Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
0DrqlQ4JfZ.exe

Overview

General Information

Sample name:0DrqlQ4JfZ.exe
renamed because original name is a hash value
Original sample name:de3f0f8cbac7723e54298baec915e2ba.exe
Analysis ID:1583300
MD5:de3f0f8cbac7723e54298baec915e2ba
SHA1:0bc6ae31882e2856b2ea52c56985409a58920b36
SHA256:6e797fb47dd3d5bb42fb578ea9dcd64a11af9e82902bffd1aa5ea3226498f1f0
Tags:exeValleyRATuser-abuse_ch
Infos:

Detection

GhostRat
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Yara detected GhostRat
AI detected suspicious sample
Contains functionality to capture and log keystrokes
Contains functionality to inject code into remote processes
Contains functionality to inject threads in other processes
Found evasive API chain (may stop execution after checking mutex)
Found stalling execution ending in API Sleep call
Sample is not signed and drops a device driver
Sigma detected: Potentially Suspicious Malware Callback Communication
Tries to detect sandboxes / dynamic malware analysis system (QueryWinSAT)
AV process strings found (often used to terminate AV products)
Checks for available system drives (often done to infect USB drives)
Contains functionality for read data from the clipboard
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to check if a debugger is running (OutputDebugString,GetLastError)
Contains functionality to check the parent process ID (often done to detect debuggers and analysis systems)
Contains functionality to clear windows event logs (to hide its activities)
Contains functionality to communicate with device drivers
Contains functionality to dynamically determine API calls
Contains functionality to enumerate process and check for explorer.exe or svchost.exe (often used for thread injection)
Contains functionality to modify clipboard data
Contains functionality to query CPU information (cpuid)
Contains functionality to query locales information (e.g. system language)
Contains functionality to read the clipboard data
Contains functionality to record screenshots
Contains functionality to shutdown / reboot the system
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Creates a DirectInput object (often for capturing keystrokes)
Creates driver files
Detected TCP or UDP traffic on non-standard ports
Detected potential crypto function
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found evasive API chain checking for process token information
Installs a global mouse hook
Internet Provider seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
Queries the volume information (name, serial number etc) of a device
Sigma detected: Execution of Suspicious File Type Extension
Spawns drivers
Stores large binary data to the registry
Uses code obfuscation techniques (call, push, ret)

Classification

  • System is w10x64
  • 0DrqlQ4JfZ.exe (PID: 2564 cmdline: "C:\Users\user\Desktop\0DrqlQ4JfZ.exe" MD5: DE3F0F8CBAC7723E54298BAEC915E2BA)
  • LogonUI.exe (PID: 5824 cmdline: "LogonUI.exe" /flags:0x4 /state0:0xa3f52855 /state1:0x41c64e6d MD5: 893144FE49AA16124B5BD3034E79BBC6)
  • cdd.dll (PID: 4 cmdline: MD5: 9B684213A399B4E286982BDAD6CF3D07)
  • LogonUI.exe (PID: 3744 cmdline: "LogonUI.exe" /flags:0x2 /state0:0xa3f5c855 /state1:0x41c64e6d MD5: 893144FE49AA16124B5BD3034E79BBC6)
  • fontdrvhost.exe (PID: 5596 cmdline: "fontdrvhost.exe" MD5: BBCB897697B3442657C7D6E3EDDBD25F)
  • cdd.dll (PID: 4 cmdline: MD5: 9B684213A399B4E286982BDAD6CF3D07)
  • LogonUI.exe (PID: 2720 cmdline: "LogonUI.exe" /flags:0x2 /state0:0xa3f64055 /state1:0x41c64e6d MD5: 893144FE49AA16124B5BD3034E79BBC6)
  • fontdrvhost.exe (PID: 6240 cmdline: "fontdrvhost.exe" MD5: BBCB897697B3442657C7D6E3EDDBD25F)
  • cdd.dll (PID: 4 cmdline: MD5: 9B684213A399B4E286982BDAD6CF3D07)
  • LogonUI.exe (PID: 7076 cmdline: "LogonUI.exe" /flags:0x2 /state0:0xa3f6b855 /state1:0x41c64e6d MD5: 893144FE49AA16124B5BD3034E79BBC6)
  • fontdrvhost.exe (PID: 5088 cmdline: "fontdrvhost.exe" MD5: BBCB897697B3442657C7D6E3EDDBD25F)
  • cdd.dll (PID: 4 cmdline: MD5: 9B684213A399B4E286982BDAD6CF3D07)
  • LogonUI.exe (PID: 2496 cmdline: "LogonUI.exe" /flags:0x2 /state0:0xa3f7b055 /state1:0x41c64e6d MD5: 893144FE49AA16124B5BD3034E79BBC6)
  • fontdrvhost.exe (PID: 6328 cmdline: "fontdrvhost.exe" MD5: BBCB897697B3442657C7D6E3EDDBD25F)
  • cdd.dll (PID: 4 cmdline: MD5: 9B684213A399B4E286982BDAD6CF3D07)
  • LogonUI.exe (PID: 5816 cmdline: "LogonUI.exe" /flags:0x2 /state0:0xa3f02855 /state1:0x41c64e6d MD5: 893144FE49AA16124B5BD3034E79BBC6)
  • fontdrvhost.exe (PID: 3548 cmdline: "fontdrvhost.exe" MD5: BBCB897697B3442657C7D6E3EDDBD25F)
  • cleanup
No configs have been found
SourceRuleDescriptionAuthorStrings
Process Memory Space: 0DrqlQ4JfZ.exe PID: 2564JoeSecurity_GhostRatYara detected GhostRatJoe Security

    System Summary

    barindex
    Source: Network ConnectionAuthor: Florian Roth (Nextron Systems): Data: DestinationIp: 23.226.57.67, DestinationIsIpv6: false, DestinationPort: 4433, EventID: 3, Image: C:\Users\user\Desktop\0DrqlQ4JfZ.exe, Initiated: true, ProcessId: 2564, Protocol: tcp, SourceIp: 192.168.2.4, SourceIsIpv6: false, SourcePort: 49730
    Source: Process startedAuthor: Max Altgelt (Nextron Systems): Data: Command: , CommandLine: , CommandLine|base64offset|contains: , Image: C:\Windows\System32\cdd.dll, NewProcessName: C:\Windows\System32\cdd.dll, OriginalFileName: C:\Windows\System32\cdd.dll, ParentCommandLine: , ParentImage: , ParentProcessId: -1, ProcessCommandLine: , ProcessId: 4, ProcessName: cdd.dll
    TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
    2025-01-02T12:07:04.869764+010020528751A Network Trojan was detected192.168.2.44973023.226.57.674433TCP
    2025-01-02T12:08:08.084808+010020528751A Network Trojan was detected192.168.2.44973023.226.57.674433TCP
    2025-01-02T12:09:12.069235+010020528751A Network Trojan was detected192.168.2.44973023.226.57.674433TCP
    2025-01-02T12:10:18.743756+010020528751A Network Trojan was detected192.168.2.45000623.226.57.6710443TCP

