982 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:32.927113056 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:32.929328918 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:38:33.049715042 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:33.130310059 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:33.137335062 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:38:33.257016897 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:34.333967924 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:34.337424040 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:38:34.457098961 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:35.537504911 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:35.543942928 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:38:35.663502932 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:35.740046978 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:35.741252899 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:38:35.860718012 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:37.145634890 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:37.147558928 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:38:37.267174006 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:37.942476034 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:37.953430891 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:38:38.073071003 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:38.544955015 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:38.549438000 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:38:38.725526094 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:39.958466053 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:39.960231066 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:38:40.079766989 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:40.338048935 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:40.343122005 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:38:40.462692976 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:41.364008904 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:41.365068913 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:38:41.484574080 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:42.739595890 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:42.747486115 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:38:42.770931005 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:42.772309065 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:38:42.866993904 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:42.892333984 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:44.192683935 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:44.194130898 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:38:44.313551903 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:45.161324024 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:45.166974068 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:38:45.286566973 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:45.598896027 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:45.600367069 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:38:45.719991922 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:46.989440918 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:46.991669893 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:38:47.112031937 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:47.567301989 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:47.571747065 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:38:47.691237926 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:48.411597013 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:48.413405895 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:38:48.533035040 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:49.833108902 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:49.834400892 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:38:49.954282999 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:49.959075928 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:49.965348005 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:38:50.084845066 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:51.223838091 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:51.225601912 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:38:51.345154047 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:52.364483118 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:52.369467974 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:38:52.488986015 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:52.629703999 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:52.633382082 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:38:52.752933025 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:54.051434994 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:54.052648067 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:38:54.172238111 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:54.770412922 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:54.777307987 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:38:54.896820068 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:55.442387104 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:55.444219112 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:38:55.563935041 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:56.866055965 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:56.869266987 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:38:57.002528906 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:57.176624060 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:57.182991982 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:38:57.302681923 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:58.270169020 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:58.277254105 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:38:58.396764994 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:59.567222118 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:59.573175907 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:38:59.692671061 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:59.693320990 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:38:59.694581032 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:38:59.814239979 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:01.114168882 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:01.115971088 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:39:01.235436916 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:02.152097940 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:02.156862020 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:39:02.276314974 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:02.535888910 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:02.538140059 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:39:02.657845020 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:03.942473888 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:03.943706036 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:39:04.063361883 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:04.567224026 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:04.573191881 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:39:04.692907095 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:05.348417044 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:05.350270987 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:39:05.469980955 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:06.754942894 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:06.757178068 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:39:06.876688957 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:06.973155975 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:06.981503963 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:39:07.101260900 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:08.176389933 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:08.181155920 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:39:08.300739050 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:09.379975080 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:09.386691093 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:39:09.506496906 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:09.600244045 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:09.601505995 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:39:09.721096992 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:11.004854918 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:11.007096052 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:39:11.127496004 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:11.770123959 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:11.776150942 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:39:11.895812035 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:12.426352024 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:12.428762913 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:39:12.549328089 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:13.848573923 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:13.850271940 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:39:13.970638037 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:14.161067009 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:14.166985035 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:39:14.286624908 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:15.254652023 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:15.256145954 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:39:15.375763893 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:16.567023993 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:16.577011108 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:39:16.661432028 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:16.663145065 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:39:16.696646929 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:16.782705069 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:18.082391977 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:18.088088036 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:39:18.207570076 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:18.973156929 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:19.021260977 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:39:19.077258110 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:39:19.198312998 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:19.488827944 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:19.490710020 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:39:19.610438108 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:20.879363060 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:20.887042046 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:39:21.006638050 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:21.703777075 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:21.710436106 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:39:21.968617916 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:21.968666077 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:39:21.968750000 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:22.505057096 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:22.507342100 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:39:22.626780987 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:23.926187038 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:23.928230047 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:39:24.136545897 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:24.255944014 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:24.263351917 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:39:24.382987022 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:25.332066059 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:25.333259106 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:39:25.452779055 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:27.128782034 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:27.128808975 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:27.129051924 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:27.129072905 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:27.129096985 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:39:27.129113913 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:39:27.132162094 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:39:27.205781937 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:39:27.251681089 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:27.325308084 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:28.552551031 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:28.556196928 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:39:28.675704956 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:29.613506079 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:29.617554903 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:39:29.737138033 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:29.957201004 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:29.961740971 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:39:30.081347942 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:31.363651037 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:31.364887953 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:39:31.484364986 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:32.020342112 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:32.026956081 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:39:32.146473885 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:33.017292023 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:33.018955946 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:39:33.133999109 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:33.134042978 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:39:33.138403893 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:34.426449060 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:34.426460981 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:34.431834936 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:39:34.431835890 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:39:34.551592112 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:34.551601887 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:35.848018885 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:35.857369900 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:39:35.978492022 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:36.832087040 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:36.840893030 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:39:36.960546970 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:37.254894972 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:37.256551981 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:39:37.376130104 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:38.676213980 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:38.678009987 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:39:38.797606945 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:39.238615036 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:39.333575010 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:39:39.347291946 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:39:39.466830969 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:40.097222090 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:40.098597050 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:39:40.218146086 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:41.503983974 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:41.505220890 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:39:41.624969959 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:41.753892899 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:41.760844946 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:39:41.880388021 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:42.910089016 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:42.912838936 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:39:43.032392979 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:44.160187006 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:44.166908979 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:39:44.286480904 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:44.332195997 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:44.333458900 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:39:44.454075098 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:45.738959074 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:45.740118027 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:39:45.859575987 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:46.566803932 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:46.571201086 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:39:46.690773964 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:47.148969889 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:47.150568962 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:39:47.271614075 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:48.567270041 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:48.569329977 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:39:48.689318895 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:48.972960949 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:48.978934050 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:39:49.098448038 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:49.989007950 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:49.990835905 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:39:50.110567093 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:51.380666971 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:51.387275934 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:39:51.410749912 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:51.412185907 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:39:51.507669926 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:51.531676054 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:52.816351891 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:52.819936991 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:39:52.939522982 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:53.785432100 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:53.792120934 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:39:53.911577940 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:54.222623110 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:54.228746891 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:39:54.348437071 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:55.644671917 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:55.646500111 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:39:55.767487049 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:56.192080975 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:56.196729898 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:39:56.316288948 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:57.035353899 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:57.040118933 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:39:57.159615040 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:58.457036018 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:58.458513975 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:39:58.578104019 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:58.597862959 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:58.603980064 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:39:58.723752975 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:59.863553047 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:39:59.864826918 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:39:59.984371901 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:40:01.003808022 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:40:01.014780045 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:40:01.135050058 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:40:01.269731045 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:40:01.271456003 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:40:01.391155005 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:40:02.691301107 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:40:02.707667112 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:40:02.827101946 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:40:03.412188053 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:40:03.417973995 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:40:03.539006948 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:40:04.113214970 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:40:04.119676113 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:40:04.240627050 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:40:05.520625114 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:40:05.522631884 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:40:05.642182112 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:40:05.816268921 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:40:05.820210934 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:40:05.940141916 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:40:06.940807104 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:40:06.944122076 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:40:07.063612938 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:40:08.222625017 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:40:08.231055975 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:40:08.350665092 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:40:08.362915039 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:40:08.363862038 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:40:08.483374119 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:40:09.753858089 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:40:09.755063057 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:40:09.874577999 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:40:10.628632069 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:40:10.634211063 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:40:10.753778934 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:40:11.160264015 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:40:11.162935019 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:40:11.282685995 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:40:12.583537102 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:40:12.584883928 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:40:12.704941988 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:40:13.019814968 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:40:13.036585093 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:40:13.156434059 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:40:34.252852917 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:40:34.253086090 CET1658949730194.59.30.69192.168.2.4
            Dec 27, 2024 14:40:34.253177881 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:40:34.253176928 CET4973016589192.168.2.4194.59.30.69
            Dec 27, 2024 14:40:34.256603003 CET4973016589192.168.2.4194.59.30.69
            Dec 27, 2024 14:40:34.256603956 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:40:34.257090092 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:40:34.259834051 CET4973016589192.168.2.4194.59.30.69
            Dec 27, 2024 14:40:34.259840012 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:40:34.260446072 CET5000716589192.168.2.4194.59.30.69
            Dec 27, 2024 14:40:34.376152992 CET1658949730194.59.30.69192.168.2.4
            Dec 27, 2024 14:40:34.376163960 CET1658949731194.59.30.69192.168.2.4
            Dec 27, 2024 14:40:34.376218081 CET4973016589192.168.2.4194.59.30.69
            Dec 27, 2024 14:40:34.376223087 CET4973116589192.168.2.4194.59.30.69
            Dec 27, 2024 14:40:34.379689932 CET1658949732194.59.30.69192.168.2.4
            Dec 27, 2024 14:40:34.379806995 CET4973216589192.168.2.4194.59.30.69
            Dec 27, 2024 14:40:34.379868984 CET1658950007194.59.30.69192.168.2.4
            Dec 27, 2024 14:40:34.379941940 CET5000716589192.168.2.4194.59.30.69
            Dec 27, 2024 14:40:56.290337086 CET1658950007194.59.30.69192.168.2.4
            Dec 27, 2024 14:40:56.294523001 CET5000716589192.168.2.4194.59.30.69
            Dec 27, 2024 14:41:02.352302074 CET5000816589192.168.2.4194.59.30.69
            Dec 27, 2024 14:41:02.472157955 CET1658950008194.59.30.69192.168.2.4
            Dec 27, 2024 14:41:02.472376108 CET5000816589192.168.2.4194.59.30.69