    Click to jump to signature section

    Show All Signature Results

    AV Detection

    barindex
    Source: 0DrqlQ4JfZ.exeVirustotal: Detection: 65%Perma Link
    Source: 0DrqlQ4JfZ.exeReversingLabs: Detection: 52%
    Source: Submited SampleIntegrated Neural Analysis Model: Matched 100.0% probability
    Source: 0DrqlQ4JfZ.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeFile opened: z:Jump to behavior
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeFile opened: x:Jump to behavior
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeFile opened: v:Jump to behavior
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeFile opened: t:Jump to behavior
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeFile opened: r:Jump to behavior
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeFile opened: p:Jump to behavior
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeFile opened: n:Jump to behavior
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeFile opened: l:Jump to behavior
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeFile opened: j:Jump to behavior
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeFile opened: h:Jump to behavior
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeFile opened: f:Jump to behavior
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeFile opened: b:Jump to behavior
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeFile opened: y:Jump to behavior
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeFile opened: w:Jump to behavior
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeFile opened: u:Jump to behavior
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeFile opened: s:Jump to behavior
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeFile opened: q:Jump to behavior
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeFile opened: o:Jump to behavior
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeFile opened: m:Jump to behavior
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeFile opened: k:Jump to behavior
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeFile opened: i:Jump to behavior
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeFile opened: g:Jump to behavior
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeFile opened: e:Jump to behavior
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeFile opened: [:Jump to behavior
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600ACF410 GetLastInputInfo,GetTickCount,wsprintfW,GetForegroundWindow,GetWindowTextW,CreateToolhelp32Snapshot,Process32FirstW,Process32NextW,CreateToolhelp32Snapshot,Process32FirstW,Process32NextW,CreateToolhelp32Snapshot,Process32FirstW,Process32NextW,RegOpenKeyExW,RegQueryValueExW,RegQueryValueExW,RegCloseKey,RegOpenKeyExW,RegQueryValueExW,RegQueryValueExW,RegCloseKey,RegOpenKeyExW,RegQueryValueExW,RegQueryValueExW,RegCloseKey,SHGetFolderPathW,lstrcatW,CreateFileW,lstrlenW,WriteFile,CloseHandle,FindFirstFileW,FindClose,_invalid_parameter_noinfo_noreturn,0_2_00007FF600ACF410
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600AF4190 _invalid_parameter_noinfo,FindFirstFileExW,FindNextFileW,FindClose,FindClose,0_2_00007FF600AF4190
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600AC6370 gethostname,gethostbyname,inet_ntoa,inet_ntoa,MultiByteToWideChar,MultiByteToWideChar,GetLastInputInfo,GetTickCount,wsprintfW,MultiByteToWideChar,MultiByteToWideChar,LoadLibraryW,GetProcAddress,RegOpenKeyExW,RegQueryValueExW,RegCloseKey,FreeLibrary,GetSystemInfo,wsprintfW,GetDriveTypeW,GetDiskFreeSpaceExW,GlobalMemoryStatusEx,GetForegroundWindow,GetWindowTextW,lstrlenW,GetLocalTime,wsprintfW,lstrlenW,GetModuleHandleW,GetProcAddress,GetNativeSystemInfo,GetSystemInfo,wsprintfW,GetCurrentProcessId,OpenProcess,K32GetProcessImageFileNameW,GetLogicalDriveStringsW,lstrcmpiW,lstrcmpiW,QueryDosDeviceW,lstrlenW,lstrcpyW,CloseHandle,CoInitializeEx,CoCreateInstance,SysFreeString,CoUninitialize,RegOpenKeyExW,RegQueryInfoKeyW,RegEnumKeyExW,lstrlenW,lstrlenW,RegCloseKey,lstrlenW,GetTickCount,wsprintfW,GetLocaleInfoW,GetSystemDirectoryW,GetCurrentHwProfileW,lstrcpyW,lstrcatW,lstrlenW,GetLocalTime,wsprintfW,RegOpenKeyExW,RegDeleteValueW,RegCloseKey,RegCreateKeyW,lstrlenW,RegSetValueExW,RegCloseKey,RegCloseKey,CreateToolhelp32Snapshot,Process32FirstW,Process32NextW,CreateToolhelp32Snapshot,Process32FirstW,Process32NextW,CreateToolhelp32Snapshot,Process32FirstW,Process32NextW,0_2_00007FF600AC6370

    Networking

    barindex
    Source: Network trafficSuricata IDS: 2052875 - Severity 1 - ET MALWARE Anonymous RAT CnC Checkin : 192.168.2.4:49730 -> 23.226.57.67:4433
    Source: Network trafficSuricata IDS: 2052875 - Severity 1 - ET MALWARE Anonymous RAT CnC Checkin : 192.168.2.4:50006 -> 23.226.57.67:10443
    Source: global trafficTCP traffic: 192.168.2.4:49730 -> 23.226.57.67:4433
    Source: Joe Sandbox ViewASN Name: XIAOZHIYUN1-AS-APICIDCNETWORKUS XIAOZHIYUN1-AS-APICIDCNETWORKUS
    Source: unknownTCP traffic detected without corresponding DNS query: 23.226.57.67
    Source: unknownTCP traffic detected without corresponding DNS query: 23.226.57.67
    Source: unknownTCP traffic detected without corresponding DNS query: 23.226.57.67
    Source: unknownTCP traffic detected without corresponding DNS query: 23.226.57.67
    Source: unknownTCP traffic detected without corresponding DNS query: 23.226.57.67
    Source: unknownTCP traffic detected without corresponding DNS query: 23.226.57.67
    Source: unknownTCP traffic detected without corresponding DNS query: 23.226.57.67
    Source: unknownTCP traffic detected without corresponding DNS query: 23.226.57.67
    Source: unknownTCP traffic detected without corresponding DNS query: 23.226.57.67
    Source: unknownTCP traffic detected without corresponding DNS query: 23.226.57.67
    Source: unknownTCP traffic detected without corresponding DNS query: 23.226.57.67
    Source: unknownTCP traffic detected without corresponding DNS query: 23.226.57.67
    Source: unknownTCP traffic detected without corresponding DNS query: 23.226.57.67
    Source: unknownTCP traffic detected without corresponding DNS query: 23.226.57.67
    Source: unknownTCP traffic detected without corresponding DNS query: 23.226.57.67
    Source: unknownTCP traffic detected without corresponding DNS query: 23.226.57.67
    Source: unknownTCP traffic detected without corresponding DNS query: 23.226.57.67
    Source: unknownTCP traffic detected without corresponding DNS query: 23.226.57.67
    Source: unknownTCP traffic detected without corresponding DNS query: 23.226.57.67
    Source: unknownTCP traffic detected without corresponding DNS query: 23.226.57.67
    Source: unknownTCP traffic detected without corresponding DNS query: 23.226.57.67
    Source: unknownTCP traffic detected without corresponding DNS query: 23.226.57.67
    Source: unknownTCP traffic detected without corresponding DNS query: 23.226.57.67
    Source: unknownTCP traffic detected without corresponding DNS query: 23.226.57.67
    Source: unknownTCP traffic detected without corresponding DNS query: 23.226.57.67
    Source: unknownTCP traffic detected without corresponding DNS query: 23.226.57.67
    Source: unknownTCP traffic detected without corresponding DNS query: 23.226.57.67
    Source: unknownTCP traffic detected without corresponding DNS query: 23.226.57.67
    Source: unknownTCP traffic detected without corresponding DNS query: 23.226.57.67
    Source: unknownTCP traffic detected without corresponding DNS query: 23.226.57.67
    Source: unknownTCP traffic detected without corresponding DNS query: 23.226.57.67
    Source: unknownTCP traffic detected without corresponding DNS query: 23.226.57.67
    Source: unknownTCP traffic detected without corresponding DNS query: 23.226.57.67
    Source: unknownTCP traffic detected without corresponding DNS query: 23.226.57.67
    Source: unknownTCP traffic detected without corresponding DNS query: 23.226.57.67
    Source: unknownTCP traffic detected without corresponding DNS query: 23.226.57.67
    Source: unknownTCP traffic detected without corresponding DNS query: 23.226.57.67
    Source: unknownTCP traffic detected without corresponding DNS query: 23.226.57.67
    Source: unknownTCP traffic detected without corresponding DNS query: 23.226.57.67
    Source: unknownTCP traffic detected without corresponding DNS query: 23.226.57.67
    Source: unknownTCP traffic detected without corresponding DNS query: 23.226.57.67
    Source: unknownTCP traffic detected without corresponding DNS query: 23.226.57.67
    Source: unknownTCP traffic detected without corresponding DNS query: 23.226.57.67
    Source: unknownTCP traffic detected without corresponding DNS query: 23.226.57.67
    Source: unknownTCP traffic detected without corresponding DNS query: 23.226.57.67
    Source: unknownTCP traffic detected without corresponding DNS query: 23.226.57.67
    Source: unknownTCP traffic detected without corresponding DNS query: 23.226.57.67
    Source: unknownTCP traffic detected without corresponding DNS query: 23.226.57.67
    Source: unknownTCP traffic detected without corresponding DNS query: 23.226.57.67
    Source: unknownTCP traffic detected without corresponding DNS query: 23.226.57.67
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600AC3B00 select,recv,timeGetTime,0_2_00007FF600AC3B00
    Source: global trafficDNS traffic detected: DNS query: api.msn.com
    Source: global trafficDNS traffic detected: DNS query: tse1.mm.bing.net

    Key, Mouse, Clipboard, Microphone and Screen Capturing

    barindex
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: [esc]0_2_00007FF600ACADB0
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600ACADB0 Sleep,GetTickCount,GetTickCount,OpenClipboard,GetClipboardData,GlobalSize,GlobalLock,wsprintfW,WaitForSingleObject,CreateFileW,SetFilePointer,lstrlenW,WriteFile,CloseHandle,ReleaseMutex,GlobalUnlock,CloseClipboard,GetForegroundWindow,GetWindowTextW,lstrlenW,GetLocalTime,wsprintfW,GetKeyState,lstrlenW,lstrlenW,lstrlenW,wsprintfW,wsprintfW,wsprintfW,lstrlenW,0_2_00007FF600ACADB0
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600AD0DA0 _invalid_parameter_noinfo_noreturn,lstrlenW,Sleep,OpenClipboard,GetClipboardData,GlobalLock,GlobalUnlock,CloseClipboard,CloseClipboard,OpenClipboard,EmptyClipboard,GlobalAlloc,GlobalLock,GlobalUnlock,SetClipboardData,CloseClipboard,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,0_2_00007FF600AD0DA0
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600ACADB0 Sleep,GetTickCount,GetTickCount,OpenClipboard,GetClipboardData,GlobalSize,GlobalLock,wsprintfW,WaitForSingleObject,CreateFileW,SetFilePointer,lstrlenW,WriteFile,CloseHandle,ReleaseMutex,GlobalUnlock,CloseClipboard,GetForegroundWindow,GetWindowTextW,lstrlenW,GetLocalTime,wsprintfW,GetKeyState,lstrlenW,lstrlenW,lstrlenW,wsprintfW,wsprintfW,wsprintfW,lstrlenW,0_2_00007FF600ACADB0
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600ACFD10 GetDesktopWindow,GetDC,CreateCompatibleDC,GetDC,GetDeviceCaps,GetDeviceCaps,ReleaseDC,GetSystemMetrics,GetSystemMetrics,GetSystemMetrics,GetSystemMetrics,GetSystemMetrics,CreateCompatibleBitmap,SelectObject,SetStretchBltMode,GetSystemMetrics,GetSystemMetrics,StretchBlt,GetDIBits,DeleteObject,DeleteObject,ReleaseDC,DeleteObject,DeleteObject,ReleaseDC,_invalid_parameter_noinfo_noreturn,0_2_00007FF600ACFD10
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600AC72D0 MultiByteToWideChar,MultiByteToWideChar,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,CreateMutexExW,GetLastError,Sleep,CreateMutexW,GetLastError,lstrlenW,lstrcmpW,SleepEx,GetModuleHandleW,GetConsoleWindow,SHGetFolderPathW,lstrcatW,CreateMutexW,WaitForSingleObject,CreateFileW,GetFileSize,CloseHandle,DeleteFileW,ReleaseMutex,DirectInput8Create,GetTickCount,GetKeyState,0_2_00007FF600AC72D0
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeWindows user hook set: 0 mouse low level C:\Windows\SYSTEM32\DINPUT8.dllJump to behavior
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600ADC2D0: CreateFileA,DeviceIoControl,0_2_00007FF600ADC2D0
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600ACE3E9 GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueW,AdjustTokenPrivileges,GetLastError,CloseHandle,ExitWindowsEx,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueW,AdjustTokenPrivileges,GetLastError,CloseHandle,CloseHandle,0_2_00007FF600ACE3E9
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600ACE4EE GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueW,AdjustTokenPrivileges,GetLastError,CloseHandle,ExitWindowsEx,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueW,AdjustTokenPrivileges,GetLastError,CloseHandle,0_2_00007FF600ACE4EE
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600ACE46D GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueW,AdjustTokenPrivileges,GetLastError,CloseHandle,ExitWindowsEx,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueW,AdjustTokenPrivileges,GetLastError,CloseHandle,0_2_00007FF600ACE46D
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeFile created: C:\ProgramData\kernelquick.sysJump to behavior
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_3_00000001800010000_3_0000000180001000
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600AC72D00_2_00007FF600AC72D0
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600AC7A600_2_00007FF600AC7A60
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600ACB4100_2_00007FF600ACB410
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600ACF4100_2_00007FF600ACF410
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600AC63700_2_00007FF600AC6370
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600ACFD100_2_00007FF600ACFD10
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600AC15000_2_00007FF600AC1500
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600ADB5E00_2_00007FF600ADB5E0
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600ACCD400_2_00007FF600ACCD40
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600ADAE600_2_00007FF600ADAE60
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600AE8EB00_2_00007FF600AE8EB0
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600ADA6800_2_00007FF600ADA680
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600AC80C00_2_00007FF600AC80C0
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600AF20480_2_00007FF600AF2048
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600AF29E40_2_00007FF600AF29E4
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600AE71DC0_2_00007FF600AE71DC
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600AD79D00_2_00007FF600AD79D0
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600AE5A1C0_2_00007FF600AE5A1C
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600AF3A000_2_00007FF600AF3A00
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600AE51FC0_2_00007FF600AE51FC
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600AEF9500_2_00007FF600AEF950
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600AF41900_2_00007FF600AF4190
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600AF22C40_2_00007FF600AF22C4
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600AD93300_2_00007FF600AD9330
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600AF73EC0_2_00007FF600AF73EC
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600ACD4100_2_00007FF600ACD410
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600AE54080_2_00007FF600AE5408
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600AE64C80_2_00007FF600AE64C8
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600AEF4BC0_2_00007FF600AEF4BC
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600AC94800_2_00007FF600AC9480
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600AEB5F00_2_00007FF600AEB5F0
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600AE75E00_2_00007FF600AE75E0
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600AED5C00_2_00007FF600AED5C0
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600AE560C0_2_00007FF600AE560C
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600ACADB00_2_00007FF600ACADB0
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600AEAF200_2_00007FF600AEAF20
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600AC2E500_2_00007FF600AC2E50
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600AF5FD40_2_00007FF600AF5FD4
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600AEFFD00_2_00007FF600AEFFD0
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600AEC7BC0_2_00007FF600AEC7BC
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600AF88240_2_00007FF600AF8824
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600AE58180_2_00007FF600AE5818
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600AE4FF80_2_00007FF600AE4FF8
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600AD2FA00_2_00007FF600AD2FA0
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600AEA7980_2_00007FF600AEA798
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600AC99000_2_00007FF600AC9900
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600AE684C0_2_00007FF600AE684C
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600AD08800_2_00007FF600AD0880
    Source: unknownDriver loaded: C:\Windows\System32\cdd.dll
    Source: classification engineClassification label: mal100.troj.spyw.evad.winEXE@12/1@2/1
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600ACE3E9 GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueW,AdjustTokenPrivileges,GetLastError,CloseHandle,ExitWindowsEx,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueW,AdjustTokenPrivileges,GetLastError,CloseHandle,CloseHandle,0_2_00007FF600ACE3E9
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600ADB5E0 SleepEx,CloseHandle,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueW,AdjustTokenPrivileges,CloseHandle,GetModuleHandleA,GetProcAddress,GetCurrentProcessId,OpenProcess,GetLocalTime,wsprintfW,SetUnhandledExceptionFilter,CloseHandle,AllocateAndInitializeSid,CheckTokenMembership,FreeSid,RegOpenKeyExW,RegDeleteValueW,RegSetValueExW,RegCloseKey,SleepEx,CreateEventA,Sleep,Sleep,CloseHandle,_invalid_parameter_noinfo_noreturn,IsDebuggerPresent,LoadLibraryW,GetProcAddress,FreeLibrary,GetLocalTime,wsprintfW,CreateFileW,FreeLibrary,GetCurrentThreadId,GetCurrentProcessId,GetCurrentProcess,CloseHandle,FreeLibrary,0_2_00007FF600ADB5E0
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600ACE4EE GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueW,AdjustTokenPrivileges,GetLastError,CloseHandle,ExitWindowsEx,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueW,AdjustTokenPrivileges,GetLastError,CloseHandle,0_2_00007FF600ACE4EE
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600ACE46D GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueW,AdjustTokenPrivileges,GetLastError,CloseHandle,ExitWindowsEx,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueW,AdjustTokenPrivileges,GetLastError,CloseHandle,0_2_00007FF600ACE46D
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600AC9480 GetSystemDirectoryA,CreateProcessA,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueW,AdjustTokenPrivileges,OpenProcess,LoadLibraryA,GetProcAddress,LoadLibraryA,GetProcAddress,LoadLibraryA,GetProcAddress,LoadLibraryA,GetProcAddress,GetCurrentProcess,GetProcessId,GetModuleFileNameA,VirtualAllocEx,WriteProcessMemory,VirtualProtectEx,VirtualAllocEx,WriteProcessMemory,VirtualProtectEx,CreateRemoteThread,Sleep,VirtualProtectEx,VirtualProtectEx,ResumeThread,0_2_00007FF600AC9480
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600AC6370 gethostname,gethostbyname,inet_ntoa,inet_ntoa,MultiByteToWideChar,MultiByteToWideChar,GetLastInputInfo,GetTickCount,wsprintfW,MultiByteToWideChar,MultiByteToWideChar,LoadLibraryW,GetProcAddress,RegOpenKeyExW,RegQueryValueExW,RegCloseKey,FreeLibrary,GetSystemInfo,wsprintfW,GetDriveTypeW,GetDiskFreeSpaceExW,GlobalMemoryStatusEx,GetForegroundWindow,GetWindowTextW,lstrlenW,GetLocalTime,wsprintfW,lstrlenW,GetModuleHandleW,GetProcAddress,GetNativeSystemInfo,GetSystemInfo,wsprintfW,GetCurrentProcessId,OpenProcess,K32GetProcessImageFileNameW,GetLogicalDriveStringsW,lstrcmpiW,lstrcmpiW,QueryDosDeviceW,lstrlenW,lstrcpyW,CloseHandle,CoInitializeEx,CoCreateInstance,SysFreeString,CoUninitialize,RegOpenKeyExW,RegQueryInfoKeyW,RegEnumKeyExW,lstrlenW,lstrlenW,RegCloseKey,lstrlenW,GetTickCount,wsprintfW,GetLocaleInfoW,GetSystemDirectoryW,GetCurrentHwProfileW,lstrcpyW,lstrcatW,lstrlenW,GetLocalTime,wsprintfW,RegOpenKeyExW,RegDeleteValueW,RegCloseKey,RegCreateKeyW,lstrlenW,RegSetValueExW,RegCloseKey,RegCloseKey,CreateToolhelp32Snapshot,Process32FirstW,Process32NextW,CreateToolhelp32Snapshot,Process32FirstW,Process32NextW,CreateToolhelp32Snapshot,Process32FirstW,Process32NextW,0_2_00007FF600AC6370
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600AC7A60 CreateToolhelp32Snapshot,Process32FirstW,Process32NextW,CloseHandle,CoCreateInstance,wsprintfW,RegOpenKeyExW,RegQueryValueExW,lstrcatW,lstrcatW,RegCloseKey,lstrlenW,lstrcatW,CloseHandle,lstrcatW,lstrcatW,0_2_00007FF600AC7A60
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600AC7A60 CreateToolhelp32Snapshot,Process32FirstW,Process32NextW,CloseHandle,CoCreateInstance,wsprintfW,RegOpenKeyExW,RegQueryValueExW,lstrcatW,lstrcatW,RegCloseKey,lstrlenW,lstrcatW,CloseHandle,lstrcatW,lstrcatW,0_2_00007FF600AC7A60
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeMutant created: \Sessions\1\BaseNamedObjects\????
    Source: 0DrqlQ4JfZ.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
    Source: 0DrqlQ4JfZ.exeVirustotal: Detection: 65%
    Source: 0DrqlQ4JfZ.exeReversingLabs: Detection: 52%
    Source: unknownProcess created: C:\Users\user\Desktop\0DrqlQ4JfZ.exe "C:\Users\user\Desktop\0DrqlQ4JfZ.exe"
    Source: unknownProcess created: C:\Windows\System32\LogonUI.exe "LogonUI.exe" /flags:0x4 /state0:0xa3f52855 /state1:0x41c64e6d
    Source: unknownProcess created: C:\Windows\System32\LogonUI.exe "LogonUI.exe" /flags:0x2 /state0:0xa3f5c855 /state1:0x41c64e6d
    Source: unknownProcess created: C:\Windows\System32\fontdrvhost.exe "fontdrvhost.exe"
    Source: unknownProcess created: C:\Windows\System32\LogonUI.exe "LogonUI.exe" /flags:0x2 /state0:0xa3f64055 /state1:0x41c64e6d
    Source: unknownProcess created: C:\Windows\System32\fontdrvhost.exe "fontdrvhost.exe"
    Source: unknownProcess created: C:\Windows\System32\LogonUI.exe "LogonUI.exe" /flags:0x2 /state0:0xa3f6b855 /state1:0x41c64e6d
    Source: unknownProcess created: C:\Windows\System32\fontdrvhost.exe "fontdrvhost.exe"
    Source: unknownProcess created: C:\Windows\System32\LogonUI.exe "LogonUI.exe" /flags:0x2 /state0:0xa3f7b055 /state1:0x41c64e6d
    Source: unknownProcess created: C:\Windows\System32\fontdrvhost.exe "fontdrvhost.exe"
    Source: unknownProcess created: C:\Windows\System32\LogonUI.exe "LogonUI.exe" /flags:0x2 /state0:0xa3f02855 /state1:0x41c64e6d
    Source: unknownProcess created: C:\Windows\System32\fontdrvhost.exe "fontdrvhost.exe"
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeSection loaded: apphelp.dllJump to behavior
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeSection loaded: winmm.dllJump to behavior
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeSection loaded: dxgi.dllJump to behavior
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeSection loaded: dinput8.dllJump to behavior
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeSection loaded: inputhost.dllJump to behavior
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeSection loaded: coremessaging.dllJump to behavior
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeSection loaded: propsys.dllJump to behavior