            Click to jump to process

            Click to jump to process

            Click to dive into process behavior distribution

            Target ID:0
            Start time:08:36:56
            Start date:27/12/2024
            Path:C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exe
            Wow64 process (32bit):true
            Commandline:"C:\Users\user\Desktop\b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.exe"
            Imagebase:0x7b0000
            File size:46'592 bytes
            MD5 hash:12AC061F02656D9E3D3CFBDD429A6BCF
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Yara matches:
            • Rule: JoeSecurity_XenoRAT, Description: Yara detected XenoRAT, Source: 00000000.00000000.1643596965.00000000007B2000.00000002.00000001.01000000.00000003.sdmp, Author: Joe Security
            Reputation:low
            Has exited:false

            Reset < >

              Execution Graph

              Execution Coverage:15.9%
              Dynamic/Decrypted Code Coverage:100%
              Signature Coverage:2.3%
              Total number of Nodes:172
              Total number of Limit Nodes:6
              execution_graph 24216 55e5f8c 24217 55e5fa7 24216->24217 24218 55e54c4 DuplicateHandle 24216->24218 24218->24217 24004 55e21d8 24005 55e21f2 24004->24005 24013 55e1d74 24005->24013 24010 55e221a 24014 55e2390 SetWindowsHookExA 24013->24014 24016 55e21fe 24014->24016 24017 55e1d80 24016->24017 24018 55e1d8b 24017->24018 24033 55e54c4 24018->24033 24021 55e76d8 24022 55e76e7 24021->24022 24023 55e2458 DuplicateHandle 24022->24023 24024 55e76ee 24023->24024 24066 55e726c 24024->24066 24027 55e76c9 24028 55e76d8 24027->24028 24029 55e2458 DuplicateHandle 24028->24029 24030 55e76ee 24029->24030 24031 55e726c 6 API calls 24030->24031 24032 55e7707 24031->24032 24032->24010 24034 55e54cf 24033->24034 24039 55e2210 24034->24039 24042 55e5678 24034->24042 24037 55e5678 DuplicateHandle 24038 55e6027 24037->24038 24038->24039 24047 55e2458 24038->24047 24039->24010 24039->24021 24039->24027 24041 55e60cb 24044 55e5683 24042->24044 24043 55e5ff6 24043->24037 24043->24039 24044->24043 24045 55e2458 DuplicateHandle 24044->24045 24046 55e60cb 24045->24046 24048 55e2468 24047->24048 24049 55e2485 24048->24049 24051 55e1dac 24048->24051 24049->24041 24052 55e1db7 24051->24052 24053 55e58e3 24052->24053 24056 55e5990 24052->24056 24059 55e5980 24052->24059 24053->24049 24063 55e537c 24056->24063 24060 55e5990 24059->24060 24061 55e537c DuplicateHandle 24060->24061 24062 55e59be 24061->24062 24062->24053 24064 55e59f8 DuplicateHandle 24063->24064 24065 55e59be 24064->24065 24065->24053 24067 55e7277 24066->24067 24070 55e72d0 24067->24070 24069 55e7be6 24069->24069 24072 55e72db 24070->24072 24071 55e830c 24073 55e833c 24071->24073 24075 55e5678 DuplicateHandle 24071->24075 24072->24071 24076 55e8354 24072->24076 24081 55e9b60 24072->24081 24088 55e9aba 24072->24088 24095 55e9b78 24072->24095 24101 55e9b88 24072->24101 24074 55e5678 DuplicateHandle 24073->24074 24073->24076 24074->24076 24075->24073 24076->24069 24082 55e9bac 24081->24082 24083 55e9b6b 24081->24083 24084 55e9bcd 24082->24084 24107 55e9d38 24082->24107 24113 55e9cf5 24082->24113 24119 55e9d28 24082->24119 24083->24071 24084->24071 24089 55e9ac2 24088->24089 24091 55e9b38 24088->24091 24089->24071 24090 55e9bcd 24090->24071 24091->24071 24091->24090 24092 55e9d38 6 API calls 24091->24092 24093 55e9d28 6 API calls 24091->24093 24094 55e9cf5 6 API calls 24091->24094 24092->24090 24093->24090 24094->24090 24097 55e9b7f 24095->24097 24096 55e9bcd 24096->24071 24097->24096 24098 55e9d38 6 API calls 24097->24098 24099 55e9d28 6 API calls 24097->24099 24100 55e9cf5 6 API calls 24097->24100 24098->24096 24099->24096 24100->24096 24102 55e9b8c 24101->24102 24103 55e9bcd 24102->24103 24104 55e9d38 6 API calls 24102->24104 24105 55e9d28 6 API calls 24102->24105 24106 55e9cf5 6 API calls 24102->24106 24103->24071 24104->24103 24105->24103 24106->24103 24110 55e9d3c 24107->24110 24108 55e2458 DuplicateHandle 24109 55e9d73 24108->24109 24111 55e9d7e 24109->24111 24125 55e7f3c 24109->24125 24110->24108 24111->24084 24116 55e9cfb 24113->24116 24114 55e2458 DuplicateHandle 24115 55e9d73 24114->24115 24117 55e7f3c 6 API calls 24115->24117 24118 55e9d7e 24115->24118 24116->24084 24116->24114 24117->24118 24118->24084 24120 55e9d2b 24119->24120 24121 55e2458 DuplicateHandle 24120->24121 24122 55e9d73 24121->24122 24123 55e7f3c 6 API calls 24122->24123 24124 55e9d7e 24122->24124 24123->24124 24124->24084 24127 55e7f47 24125->24127 24126 55e9df0 24127->24126 24129 55e7f70 24127->24129 24130 55e7f7b 24129->24130 24136 55e7f80 24130->24136 24132 55e9e5f 24142 55ef230 24132->24142 24148 55ef218 24132->24148 24133 55e9e99 24133->24126 24137 55e7f8b 24136->24137 24153 55ead74 24137->24153 24139 55eaf58 24140 55eb180 24139->24140 24141 55e9b88 6 API calls 24139->24141 24140->24132 24141->24140 24144 55ef261 24142->24144 24145 55ef2ad 24142->24145 24143 55ef26d 24143->24133 24144->24143 24170 55ef498 24144->24170 24175 55ef4a8 24144->24175 24145->24133 24149 55ef230 24148->24149 24150 55ef26d 24149->24150 24151 55ef498 3 API calls 24149->24151 24152 55ef4a8 3 API calls 24149->24152 24150->24133 24151->24150 24152->24150 24154 55ead7f 24153->24154 24155 55ec76a 24154->24155 24158 55ec7c8 24154->24158 24162 55ec7b9 24154->24162 24155->24139 24159 55ec80b 24158->24159 24160 55ec816 KiUserCallbackDispatcher 24159->24160 24161 55ec840 24159->24161 24160->24161 24161->24155 24163 55ec762 24162->24163 24164 55ec7c2 24162->24164 24165 55ec76a 24163->24165 24168 55ec7c8 KiUserCallbackDispatcher 24163->24168 24169 55ec7b9 KiUserCallbackDispatcher 24163->24169 24166 55ec816 KiUserCallbackDispatcher 24164->24166 24167 55ec840 24164->24167 24165->24155 24166->24167 24167->24155 24168->24165 24169->24165 24171 55ef4a8 24170->24171 24179 55ef4d8 24171->24179 24189 55ef4e8 24171->24189 24172 55ef4b2 24172->24145 24177 55ef4d8 2 API calls 24175->24177 24178 55ef4e8 2 API calls 24175->24178 24176 55ef4b2 24176->24145 24177->24176 24178->24176 24180 55ef4e8 24179->24180 24181 55ee4d0 GetModuleHandleW 24180->24181 24183 55ef51c 24180->24183 24182 55ef504 24181->24182 24182->24183 24187 55ef780 GetModuleHandleW 24182->24187 24188 55ef771 GetModuleHandleW 24182->24188 24183->24172 24184 55ef514 24184->24183 24185 55ef720 GetModuleHandleW 24184->24185 24186 55ef74d 24185->24186 24186->24172 24187->24184 24188->24184 24190 55ef4f9 24189->24190 24193 55ef51c 24189->24193 24191 55ee4d0 GetModuleHandleW 24190->24191 24192 55ef504 24191->24192 24192->24193 24197 55ef780 GetModuleHandleW 24192->24197 24198 55ef771 GetModuleHandleW 24192->24198 24193->24172 24194 55ef514 24194->24193 24195 55ef720 GetModuleHandleW 24194->24195 24196 55ef74d 24195->24196 24196->24172 24197->24194 24198->24194 24199 292e938 24200 292e97c 24199->24200 24203 292e9af 24200->24203 24204 292e9e9 24203->24204 24208 292ee38 24204->24208 24212 292ee48 24204->24212 24205 292ea03 24210 292ee77 24208->24210 24209 292eff6 24209->24205 24210->24209 24211 292f380 LdrInitializeThunk 24210->24211 24211->24209 24211->24210 24214 292ee77 24212->24214 24213 292eff6 24213->24205 24214->24213 24215 292f380 LdrInitializeThunk 24214->24215 24215->24213 24215->24214