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeSection loaded: wintypes.dllJump to behavior
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeSection loaded: coreuicomponents.dllJump to behavior
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeSection loaded: ntmarta.dllJump to behavior
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeSection loaded: kernel.appcore.dllJump to behavior
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeSection loaded: kernel.appcore.dllJump to behavior
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeSection loaded: mswsock.dllJump to behavior
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeSection loaded: napinsp.dllJump to behavior
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeSection loaded: pnrpnsp.dllJump to behavior
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeSection loaded: wshbth.dllJump to behavior
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeSection loaded: nlaapi.dllJump to behavior
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeSection loaded: iphlpapi.dllJump to behavior
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeSection loaded: dnsapi.dllJump to behavior
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeSection loaded: winrnr.dllJump to behavior
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeSection loaded: fwpuclnt.dllJump to behavior
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeSection loaded: rasadhlp.dllJump to behavior
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeSection loaded: resourcepolicyclient.dllJump to behavior
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeSection loaded: uxtheme.dllJump to behavior
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeSection loaded: devenum.dllJump to behavior
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeSection loaded: devobj.dllJump to behavior
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeSection loaded: msasn1.dllJump to behavior
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeSection loaded: msdmo.dllJump to behavior
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeSection loaded: windows.storage.dllJump to behavior
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeSection loaded: wldp.dllJump to behavior
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeSection loaded: profapi.dllJump to behavior
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeSection loaded: windowscodecs.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: kernel.appcore.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: uxtheme.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: logoncontroller.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: umpdc.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: dxgi.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: powrprof.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: userenv.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: powrprof.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: slc.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: sppc.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: dsreg.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: msvcp110_win.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: cryptsp.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: dwmapi.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: wtsapi32.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: winsta.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: windows.ui.logon.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: wincorlib.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: dcomp.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: windows.ui.xamlhost.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: mrmcorer.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: windows.ui.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: windowmanagementapi.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: textinputframework.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: inputhost.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: coreuicomponents.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: coremessaging.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: coremessaging.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: propsys.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: wintypes.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: coreuicomponents.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: wintypes.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: twinapi.appcore.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: coremessaging.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: ntmarta.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: twinapi.appcore.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: coremessaging.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: wintypes.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: wintypes.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: wintypes.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: languageoverlayutil.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: bcp47mrm.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: windows.ui.xaml.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: bcp47langs.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: iertutil.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: windows.ui.immersive.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: profapi.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: urlmon.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: srvcli.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: netutils.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: resourcepolicyclient.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: d3d11.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: dwrite.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: d3d10warp.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: windows.globalization.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: dxcore.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: d2d1.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: textshaping.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: directmanipulation.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: windows.ui.xaml.controls.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: uiautomationcore.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: kernel.appcore.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: uxtheme.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: logoncontroller.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: umpdc.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: dxgi.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: powrprof.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: userenv.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: powrprof.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: slc.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: sppc.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: dsreg.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: msvcp110_win.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: cryptsp.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: dwmapi.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: wtsapi32.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: winsta.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: kernel.appcore.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: uxtheme.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: logoncontroller.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: umpdc.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: dxgi.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: powrprof.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: userenv.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: powrprof.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: slc.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: sppc.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: dsreg.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: msvcp110_win.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: cryptsp.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: dwmapi.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: wtsapi32.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: winsta.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: kernel.appcore.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: uxtheme.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: logoncontroller.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: umpdc.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: dxgi.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: powrprof.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: userenv.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: powrprof.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: slc.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: sppc.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: dsreg.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: msvcp110_win.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: cryptsp.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: dwmapi.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: wtsapi32.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: winsta.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: kernel.appcore.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: uxtheme.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: logoncontroller.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: umpdc.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: dxgi.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: powrprof.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: userenv.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: powrprof.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: slc.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: sppc.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: dsreg.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: msvcp110_win.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: cryptsp.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: dwmapi.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: wtsapi32.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: winsta.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: kernel.appcore.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: uxtheme.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: logoncontroller.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: umpdc.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: dxgi.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: powrprof.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: userenv.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: powrprof.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: slc.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: sppc.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: dsreg.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: msvcp110_win.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: cryptsp.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: dwmapi.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: wtsapi32.dllJump to behavior
    Source: C:\Windows\System32\LogonUI.exeSection loaded: winsta.dllJump to behavior
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{62BE5D10-60EB-11d0-BD3B-00A0C911CE86}\InprocServer32Jump to behavior
    Source: 0DrqlQ4JfZ.exeStatic PE information: Image base 0x140000000 > 0x60000000
    Source: 0DrqlQ4JfZ.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
    Source: 0DrqlQ4JfZ.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600AC6370 gethostname,gethostbyname,inet_ntoa,inet_ntoa,MultiByteToWideChar,MultiByteToWideChar,GetLastInputInfo,GetTickCount,wsprintfW,MultiByteToWideChar,MultiByteToWideChar,LoadLibraryW,GetProcAddress,RegOpenKeyExW,RegQueryValueExW,RegCloseKey,FreeLibrary,GetSystemInfo,wsprintfW,GetDriveTypeW,GetDiskFreeSpaceExW,GlobalMemoryStatusEx,GetForegroundWindow,GetWindowTextW,lstrlenW,GetLocalTime,wsprintfW,lstrlenW,GetModuleHandleW,GetProcAddress,GetNativeSystemInfo,GetSystemInfo,wsprintfW,GetCurrentProcessId,OpenProcess,K32GetProcessImageFileNameW,GetLogicalDriveStringsW,lstrcmpiW,lstrcmpiW,QueryDosDeviceW,lstrlenW,lstrcpyW,CloseHandle,CoInitializeEx,CoCreateInstance,SysFreeString,CoUninitialize,RegOpenKeyExW,RegQueryInfoKeyW,RegEnumKeyExW,lstrlenW,lstrlenW,RegCloseKey,lstrlenW,GetTickCount,wsprintfW,GetLocaleInfoW,GetSystemDirectoryW,GetCurrentHwProfileW,lstrcpyW,lstrcatW,lstrlenW,GetLocalTime,wsprintfW,RegOpenKeyExW,RegDeleteValueW,RegCloseKey,RegCreateKeyW,lstrlenW,RegSetValueExW,RegCloseKey,RegCloseKey,CreateToolhelp32Snapshot,Process32FirstW,Process32NextW,CreateToolhelp32Snapshot,Process32FirstW,Process32NextW,CreateToolhelp32Snapshot,Process32FirstW,Process32NextW,0_2_00007FF600AC6370
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_3_0000000180007C73 push 6FFDC5D5h; iretd 0_3_0000000180007C79
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_3_000000018000508E push 6FFDC5D5h; iretd 0_3_0000000180005094
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_3_0000000180007F23 push 6FFDC5CAh; ret 0_3_0000000180007F29
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_3_000000018000553E push 6FFDC5CAh; ret 0_3_0000000180005544
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_3_0000000180007F6F push 6FFDC5C3h; iretd 0_3_0000000180007F75
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_3_000000018000558A push 6FFDC5C3h; iretd 0_3_0000000180005590
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_3_00000001800079C5 push 60F5C5F1h; iretd 0_3_00000001800079CD
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_3_0000000180004BE0 push 60F5C5F1h; iretd 0_3_0000000180004BE8