              Control-flow Graph

              • Executed
              • Not Executed
              control_flow_graph 600 292ee48-292ee75 601 292ee77 600->601 602 292ee7e-292ee98 600->602 603 292f1e3-292f1fd 601->603 604 292ef01-292ef22 601->604 605 292ef61-292ef65 601->605 613 292f8a1-292f8ca 602->613 614 292ee9e-292eeca call 2929fc8 602->614 606 292f204-292f214 603->606 608 292ef29-292ef3c 604->608 609 292f034-292f055 605->609 610 292ef6b-292ef6f 605->610 611 292f216 606->611 612 292f21b-292f25b 606->612 615 292ef43-292ef5e 608->615 616 292ef3e 608->616 617 292f05c-292f06c 609->617 618 292ef75-292ef80 call 292fa57 610->618 619 292f0ff-292f120 610->619 611->612 633 292f2b5-292f2c5 612->633 634 292f25d-292f28f 612->634 646 292f8e2-292f8e8 613->646 614->608 636 292eecc-292eef3 614->636 615->605 616->615 622 292f073-292f08d 617->622 623 292f06e 617->623 631 292ef82-292ef85 call 292faa0 618->631 632 292ef90-292eff4 call 292ea38 call 292ea48 618->632 621 292f127-292f137 619->621 628 292f139 621->628 629 292f13e-292f144 621->629 643 292f093-292f09b call 2929fc8 622->643 644 292f146-292f151 622->644 623->622 628->629 637 292f15d-292f166 629->637 645 292ef8b 631->645 632->617 693 292eff6-292f02f 632->693 641 292f2cb-292f2d0 633->641 642 292f8cc-292f8da 633->642 634->646 664 292eefc 636->664 638 292f7e4-292f7f2 call 2925888 637->638 639 292f16c-292f1aa call 2929fc8 637->639 662 292f2d5-292f2de 638->662 663 292f7f8-292f7ff 638->663 639->606 672 292f1ac-292f1de 639->672 641->642 642->646 655 292f0a0-292f0bf 643->655 644->637 645->622 655->621 661 292f0c1-292f0fa 655->661 661->646 667 292f2e0 662->667 668 292f2e7-292f312 call 29258d0 662->668 663->642 669 292f805-292f80c 663->669 664->604 664->646 667->668 673 292f350-292f371 667->673 674 292f420-292f441 667->674 675 292f5b1-292f5d2 667->675 676 292f4ea-292f50b 667->676 677 292f64f-292f670 667->677 682 292f378-292f390 LdrInitializeThunk 668->682 690 292f314-292f342 668->690 669->642 670 292f812-292f837 669->670 715 292f88a-292f899 670->715 716 292f839-292f85e 670->716 672->603 672->646 673->682 683 292f448-292f45f 674->683 684 292f5d9-292f5e1 675->684 680 292f512-292f52c 676->680 685 292f677-292f6ba call 2929fc8 677->685 680->638 699 292f396-292f3a5 682->699 700 292f7c8-292f7d5 682->700 711 292f461-292f476 683->711 712 292f48b-292f4b5 call 2929fc8 683->712 684->638 753 292f717-292f729 685->753 754 292f6bc-292f6ea 685->754 707 292f34b 690->707 693->646 718 292f531-292f534 699->718 719 292f3ab-292f3eb 699->719 725 292f7dd-292f7e2 700->725 707->646 711->700 726 292f47c-292f483 711->726 712->680 750 292f4b7-292f4e5 712->750 715->670 738 292f89f 715->738 741 292f867 716->741 723 292f536-292f541 718->723 724 292f54f-292f552 718->724 719->683 768 292f3ed-292f41b 719->768 784 292f544 call 55e013f 723->784 785 292f544 call 55e0150 723->785 730 292f5e6-292f5e9 724->730 731 292f558-292f57c 724->731 725->663 726->712 736 292f72e-292f731 730->736 737 292f5ef-292f615 730->737 731->684 760 292f57e-292f5ac 731->760 736->638 739 292f737-292f75b 736->739 737->685 764 292f617-292f64a 737->764 738->642 770 292f7b1-292f7c6 739->770 771 292f75d-292f78b 739->771 741->646 746 292f54a 746->638 750->646 753->638 754->646 760->646 764->646 768->646 770->663 771->646 784->746 785->746
              Memory Dump Source
              • Source File: 00000000.00000002.4107496956.0000000002920000.00000040.00000800.00020000.00000000.sdmp, Offset: 02920000, based on PE: false
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_2920000_b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.jbxd
              Similarity
              • API ID:
              • String ID:
              • API String ID:
              • Opcode ID: f3094369df0a257e82811bebfb43a7ec59fef120520c577333b8c51eea664c25
              • Instruction ID: 983cb573dabac0fb4db0b8a7f804bff9e89a1691e083287ae7bc53f82e56f2c5
              • Opcode Fuzzy Hash: f3094369df0a257e82811bebfb43a7ec59fef120520c577333b8c51eea664c25
              • Instruction Fuzzy Hash: 9E723770A00319CFCB15DFA8C584A9DBBF2BF4A310F2585A9E409AF3A5D734AD45CB50

              Control-flow Graph

              • Executed
              • Not Executed
              control_flow_graph 786 2920b12-2920b48 787 2920b51-2920ba6 call 29207d4 786->787 788 2920b4a 786->788 929 2920ba6 call 29213b0 787->929 930 2920ba6 call 29213a1 787->930 788->787 789 2920d44-2920d68 788->789 790 2920f04-2920f28 788->790 791 2920e3f-2920e63 788->791 795 2920d6f-2920d7f 789->795 794 2920f2f-2920f3f 790->794 793 2920e6a-2920e7a 791->793 798 2920e81-2920e87 793->798 799 2920e7c 793->799 800 2920f41 794->800 801 2920f46-2920f49 794->801 796 2920d81 795->796 797 2920d86-2920d8d 795->797 796->797 802 2920d93-2920da6 797->802 803 2920f4c-2920f5d 797->803 798->803 799->798 800->801 801->803 815 2920da8-2920dae 802->815 816 2920db9-2920dc1 802->816 806 2920f66-2920fa0 803->806 807 2920f5f 803->807 843 2920fa8-2920fc7 806->843 807->806 810 29211b0-29211d4 807->810 811 29210e6-292110a 807->811 812 292100a-292102e 807->812 817 29211db-2921214 810->817 814 2921111-292114e 811->814 818 2921035-2921043 812->818 923 2921150 call 29250b0 814->923 924 2921150 call 29250a0 814->924 815->816 827 2920dc7-2920e03 816->827 828 2920e8c-2920ec8 816->828 833 29212f3-29212fa 817->833 834 292121a-2921221 817->834 825 2921045 818->825 826 292104c-292107f 818->826 825->826 927 2921081 call 2921ef8 826->927 928 2921081 call 2921f08 826->928 827->793 859 2920e05-2920e3a 827->859 828->794 860 2920eca-2920eff 828->860 833->803 835 2921223-2921229 834->835 836 292123b-292126b 834->836 841 292122b 835->841 842 292122d-2921239 835->842 879 29212ce-29212f0 836->879 880 292126d-292129e 836->880 841->836 842->836 843->818 849 2920fc9-2921005 843->849 871 292133f-2921346 849->871 857 2921087-29210a2 857->814 881 29210a4-29210e1 857->881 859->871 860->871 862 2920bac-2920bae 869 2920bb0-2920bc1 862->869 870 2920bcc-2920bdf 862->870 866 2921156-2921171 866->817 889 2921173-29211ab 866->889 869->870 882 2920ca2-2920cc8 call 292014c 870->882 883 2920be5-2920c1b 870->883 879->833 880->871 881->871 898 2921325-2921337 882->898 899 2920cce-2920d0a 882->899 883->882 906 2920c21-2920c40 883->906 889->871 898->871 899->795 905 2920d0c-2920d36 899->905 925 2920d39 call 29214a0 905->925 926 2920d39 call 2921491 905->926 912 2920c42 906->912 913 2920c49-2920c98 906->913 909 2920d3f 909->871 912->913 913->882 923->866 924->866 925->909 926->909 927->857 928->857 929->862 930->862
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.4107496956.0000000002920000.00000040.00000800.00020000.00000000.sdmp, Offset: 02920000, based on PE: false
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_2920000_b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.jbxd
              Similarity
              • API ID:
              • String ID: doq
              • API String ID: 0-3318987180
              • Opcode ID: 42cf1a854eefdec5196a4375f19bcac2e8c605dcf5c1fa18aa0d1dc3aee17977
              • Instruction ID: d735a2c07eda6eb514dffd27b6c4f2c2a5d533976134515c2cf5942a6eaf20ef
              • Opcode Fuzzy Hash: 42cf1a854eefdec5196a4375f19bcac2e8c605dcf5c1fa18aa0d1dc3aee17977
              • Instruction Fuzzy Hash: 97423974A002598FCB15DFA8C584A9DBBF2FF89314F158569E405EB3AADB30AC49CF50

              Control-flow Graph

              • Executed
              • Not Executed
              control_flow_graph 992 2922320-292235a 993 2922387-292238d 992->993 994 292235c-292237f 992->994 995 2922396-29223b2 993->995 996 292238f 993->996 994->993 1073 29223b4 call 2922858 995->1073 1074 29223b4 call 292283d 995->1074 996->995 998 2922402-292241c 996->998 999 2922492-29224ac 996->999 1000 29226b2-29226cc 996->1000 1001 29225f9-2922613 996->1001 1002 292252f-2922549 996->1002 1007 2922423-2922433 998->1007 1004 29224b3-29224c3 999->1004 1005 29226d3-29226e3 1000->1005 1006 292261a-292262a 1001->1006 1003 2922550-2922560 1002->1003 1009 2922562 1003->1009 1010 2922567-2922590 1003->1010 1011 29224c5 1004->1011 1012 29224ca-29224d1 1004->1012 1013 29226e5 1005->1013 1014 29226ea-2922702 1005->1014 1015 2922631-2922638 1006->1015 1016 292262c 1006->1016 1017 2922435 1007->1017 1018 292243a-2922445 1007->1018 1009->1010 1041 2922596-29225ac 1010->1041 1042 29227dc-29227de 1010->1042 1011->1012 1020 29224d3-29224d5 1012->1020 1021 29224da-29224dd 1012->1021 1013->1014 1031 29227c7-29227d5 1014->1031 1022 2922641-2922648 1015->1022 1023 292263a-292263c 1015->1023 1016->1015 1017->1018 1069 2922447 call 2923c80 1018->1069 1070 2922447 call 2923c70 1018->1070 1019 29223ba-29223ca 1019->1007 1027 29223cc-29223fd 1019->1027 1024 2922804-2922817 1020->1024 1071 29224df call 2922858 1021->1071 1072 29224df call 292283d 1021->1072 1025 2922707-2922726 1022->1025 1026 292264e-2922651 1022->1026 1023->1024 1035 292281f-2922826 1024->1035 1067 2922728 call 2923c80 1025->1067 1068 2922728 call 2923c70 1025->1068 1063 2922653 call 2922858 1026->1063 1064 2922653 call 292283d 1026->1064 1027->1035 1030 292244d-292245d 1030->1004 1033 292245f-292248d 1030->1033 1031->1024 1032 29224e5-29224f5 1032->1003 1034 29224f7-292252a 1032->1034 1033->1035 1034->1035 1036 2922659-2922678 1036->1005 1043 292267a-29226ad 1036->1043 1065 29225ae call 2923c80 1041->1065 1066 29225ae call 2923c70 1041->1066 1042->1024 1043->1035 1046 292272e-292274d 1050 29227a3-29227b3 1046->1050 1051 292274f-292277d 1046->1051 1052 29227b5 1050->1052 1053 29227ba-29227c1 1050->1053 1051->1035 1052->1053 1053->1031 1057 29227c3-29227c5 1053->1057 1057->1024 1058 29225b4-29225c4 1058->1006 1059 29225c6-29225f4 1058->1059 1059->1035 1063->1036 1064->1036 1065->1058 1066->1058 1067->1046 1068->1046 1069->1030 1070->1030 1071->1032 1072->1032 1073->1019 1074->1019
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.4107496956.0000000002920000.00000040.00000800.00020000.00000000.sdmp, Offset: 02920000, based on PE: false
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_2920000_b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.jbxd
              Similarity
              • API ID:
              • String ID: P {
              • API String ID: 0-3249437620
              • Opcode ID: f1af22aed2f6c1ceca574f2bf1fcc16b21f1e9ffb111c67d4fccc7c4ac8be771
              • Instruction ID: b487a2052eb5a8cd6d266914597408645fbf942dd41695ed762b9d429bab68b0
              • Opcode Fuzzy Hash: f1af22aed2f6c1ceca574f2bf1fcc16b21f1e9ffb111c67d4fccc7c4ac8be771
              • Instruction Fuzzy Hash: 7502D3B4E012499FDB05CF68D484A9DBBF2BF49320F1985A5E805AB366DB34EC85CF50
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.4107496956.0000000002920000.00000040.00000800.00020000.00000000.sdmp, Offset: 02920000, based on PE: false
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_2920000_b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.jbxd
              Similarity
              • API ID:
              • String ID: \Vcm
              • API String ID: 0-3044874373
              • Opcode ID: 450ae150e70595728013c07edb867ca3b4181b256992652cf328e134936e8aca
              • Instruction ID: c6851367940a991462ce744cf8677abbf71fff5d34b0e14a2a76099c9add292d
              • Opcode Fuzzy Hash: 450ae150e70595728013c07edb867ca3b4181b256992652cf328e134936e8aca
              • Instruction Fuzzy Hash: C3B12F70E00229CFEB14CFA9D9857DDBBF6BF88314F248529D415E7298EB749849CB81
              Memory Dump Source
              • Source File: 00000000.00000002.4107496956.0000000002920000.00000040.00000800.00020000.00000000.sdmp, Offset: 02920000, based on PE: false
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_2920000_b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.jbxd
              Similarity
              • API ID:
              • String ID:
              • API String ID:
              • Opcode ID: 793923a787ac206325f3054d9ea36e4e982f44762ae3ca30e400d068baa55914
              • Instruction ID: 4520d304637d3011dc653c8e16bb395e0e3fab4e2084590293e9e260a23f55c5
              • Opcode Fuzzy Hash: 793923a787ac206325f3054d9ea36e4e982f44762ae3ca30e400d068baa55914
              • Instruction Fuzzy Hash: 27321970A002598FCB05DFA8C580A9DBBF6BF89310F2585A9E446AF369D734ED49CB50
              Memory Dump Source
              • Source File: 00000000.00000002.4107496956.0000000002920000.00000040.00000800.00020000.00000000.sdmp, Offset: 02920000, based on PE: false
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_2920000_b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.jbxd
              Similarity
              • API ID:
              • String ID:
              • API String ID:
              • Opcode ID: 5f99cb32462e808a2ce5e126344e020ce0b806abfff709c39e5a64fd4ae7d2c5
              • Instruction ID: 28fb516846a5168af6acc14ffab7dcca7e755af03b88b8f939073c67fc4ed15f
              • Opcode Fuzzy Hash: 5f99cb32462e808a2ce5e126344e020ce0b806abfff709c39e5a64fd4ae7d2c5
              • Instruction Fuzzy Hash: 8BB14270E00319CFEB14CFA9D98179DBBF6BF88314F249529D419E7258EB749849CB81