    Persistence and Installation Behavior

    barindex
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeFile created: C:\ProgramData\kernelquick.sysJump to behavior
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600ACE36A OpenEventLogW,ClearEventLogW,CloseEventLog,0_2_00007FF600ACE36A
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeKey value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE VenkernalData_infoJump to behavior
    Source: C:\Windows\System32\LogonUI.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Windows\System32\LogonUI.exeProcess information set: NOOPENFILEERRORBOXJump to behavior

    Malware Analysis System Evasion

    barindex
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeEvasive API call chain: CreateMutex,DecisionNodes,Sleepgraph_0-21647
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeStalling execution: Execution stalls by calling Sleepgraph_0-22022
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{05DF8D13-C355-47F4-A11E-851B338CEFB8}Jump to behavior
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600AC6370 gethostname,gethostbyname,inet_ntoa,inet_ntoa,MultiByteToWideChar,MultiByteToWideChar,GetLastInputInfo,GetTickCount,wsprintfW,MultiByteToWideChar,MultiByteToWideChar,LoadLibraryW,GetProcAddress,RegOpenKeyExW,RegQueryValueExW,RegCloseKey,FreeLibrary,GetSystemInfo,wsprintfW,GetDriveTypeW,GetDiskFreeSpaceExW,GlobalMemoryStatusEx,GetForegroundWindow,GetWindowTextW,lstrlenW,GetLocalTime,wsprintfW,lstrlenW,GetModuleHandleW,GetProcAddress,GetNativeSystemInfo,GetSystemInfo,wsprintfW,GetCurrentProcessId,OpenProcess,K32GetProcessImageFileNameW,GetLogicalDriveStringsW,lstrcmpiW,lstrcmpiW,QueryDosDeviceW,lstrlenW,lstrcpyW,CloseHandle,CoInitializeEx,CoCreateInstance,SysFreeString,CoUninitialize,RegOpenKeyExW,RegQueryInfoKeyW,RegEnumKeyExW,lstrlenW,lstrlenW,RegCloseKey,lstrlenW,GetTickCount,wsprintfW,GetLocaleInfoW,GetSystemDirectoryW,GetCurrentHwProfileW,lstrcpyW,lstrcatW,lstrlenW,GetLocalTime,wsprintfW,RegOpenKeyExW,RegDeleteValueW,RegCloseKey,RegCreateKeyW,lstrlenW,RegSetValueExW,RegCloseKey,RegCloseKey,CreateToolhelp32Snapshot,Process32FirstW,Process32NextW,CreateToolhelp32Snapshot,Process32FirstW,Process32NextW,CreateToolhelp32Snapshot,Process32FirstW,Process32NextW,0_2_00007FF600AC6370
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeWindow / User API: threadDelayed 3269Jump to behavior
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeWindow / User API: threadDelayed 5394Jump to behavior
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCheck user administrative privileges: GetTokenInformation,DecisionNodesgraph_0-21580
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exe TID: 2080Thread sleep count: 58 > 30Jump to behavior
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exe TID: 2080Thread sleep time: -58000s >= -30000sJump to behavior
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exe TID: 4296Thread sleep count: 3269 > 30Jump to behavior
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exe TID: 4296Thread sleep time: -32690s >= -30000sJump to behavior
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exe TID: 4048Thread sleep count: 339 > 30Jump to behavior
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exe TID: 2080Thread sleep count: 5394 > 30Jump to behavior
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exe TID: 2080Thread sleep time: -5394000s >= -30000sJump to behavior
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600ACF410 GetLastInputInfo,GetTickCount,wsprintfW,GetForegroundWindow,GetWindowTextW,CreateToolhelp32Snapshot,Process32FirstW,Process32NextW,CreateToolhelp32Snapshot,Process32FirstW,Process32NextW,CreateToolhelp32Snapshot,Process32FirstW,Process32NextW,RegOpenKeyExW,RegQueryValueExW,RegQueryValueExW,RegCloseKey,RegOpenKeyExW,RegQueryValueExW,RegQueryValueExW,RegCloseKey,RegOpenKeyExW,RegQueryValueExW,RegQueryValueExW,RegCloseKey,SHGetFolderPathW,lstrcatW,CreateFileW,lstrlenW,WriteFile,CloseHandle,FindFirstFileW,FindClose,_invalid_parameter_noinfo_noreturn,0_2_00007FF600ACF410
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600AF4190 _invalid_parameter_noinfo,FindFirstFileExW,FindNextFileW,FindClose,FindClose,0_2_00007FF600AF4190
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600AC6370 gethostname,gethostbyname,inet_ntoa,inet_ntoa,MultiByteToWideChar,MultiByteToWideChar,GetLastInputInfo,GetTickCount,wsprintfW,MultiByteToWideChar,MultiByteToWideChar,LoadLibraryW,GetProcAddress,RegOpenKeyExW,RegQueryValueExW,RegCloseKey,FreeLibrary,GetSystemInfo,wsprintfW,GetDriveTypeW,GetDiskFreeSpaceExW,GlobalMemoryStatusEx,GetForegroundWindow,GetWindowTextW,lstrlenW,GetLocalTime,wsprintfW,lstrlenW,GetModuleHandleW,GetProcAddress,GetNativeSystemInfo,GetSystemInfo,wsprintfW,GetCurrentProcessId,OpenProcess,K32GetProcessImageFileNameW,GetLogicalDriveStringsW,lstrcmpiW,lstrcmpiW,QueryDosDeviceW,lstrlenW,lstrcpyW,CloseHandle,CoInitializeEx,CoCreateInstance,SysFreeString,CoUninitialize,RegOpenKeyExW,RegQueryInfoKeyW,RegEnumKeyExW,lstrlenW,lstrlenW,RegCloseKey,lstrlenW,GetTickCount,wsprintfW,GetLocaleInfoW,GetSystemDirectoryW,GetCurrentHwProfileW,lstrcpyW,lstrcatW,lstrlenW,GetLocalTime,wsprintfW,RegOpenKeyExW,RegDeleteValueW,RegCloseKey,RegCreateKeyW,lstrlenW,RegSetValueExW,RegCloseKey,RegCloseKey,CreateToolhelp32Snapshot,Process32FirstW,Process32NextW,CreateToolhelp32Snapshot,Process32FirstW,Process32NextW,CreateToolhelp32Snapshot,Process32FirstW,Process32NextW,0_2_00007FF600AC6370