              Control-flow Graph

              • Executed
              • Not Executed
              control_flow_graph 931 55ef4e8-55ef4f7 932 55ef4f9-55ef506 call 55ee4d0 931->932 933 55ef523-55ef527 931->933 940 55ef51c 932->940 941 55ef508 932->941 934 55ef53b-55ef57c 933->934 935 55ef529-55ef533 933->935 942 55ef57e-55ef586 934->942 943 55ef589-55ef597 934->943 935->934 940->933 988 55ef50e call 55ef780 941->988 989 55ef50e call 55ef771 941->989 942->943 944 55ef5bb-55ef5bd 943->944 945 55ef599-55ef59e 943->945 947 55ef5c0-55ef5c7 944->947 948 55ef5a9 945->948 949 55ef5a0-55ef5a7 call 55ee4dc 945->949 946 55ef514-55ef516 946->940 950 55ef658-55ef718 946->950 951 55ef5c9-55ef5d1 947->951 952 55ef5d4-55ef5db 947->952 953 55ef5ab-55ef5b9 948->953 949->953 983 55ef71a-55ef71d 950->983 984 55ef720-55ef74b GetModuleHandleW 950->984 951->952 955 55ef5dd-55ef5e5 952->955 956 55ef5e8-55ef5f1 call 55e7b40 952->956 953->947 955->956 962 55ef5fe-55ef603 956->962 963 55ef5f3-55ef5fb 956->963 964 55ef605-55ef60c 962->964 965 55ef621-55ef625 962->965 963->962 964->965 967 55ef60e-55ef61e call 55ee34c call 55ee4ec 964->967 990 55ef628 call 55efe40 965->990 991 55ef628 call 55efe31 965->991 967->965 968 55ef62b-55ef62e 971 55ef630-55ef64e 968->971 972 55ef651-55ef657 968->972 971->972 983->984 985 55ef74d-55ef753 984->985 986 55ef754-55ef768 984->986 985->986 988->946 989->946 990->968 991->968
              Memory Dump Source
              • Source File: 00000000.00000002.4108832387.00000000055E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 055E0000, based on PE: false
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_55e0000_b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.jbxd
              Similarity
              • API ID: HandleModule
              • String ID:
              • API String ID: 4139908857-0
              • Opcode ID: 09b941c47b099d3790b45ff9231f3a89e8d93ea05cce1f6a76db23e2b80f8a7f
              • Instruction ID: 7214eafa35c5ab1f3515725cb47b8b5b67e14277c38807775a5ebf3845b14f8c
              • Opcode Fuzzy Hash: 09b941c47b099d3790b45ff9231f3a89e8d93ea05cce1f6a76db23e2b80f8a7f
              • Instruction Fuzzy Hash: 4D714670A00B058FD728DF29D545B5ABBF6FF88304F108A2ED48AD7A50DB74E946CB91

              Control-flow Graph

              • Executed
              • Not Executed
              control_flow_graph 1075 55ec7b9-55ec7c0 1076 55ec762 1075->1076 1077 55ec7c2-55ec814 1075->1077 1078 55ec764 1076->1078 1079 55ec7b0-55ec7b1 1076->1079 1085 55ec816-55ec83e KiUserCallbackDispatcher 1077->1085 1086 55ec862-55ec87b 1077->1086 1096 55ec764 call 55ec7c8 1078->1096 1097 55ec764 call 55ec7b9 1078->1097 1082 55ec76a-55ec77e 1083 55ec7a9 1082->1083 1084 55ec780-55ec793 call 55ec1a4 1082->1084 1083->1079 1084->1083 1091 55ec795-55ec7a2 call 55eade0 1084->1091 1088 55ec847-55ec85b 1085->1088 1089 55ec840-55ec846 1085->1089 1088->1086 1089->1088 1091->1083 1095 55ec7a4 1091->1095 1095->1083 1096->1082 1097->1082
              APIs
              • KiUserCallbackDispatcher.NTDLL(0000004B), ref: 055EC82D
              Memory Dump Source
              • Source File: 00000000.00000002.4108832387.00000000055E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 055E0000, based on PE: false
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_55e0000_b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.jbxd
              Similarity
              • API ID: CallbackDispatcherUser
              • String ID:
              • API String ID: 2492992576-0
              • Opcode ID: 5801bdbb2911c1f9d70a5e14e175ca00426135e422a5e10e396befd84bcb3f9b
              • Instruction ID: b23cb6bffcc9b7cb32264611f224a7b57bddf7ecbb82432236c9ae988e226fea
              • Opcode Fuzzy Hash: 5801bdbb2911c1f9d70a5e14e175ca00426135e422a5e10e396befd84bcb3f9b
              • Instruction Fuzzy Hash: F531F570908398CEEB14DFA9E6047EA7FF5FB55308F0480AAD58597282C778A948CB71

              Control-flow Graph

              • Executed
              • Not Executed
              control_flow_graph 1098 55e59f1-55e59f7 1100 55e59f8-55e5a8c DuplicateHandle 1098->1100 1101 55e5a8e-55e5a94 1100->1101 1102 55e5a95-55e5ab2 1100->1102 1101->1102
              APIs
              • DuplicateHandle.KERNELBASE(?,?,?,?,?,?,?,?,?,?,055E59BE,?,?,?,?,?), ref: 055E5A7F
              Memory Dump Source
              • Source File: 00000000.00000002.4108832387.00000000055E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 055E0000, based on PE: false
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_55e0000_b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.jbxd
              Similarity
              • API ID: DuplicateHandle
              • String ID:
              • API String ID: 3793708945-0
              • Opcode ID: 68e21cd947c0c02dbe2aa954a695cad67c876db5aa9300dd797d79729e72aea7
              • Instruction ID: fe28fc51d69f4565ece37d920859788ec25f97c7f77d2650299bc09675817a81
              • Opcode Fuzzy Hash: 68e21cd947c0c02dbe2aa954a695cad67c876db5aa9300dd797d79729e72aea7
              • Instruction Fuzzy Hash: 462126B5D00248DFDB10CF9AD985AEEBFF8FB48314F14801AE955A3210D374A941CFA1

              Control-flow Graph

              • Executed
              • Not Executed
              control_flow_graph 1105 55e537c-55e5a8c DuplicateHandle 1107 55e5a8e-55e5a94 1105->1107 1108 55e5a95-55e5ab2 1105->1108 1107->1108
              APIs
              • DuplicateHandle.KERNELBASE(?,?,?,?,?,?,?,?,?,?,055E59BE,?,?,?,?,?), ref: 055E5A7F
              Memory Dump Source
              • Source File: 00000000.00000002.4108832387.00000000055E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 055E0000, based on PE: false
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_55e0000_b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.jbxd
              Similarity
              • API ID: DuplicateHandle
              • String ID:
              • API String ID: 3793708945-0
              • Opcode ID: 55493d72b4bda853fd1febcb3eef781f16cd243ef8536a1728cb40760d173095
              • Instruction ID: 817b4d1349645e7bc8ccb3b21a4be1002784dbdfb17add84e1360052835372f5
              • Opcode Fuzzy Hash: 55493d72b4bda853fd1febcb3eef781f16cd243ef8536a1728cb40760d173095
              • Instruction Fuzzy Hash: F92116B5900219EFDB10CF9AD484ADEBFF4FB48310F14801AE915A7310D374A940CFA1

              Control-flow Graph

              • Executed
              • Not Executed
              control_flow_graph 1111 55e2389-55e238d 1112 55e23cf-55e23da 1111->1112 1113 55e238f-55e23cc 1111->1113 1116 55e23dc-55e23e4 1112->1116 1117 55e23e6-55e2418 SetWindowsHookExA 1112->1117 1113->1112 1116->1117 1118 55e241a-55e2420 1117->1118 1119 55e2421-55e2441 1117->1119 1118->1119
              APIs
              • SetWindowsHookExA.USER32(05153BA0,00000000,?,?,?,?,?,05153BA0,?,055E21FE,00000000,00000000), ref: 055E240B
              Memory Dump Source
              • Source File: 00000000.00000002.4108832387.00000000055E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 055E0000, based on PE: false
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_55e0000_b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.jbxd
              Similarity
              • API ID: HookWindows
              • String ID:
              • API String ID: 2559412058-0
              • Opcode ID: 093f4660df8543ba502468766f613a3b0b92ca63adae8c27fa01cf6e44dc2378
              • Instruction ID: 64fac100ea510df78f5e0684d30218525967dd48f9fa5caf12065141526c4905
              • Opcode Fuzzy Hash: 093f4660df8543ba502468766f613a3b0b92ca63adae8c27fa01cf6e44dc2378
              • Instruction Fuzzy Hash: A72147B5900209DFCB14CF9AD844BDEFBF9FB88320F10842AE459A7254C774A944CFA1