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600AC9300 GetModuleHandleW,GetProcAddress,GetNativeSystemInfo,GetSystemInfo,0_2_00007FF600AC9300
    Source: 0DrqlQ4JfZ.exe, 00000000.00000002.3973837012.000002141BA5C000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll
    Source: C:\Windows\System32\cdd.dllSystem information queried: ModuleInformationJump to behavior
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeProcess information queried: ProcessInformationJump to behavior
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600ADB5E0 SleepEx,CloseHandle,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueW,AdjustTokenPrivileges,CloseHandle,GetModuleHandleA,GetProcAddress,GetCurrentProcessId,OpenProcess,GetLocalTime,wsprintfW,SetUnhandledExceptionFilter,CloseHandle,AllocateAndInitializeSid,CheckTokenMembership,FreeSid,RegOpenKeyExW,RegDeleteValueW,RegSetValueExW,RegCloseKey,SleepEx,CreateEventA,Sleep,Sleep,CloseHandle,_invalid_parameter_noinfo_noreturn,IsDebuggerPresent,LoadLibraryW,GetProcAddress,FreeLibrary,GetLocalTime,wsprintfW,CreateFileW,FreeLibrary,GetCurrentThreadId,GetCurrentProcessId,GetCurrentProcess,CloseHandle,FreeLibrary,0_2_00007FF600ADB5E0
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600ADC82C GetLastError,IsDebuggerPresent,OutputDebugStringW,0_2_00007FF600ADC82C
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600AC6370 gethostname,gethostbyname,inet_ntoa,inet_ntoa,MultiByteToWideChar,MultiByteToWideChar,GetLastInputInfo,GetTickCount,wsprintfW,MultiByteToWideChar,MultiByteToWideChar,LoadLibraryW,GetProcAddress,RegOpenKeyExW,RegQueryValueExW,RegCloseKey,FreeLibrary,GetSystemInfo,wsprintfW,GetDriveTypeW,GetDiskFreeSpaceExW,GlobalMemoryStatusEx,GetForegroundWindow,GetWindowTextW,lstrlenW,GetLocalTime,wsprintfW,lstrlenW,GetModuleHandleW,GetProcAddress,GetNativeSystemInfo,GetSystemInfo,wsprintfW,GetCurrentProcessId,OpenProcess,K32GetProcessImageFileNameW,GetLogicalDriveStringsW,lstrcmpiW,lstrcmpiW,QueryDosDeviceW,lstrlenW,lstrcpyW,CloseHandle,CoInitializeEx,CoCreateInstance,SysFreeString,CoUninitialize,RegOpenKeyExW,RegQueryInfoKeyW,RegEnumKeyExW,lstrlenW,lstrlenW,RegCloseKey,lstrlenW,GetTickCount,wsprintfW,GetLocaleInfoW,GetSystemDirectoryW,GetCurrentHwProfileW,lstrcpyW,lstrcatW,lstrlenW,GetLocalTime,wsprintfW,RegOpenKeyExW,RegDeleteValueW,RegCloseKey,RegCreateKeyW,lstrlenW,RegSetValueExW,RegCloseKey,RegCloseKey,CreateToolhelp32Snapshot,Process32FirstW,Process32NextW,CreateToolhelp32Snapshot,Process32FirstW,Process32NextW,CreateToolhelp32Snapshot,Process32FirstW,Process32NextW,0_2_00007FF600AC6370
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600AC6370 gethostname,gethostbyname,inet_ntoa,inet_ntoa,MultiByteToWideChar,MultiByteToWideChar,GetLastInputInfo,GetTickCount,wsprintfW,MultiByteToWideChar,MultiByteToWideChar,LoadLibraryW,GetProcAddress,RegOpenKeyExW,RegQueryValueExW,RegCloseKey,FreeLibrary,GetSystemInfo,wsprintfW,GetDriveTypeW,GetDiskFreeSpaceExW,GlobalMemoryStatusEx,GetForegroundWindow,GetWindowTextW,lstrlenW,GetLocalTime,wsprintfW,lstrlenW,GetModuleHandleW,GetProcAddress,GetNativeSystemInfo,GetSystemInfo,wsprintfW,GetCurrentProcessId,OpenProcess,K32GetProcessImageFileNameW,GetLogicalDriveStringsW,lstrcmpiW,lstrcmpiW,QueryDosDeviceW,lstrlenW,lstrcpyW,CloseHandle,CoInitializeEx,CoCreateInstance,SysFreeString,CoUninitialize,RegOpenKeyExW,RegQueryInfoKeyW,RegEnumKeyExW,lstrlenW,lstrlenW,RegCloseKey,lstrlenW,GetTickCount,wsprintfW,GetLocaleInfoW,GetSystemDirectoryW,GetCurrentHwProfileW,lstrcpyW,lstrcatW,lstrlenW,GetLocalTime,wsprintfW,RegOpenKeyExW,RegDeleteValueW,RegCloseKey,RegCreateKeyW,lstrlenW,RegSetValueExW,RegCloseKey,RegCloseKey,CreateToolhelp32Snapshot,Process32FirstW,Process32NextW,CreateToolhelp32Snapshot,Process32FirstW,Process32NextW,CreateToolhelp32Snapshot,Process32FirstW,Process32NextW,0_2_00007FF600AC6370
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600ADAD40 VirtualFree,GetProcessHeap,HeapFree,0_2_00007FF600ADAD40
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600ADBDF0 SetUnhandledExceptionFilter,GetConsoleWindow,ShowWindow,GetCurrentThreadId,PostThreadMessageA,GetInputState,CreateThread,WaitForSingleObject,CloseHandle,Sleep,0_2_00007FF600ADBDF0
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600ADB5E0 SleepEx,CloseHandle,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueW,AdjustTokenPrivileges,CloseHandle,GetModuleHandleA,GetProcAddress,GetCurrentProcessId,OpenProcess,GetLocalTime,wsprintfW,SetUnhandledExceptionFilter,CloseHandle,AllocateAndInitializeSid,CheckTokenMembership,FreeSid,RegOpenKeyExW,RegDeleteValueW,RegSetValueExW,RegCloseKey,SleepEx,CreateEventA,Sleep,Sleep,CloseHandle,_invalid_parameter_noinfo_noreturn,IsDebuggerPresent,LoadLibraryW,GetProcAddress,FreeLibrary,GetLocalTime,wsprintfW,CreateFileW,FreeLibrary,GetCurrentThreadId,GetCurrentProcessId,GetCurrentProcess,CloseHandle,FreeLibrary,0_2_00007FF600ADB5E0
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600ADEA00 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,0_2_00007FF600ADEA00
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600AE3D0C RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_00007FF600AE3D0C
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600ADE66C IsProcessorFeaturePresent,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_00007FF600ADE66C
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600ADE814 SetUnhandledExceptionFilter,0_2_00007FF600ADE814

    HIPS / PFW / Operating System Protection Evasion

    barindex
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600ACCD40 GetSystemDirectoryA,CreateProcessA,VirtualAllocEx,WriteProcessMemory,GetThreadContext,SetThreadContext,ResumeThread,0_2_00007FF600ACCD40
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600AC9480 GetSystemDirectoryA,CreateProcessA,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueW,AdjustTokenPrivileges,OpenProcess,LoadLibraryA,GetProcAddress,LoadLibraryA,GetProcAddress,LoadLibraryA,GetProcAddress,LoadLibraryA,GetProcAddress,GetCurrentProcess,GetProcessId,GetModuleFileNameA,VirtualAllocEx,WriteProcessMemory,VirtualProtectEx,VirtualAllocEx,WriteProcessMemory,VirtualProtectEx,CreateRemoteThread,Sleep,VirtualProtectEx,VirtualProtectEx,ResumeThread,0_2_00007FF600AC9480
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: GetSystemDirectoryA,CreateProcessA,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueW,AdjustTokenPrivileges,OpenProcess,LoadLibraryA,GetProcAddress,LoadLibraryA,GetProcAddress,LoadLibraryA,GetProcAddress,LoadLibraryA,GetProcAddress,GetCurrentProcess,GetProcessId,GetModuleFileNameA,VirtualAllocEx,WriteProcessMemory,VirtualProtectEx,VirtualAllocEx,WriteProcessMemory,VirtualProtectEx,CreateRemoteThread,Sleep,VirtualProtectEx,VirtualProtectEx,ResumeThread, Windows\System32\svchost.exe0_2_00007FF600AC9480
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600ADB5E0 SleepEx,CloseHandle,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueW,AdjustTokenPrivileges,CloseHandle,GetModuleHandleA,GetProcAddress,GetCurrentProcessId,OpenProcess,GetLocalTime,wsprintfW,SetUnhandledExceptionFilter,CloseHandle,AllocateAndInitializeSid,CheckTokenMembership,FreeSid,RegOpenKeyExW,RegDeleteValueW,RegSetValueExW,RegCloseKey,SleepEx,CreateEventA,Sleep,Sleep,CloseHandle,_invalid_parameter_noinfo_noreturn,IsDebuggerPresent,LoadLibraryW,GetProcAddress,FreeLibrary,GetLocalTime,wsprintfW,CreateFileW,FreeLibrary,GetCurrentThreadId,GetCurrentProcessId,GetCurrentProcess,CloseHandle,FreeLibrary,0_2_00007FF600ADB5E0
    Source: 0DrqlQ4JfZ.exe, 00000000.00000002.3973837012.000002141BA92000.00000004.00000020.00020000.00000000.sdmp, 0DrqlQ4JfZ.exe, 00000000.00000002.3973837012.000002141BA5C000.00000004.00000020.00020000.00000000.sdmp, 0DrqlQ4JfZ.exe, 00000000.00000002.3973837012.000002141BAFC000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: 0 minProgram Manager
    Source: 0DrqlQ4JfZ.exe, 00000000.00000003.3627831841.000002141BB2E000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Program Manager
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_3_00000001800015A0 cpuid 0_3_00000001800015A0
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: gethostname,gethostbyname,inet_ntoa,inet_ntoa,MultiByteToWideChar,MultiByteToWideChar,GetLastInputInfo,GetTickCount,wsprintfW,MultiByteToWideChar,MultiByteToWideChar,LoadLibraryW,GetProcAddress,RegOpenKeyExW,RegQueryValueExW,RegCloseKey,FreeLibrary,GetSystemInfo,wsprintfW,GetDriveTypeW,GetDiskFreeSpaceExW,GlobalMemoryStatusEx,GetForegroundWindow,GetWindowTextW,lstrlenW,GetLocalTime,wsprintfW,lstrlenW,GetModuleHandleW,GetProcAddress,GetNativeSystemInfo,GetSystemInfo,wsprintfW,GetCurrentProcessId,OpenProcess,K32GetProcessImageFileNameW,GetLogicalDriveStringsW,lstrcmpiW,lstrcmpiW,QueryDosDeviceW,lstrlenW,lstrcpyW,CloseHandle,CoInitializeEx,CoCreateInstance,SysFreeString,CoUninitialize,RegOpenKeyExW,RegQueryInfoKeyW,RegEnumKeyExW,lstrlenW,lstrlenW,RegCloseKey,lstrlenW,GetTickCount,wsprintfW,GetLocaleInfoW,GetSystemDirectoryW,GetCurrentHwProfileW,lstrcpyW,lstrcatW,lstrlenW,GetLocalTime,wsprintfW,RegOpenKeyExW,RegDeleteValueW,RegCloseKey,RegCreateKeyW,lstrlenW,RegSetValueExW,RegCloseKey,RegCloseKey,CreateToolhelp32Snapshot,Process32FirstW,Process32NextW,CreateToolhelp32Snapshot,Process32FirstW,Process32NextW,CreateToolhelp32Snapshot,Process32FirstW,Process32NextW,0_2_00007FF600AC6370
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: GetLocaleInfoW,GetLocaleInfoW,GetACP,0_2_00007FF600AF81E0
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: TranslateName,TranslateName,GetACP,IsValidCodePage,GetLocaleInfoW,0_2_00007FF600AF797C
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: EnumSystemLocalesW,0_2_00007FF600AF0AD8
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: GetLocaleInfoW,0_2_00007FF600AF8290
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: EnumSystemLocalesW,GetUserDefaultLCID,ProcessCodePage,IsValidCodePage,IsValidLocale,GetLocaleInfoW,GetLocaleInfoW,0_2_00007FF600AF83C4
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: EnumSystemLocalesW,0_2_00007FF600AF7CD8
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: EnumSystemLocalesW,0_2_00007FF600AF7DA8
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,0_2_00007FF600AF7E40
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: GetLocaleInfoW,0_2_00007FF600AF0FB0
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: GetLocaleInfoW,0_2_00007FF600AF8088
    Source: C:\Windows\System32\LogonUI.exeQueries volume information: C:\Windows\Fonts\segoeui.ttf VolumeInformationJump to behavior
    Source: C:\Windows\System32\LogonUI.exeQueries volume information: C:\Windows\Fonts\segoeuisl.ttf VolumeInformationJump to behavior
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_3_000000018004CBA8 GetSystemTimeAsFileTime,GetCurrentThreadId,GetCurrentProcessId,QueryPerformanceCounter,0_3_000000018004CBA8
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600AF2048 _get_daylight,_get_daylight,_get_daylight,_get_daylight,_get_daylight,GetTimeZoneInformation,0_2_00007FF600AF2048
    Source: C:\Users\user\Desktop\0DrqlQ4JfZ.exeCode function: 0_2_00007FF600AC8A40 GetCurrentProcessId,OpenProcess,OpenProcessToken,CloseHandle,SysStringLen,SysStringLen,CloseHandle,CloseHandle,SysFreeString,SysFreeString,GetCurrentProcessId,wsprintfW,GetVersionExW,GetCurrentProcess,OpenProcessToken,GetTokenInformation,GetLastError,LocalAlloc,GetTokenInformation,GetSidSubAuthorityCount,GetSidSubAuthority,LocalFree,CloseHandle,wsprintfW,0_2_00007FF600AC8A40
    Source: 0DrqlQ4JfZ.exe, 00000000.00000000.1684425201.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmp, 0DrqlQ4JfZ.exe, 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpBinary or memory string: KSafeTray.exe