              Control-flow Graph

              • Executed
              • Not Executed
              control_flow_graph 1123 55e1d74-55e23da 1127 55e23dc-55e23e4 1123->1127 1128 55e23e6-55e2418 SetWindowsHookExA 1123->1128 1127->1128 1129 55e241a-55e2420 1128->1129 1130 55e2421-55e2441 1128->1130 1129->1130
              APIs
              • SetWindowsHookExA.USER32(05153BA0,00000000,?,?,?,?,?,05153BA0,?,055E21FE,00000000,00000000), ref: 055E240B
              Memory Dump Source
              • Source File: 00000000.00000002.4108832387.00000000055E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 055E0000, based on PE: false
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_55e0000_b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.jbxd
              Similarity
              • API ID: HookWindows
              • String ID:
              • API String ID: 2559412058-0
              • Opcode ID: 513f54f3cb9816e4be1dfcfbd73663c6737ecfb394e14adaf5cab46a02dba699
              • Instruction ID: 83af5fd463a47672e2169e626323941fa6f1967d1e9bef94501bd76e6248bd2c
              • Opcode Fuzzy Hash: 513f54f3cb9816e4be1dfcfbd73663c6737ecfb394e14adaf5cab46a02dba699
              • Instruction Fuzzy Hash: A02135B5904209CFCB14DF9AC944BEEBBF9FB88320F10842AE459A7254C774A944CFA1
              APIs
              • GetModuleHandleW.KERNELBASE(00000000,?,?,?,?,?,?,?,055EF504), ref: 055EF73E
              Memory Dump Source
              • Source File: 00000000.00000002.4108832387.00000000055E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 055E0000, based on PE: false
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_55e0000_b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.jbxd
              Similarity
              • API ID: HandleModule
              • String ID:
              • API String ID: 4139908857-0
              • Opcode ID: b46055f0c4a9c49c2d9fb98013de11d21ce2d88addd695a521efbc29aeed2a77
              • Instruction ID: 6556934a9110367203d8c7ef711e1e901170d6b0bcf1c8c16a23630e38dbfe89
              • Opcode Fuzzy Hash: b46055f0c4a9c49c2d9fb98013de11d21ce2d88addd695a521efbc29aeed2a77
              • Instruction Fuzzy Hash: 981120B5C00248CBDB14CF9AC444ADEFBF4FF88210F10842AD459A7210C775A945CFA1
              APIs
              • KiUserCallbackDispatcher.NTDLL(0000004B), ref: 055EC82D
              Memory Dump Source
              • Source File: 00000000.00000002.4108832387.00000000055E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 055E0000, based on PE: false
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_55e0000_b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.jbxd
              Similarity
              • API ID: CallbackDispatcherUser
              • String ID:
              • API String ID: 2492992576-0
              • Opcode ID: 2f61ae0fc5a6b549fa48a67fedca85ac44b81ebe7be20dd420094418bb451338
              • Instruction ID: 1959085fa3b216117f4b02d49615104368e4e2610b5528053e9922ea3966160b
              • Opcode Fuzzy Hash: 2f61ae0fc5a6b549fa48a67fedca85ac44b81ebe7be20dd420094418bb451338
              • Instruction Fuzzy Hash: A21182718043A8CEEB10DF99D6047EEBFF4EB05314F54806AD595A7242C379AA48CFB5
              Memory Dump Source
              • Source File: 00000000.00000002.4107254745.0000000000F9D000.00000040.00000800.00020000.00000000.sdmp, Offset: 00F9D000, based on PE: false
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_f9d000_b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.jbxd
              Similarity
              • API ID:
              • String ID:
              • API String ID:
              • Opcode ID: cc5790e7bbec39893919f74ccdd2fa9b5b947947ac1c9818273f44bc5254f832
              • Instruction ID: 8b4ae841f6ec79e415714fc9670063ae37443eb0b6ae4b08a8b1729f9530bcce
              • Opcode Fuzzy Hash: cc5790e7bbec39893919f74ccdd2fa9b5b947947ac1c9818273f44bc5254f832
              • Instruction Fuzzy Hash: 8A210372904204DFEF05DF14D9C0B2ABF66FB98324F34C169E9094B256C336D856EAA2
              Memory Dump Source
              • Source File: 00000000.00000002.4107284883.0000000000FAD000.00000040.00000800.00020000.00000000.sdmp, Offset: 00FAD000, based on PE: false
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_fad000_b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.jbxd
              Similarity
              • API ID:
              • String ID:
              • API String ID:
              • Opcode ID: ce139b1a059e226a7500f63f56e0e14e01fd04145333a2e9a86b897ac60b9525
              • Instruction ID: 2569e53ce3059f786ce580381cc467dc9a2296cda0190b84199b3bf17c2ad1d9
              • Opcode Fuzzy Hash: ce139b1a059e226a7500f63f56e0e14e01fd04145333a2e9a86b897ac60b9525
              • Instruction Fuzzy Hash: CA2146B1904200DFDB04DF14D9C0B26BBA5FB89328F24C56DEC0A4B696C336E846DB61
              Memory Dump Source
              • Source File: 00000000.00000002.4107254745.0000000000F9D000.00000040.00000800.00020000.00000000.sdmp, Offset: 00F9D000, based on PE: false
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_f9d000_b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.jbxd
              Similarity
              • API ID:
              • String ID:
              • API String ID:
              • Opcode ID: 201b50b495cf87aa99c5283e85c62261d36f592a674eeeb3b47fc5aac64b1fd2
              • Instruction ID: c6ffa3cbb4fcb69a6df5ea2b287ec491576a4bc7ef08cf75e3a6d390545f90ea
              • Opcode Fuzzy Hash: 201b50b495cf87aa99c5283e85c62261d36f592a674eeeb3b47fc5aac64b1fd2
              • Instruction Fuzzy Hash: 8B11E172804240CFDF06CF00D5C4B16BF72FB94324F24C2A9D8490B256C33AD85ADBA2
              Memory Dump Source
              • Source File: 00000000.00000002.4107284883.0000000000FAD000.00000040.00000800.00020000.00000000.sdmp, Offset: 00FAD000, based on PE: false
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_fad000_b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.jbxd
              Similarity
              • API ID:
              • String ID:
              • API String ID:
              • Opcode ID: 48042a67946fd5b471a152cae87ddc5a96e5ad52caa5f07da488830fbc7c129d
              • Instruction ID: e546e1ca0cbdfc8397b21af3521e5989f48e71802d4a032152d52bc0fb241b3a
              • Opcode Fuzzy Hash: 48042a67946fd5b471a152cae87ddc5a96e5ad52caa5f07da488830fbc7c129d
              • Instruction Fuzzy Hash: 7B11D0B5904280CFDB01CF14D5C4B15BF71FB45328F28C6A9D80A4B656C33AD80ADB61
              Memory Dump Source
              • Source File: 00000000.00000002.4107254745.0000000000F9D000.00000040.00000800.00020000.00000000.sdmp, Offset: 00F9D000, based on PE: false
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_f9d000_b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.jbxd
              Similarity
              • API ID:
              • String ID:
              • API String ID:
              • Opcode ID: 9845d283d040e5732ee48e5476fd08139c241469629fcf00aa02189cab3421b0
              • Instruction ID: 5d198ef03fd677ed68b6f491dad0ab6cffe713c3b70593a6bfac93673eaf822c
              • Opcode Fuzzy Hash: 9845d283d040e5732ee48e5476fd08139c241469629fcf00aa02189cab3421b0
              • Instruction Fuzzy Hash: 9401FC714093449AFB108A25CD84767BF98DF40334F28C515ED094F25AC2399C41D6B2
              Memory Dump Source
              • Source File: 00000000.00000002.4107254745.0000000000F9D000.00000040.00000800.00020000.00000000.sdmp, Offset: 00F9D000, based on PE: false
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_f9d000_b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.jbxd
              Similarity
              • API ID:
              • String ID:
              • API String ID:
              • Opcode ID: 2fecca1df4d1ac87e956f28bcda34aad98a5e535dda7e67789dadb9b912a6159
              • Instruction ID: e5bd162d0623156ea713ed8d62cf830e3814873e6f924cbd45274d44bbf3bbd4
              • Opcode Fuzzy Hash: 2fecca1df4d1ac87e956f28bcda34aad98a5e535dda7e67789dadb9b912a6159
              • Instruction Fuzzy Hash: A9F0C2714093449AEB108A16CC84BA2FFA8EB50334F28C55AED084F29AC2799C45DAB1
              Strings
              Memory Dump Source
              • Source File: 00000000.00000002.4107496956.0000000002920000.00000040.00000800.00020000.00000000.sdmp, Offset: 02920000, based on PE: false
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_2920000_b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.jbxd
              Similarity
              • API ID:
              • String ID: \Vcm
              • API String ID: 0-3044874373
              • Opcode ID: 856b6924f941b36c3422485d47b92c90ac3f83e1b29f571a8d721df8350c4c20
              • Instruction ID: fee78e17fbd8a3d441a7c9e1550488d72e6ca2f2b7826b93a50384b35bac16fc
              • Opcode Fuzzy Hash: 856b6924f941b36c3422485d47b92c90ac3f83e1b29f571a8d721df8350c4c20
              • Instruction Fuzzy Hash: E9916E70E00219DFDF10DFA9C9857EDBBF6BF88314F148529E405A7298DB349949CB91
              Memory Dump Source
              • Source File: 00000000.00000002.4108832387.00000000055E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 055E0000, based on PE: false
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_55e0000_b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.jbxd
              Similarity
              • API ID:
              • String ID:
              • API String ID:
              • Opcode ID: 4b5e04a894750031384796dd9805891ee341f1428beec5005449e403ca9bbcee
              • Instruction ID: f0a18ae2a201fe38bfea218f00a4707da58ef9b641e0416af9f9557e5b6c7d95
              • Opcode Fuzzy Hash: 4b5e04a894750031384796dd9805891ee341f1428beec5005449e403ca9bbcee
              • Instruction Fuzzy Hash: A31290B44017668AF714DFA5EA882C93FA2B75A358F50430DD361AF2E5D7B8118ECF48
              Memory Dump Source
              • Source File: 00000000.00000002.4108832387.00000000055E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 055E0000, based on PE: false
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_55e0000_b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.jbxd
              Similarity
              • API ID:
              • String ID:
              • API String ID:
              • Opcode ID: 75a489ac4908a771d022b1ea301af7b8f8051b257cb2e60fd0a3304077032911
              • Instruction ID: 240f072288e51edf7d97afb41479eb71fcb5c606c2f9f6a4655b5460fa0d518d
              • Opcode Fuzzy Hash: 75a489ac4908a771d022b1ea301af7b8f8051b257cb2e60fd0a3304077032911
              • Instruction Fuzzy Hash: B7A1A132F1021ACFCF19DFB4C9449AEB7B6FF88300B15456AE906AB255DB31E945CB80
              Memory Dump Source
              • Source File: 00000000.00000002.4108832387.00000000055E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 055E0000, based on PE: false
              Joe Sandbox IDA Plugin
              • Snapshot File: hcaresult_0_2_55e0000_b1593574e46fb1f30b1da4fa594f43bb52b051a616db3.jbxd
              Similarity
              • API ID:
              • String ID:
              • API String ID:
              • Opcode ID: a62724165c62d07a2d09001ca25de9a7e070a9d53c274f7f9d0f7e13a1fd80db
              • Instruction ID: b5a53986d66f4ce1b1173e10a3af8c3207d1efc6dea33ee9c873cac15582b738
              • Opcode Fuzzy Hash: a62724165c62d07a2d09001ca25de9a7e070a9d53c274f7f9d0f7e13a1fd80db
              • Instruction Fuzzy Hash: E3C105B08017668BF714DFA5EA481C97BB2BB9A314F14430DE361AB2E5D7B4148ECF84