    Stealing of Sensitive Information

    barindex
    Source: Yara matchFile source: Process Memory Space: 0DrqlQ4JfZ.exe PID: 2564, type: MEMORYSTR

    Remote Access Functionality

    barindex
    Source: Yara matchFile source: Process Memory Space: 0DrqlQ4JfZ.exe PID: 2564, type: MEMORYSTR
    ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
    Gather Victim Identity InformationAcquire Infrastructure1
    Replication Through Removable Media
    12
    Native API
    1
    LSASS Driver
    1
    LSASS Driver
    1
    Obfuscated Files or Information
    121
    Input Capture
    2
    System Time Discovery
    Remote Services1
    Archive Collected Data
    1
    Ingress Tool Transfer
    Exfiltration Over Other Network Medium1
    System Shutdown/Reboot
    CredentialsDomainsDefault AccountsScheduled Task/Job1
    DLL Side-Loading
    1
    DLL Side-Loading
    1
    DLL Side-Loading
    LSASS Memory11
    Peripheral Device Discovery
    Remote Desktop Protocol1
    Screen Capture
    1
    Encrypted Channel
    Exfiltration Over BluetoothNetwork Denial of Service
    Email AddressesDNS ServerDomain AccountsAt1
    Windows Service
    1
    Access Token Manipulation
    1
    Modify Registry
    Security Account Manager2
    File and Directory Discovery
    SMB/Windows Admin Shares121
    Input Capture
    1
    Non-Standard Port
    Automated ExfiltrationData Encrypted for Impact
    Employee NamesVirtual Private ServerLocal AccountsCronLogin Hook1
    Windows Service
    1
    Virtualization/Sandbox Evasion
    NTDS37
    System Information Discovery
    Distributed Component Object Model3
    Clipboard Data
    1
    Non-Application Layer Protocol
    Traffic DuplicationData Destruction
    Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon Script212
    Process Injection
    1
    Access Token Manipulation
    LSA Secrets151
    Security Software Discovery
    SSHKeylogging1
    Application Layer Protocol
    Scheduled TransferData Encrypted for Impact
    Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts212
    Process Injection
    Cached Domain Credentials1
    Virtualization/Sandbox Evasion
    VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
    DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items1
    Indicator Removal
    DCSync3
    Process Discovery
    Windows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
    Network Trust DependenciesServerlessDrive-by CompromiseContainer Orchestration JobScheduled Task/JobScheduled Task/JobIndicator Removal from ToolsProc Filesystem1
    Application Window Discovery
    Cloud ServicesCredential API HookingApplication Layer ProtocolExfiltration Over Alternative ProtocolDefacement
    Hide Legend

    Legend:

    • Process
    • Signature
    • Created File
    • DNS/IP Info
    • Is Dropped
    • Is Windows Process
    • Number of created Registry Values
    • Number of created Files
    • Visual Basic
    • Delphi
    • Java
    • .Net C# or VB.NET
    • C, C++ or other language
    • Is malicious
    • Internet

    This section contains all screenshots as thumbnails, including those not shown in the slideshow.


    windows-stand
    SourceDetectionScannerLabelLink
    0DrqlQ4JfZ.exe65%VirustotalBrowse
    0DrqlQ4JfZ.exe53%ReversingLabsWin64.Trojan.SpywareX
    No Antivirus matches
    No Antivirus matches
    No Antivirus matches
    No Antivirus matches
    NameIPActiveMaliciousAntivirus DetectionReputation
    ax-0001.ax-msedge.net
    150.171.28.10
    truefalse
      high
      tse1.mm.bing.net
      unknown
      unknownfalse
        high
        api.msn.com
        unknown
        unknownfalse
          high
          • No. of IPs < 25%
          • 25% < No. of IPs < 50%
          • 50% < No. of IPs < 75%
          • 75% < No. of IPs
          IPDomainCountryFlagASNASN NameMalicious
          23.226.57.67
          unknownUnited States
          136800XIAOZHIYUN1-AS-APICIDCNETWORKUStrue
          Joe Sandbox version:41.0.0 Charoite
          Analysis ID:1583300
          Start date and time:2025-01-02 12:06:04 +01:00
          Joe Sandbox product:CloudBasic
          Overall analysis duration:0h 10m 0s
          Hypervisor based Inspection enabled:false
          Report type:full
          Cookbook file name:default.jbs
          Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
          Number of analysed new started processes analysed:36
          Number of new started drivers analysed:5
          Number of existing processes analysed:0
          Number of existing drivers analysed:0
          Number of injected processes analysed:0
          Technologies:
          • HCA enabled
          • EGA enabled
          • AMSI enabled
          Analysis Mode:default
          Sample name:0DrqlQ4JfZ.exe
          renamed because original name is a hash value
          Original Sample Name:de3f0f8cbac7723e54298baec915e2ba.exe
          Detection:MAL
          Classification:mal100.troj.spyw.evad.winEXE@12/1@2/1
          EGA Information:
          • Successful, ratio: 100%
          HCA Information:
          • Successful, ratio: 86%
          • Number of executed functions: 55
          • Number of non-executed functions: 113
          Cookbook Comments:
          • Found application associated with file extension: .exe
          • Override analysis time to 240000 for current running targets taking high CPU consumption
          • Connection to analysis system has been lost, crash info: Unknown
          • Exclude process from analysis (whitelisted): MpCmdRun.exe, smss.exe, dwm.exe, WMIADAP.exe, SIHClient.exe, csrss.exe, winlogon.exe, conhost.exe, svchost.exe
          • Excluded IPs from analysis (whitelisted): 184.28.90.27, 184.28.90.96, 204.79.197.203, 104.102.63.47, 2.23.209.181, 2.23.209.150, 2.23.209.160, 2.23.209.177, 2.23.209.149, 2.23.209.185, 2.23.209.182, 2.23.209.176, 2.23.209.179, 40.126.32.76, 40.126.32.140, 40.126.32.133, 40.126.32.138, 40.126.32.134, 20.190.160.17, 20.190.160.20, 40.126.32.68, 2.23.209.130, 2.23.209.133, 2.23.209.187, 2.23.209.189, 2.23.209.140, 2.23.209.148, 51.132.193.105, 20.223.35.26, 2.23.209.158, 20.109.210.53, 13.107.246.45
          • Excluded domains from analysis (whitelisted): slscr.update.microsoft.com, p-static.bing.trafficmanager.net, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, arc.msn.com, cdn.onenote.net.edgekey.net, e86303.dscx.akamaiedge.net, ocsp.digicert.com, www.bing.com.edgekey.net, wildcard.weather.microsoft.com.edgekey.net, login.live.com, e16604.g.akamaiedge.net, r.bing.com, arc.trafficmanager.net, prod.fs.microsoft.com.akadns.net, cdn.onenote.net, www.bing.com, self-events-data.trafficmanager.net, prdv4a.aadg.msidentity.com, fs.microsoft.com, otelrules.azureedge.net, e15275.d.akamaiedge.net, r.bing.com.edgekey.net, www.tm.v4.a.prd.aadg.akadns.net, self.events.data.microsoft.com, a-0003.a-msedge.net, tile-service.weather.microsoft.com, ctldl.windowsupdate.com, www-www.bing.com.trafficmanager.net, login.msa.msidentity.com, fe3cr.delivery.mp.microsoft.com, onedscolprduks05.uksouth.cloudapp.azure.com, mm-mm.bing.net.trafficmanager.net, e1553.dspg.akamaiedge.net, iris-de
          • Not all processes where analyzed, report is missing behavior information
          • Report size exceeded maximum capacity and may have missing behavior information.
          • Report size getting too big, too many NtEnumerateKey calls found.
          • Report size getting too big, too many NtOpenKeyEx calls found.
          • Report size getting too big, too many NtProtectVirtualMemory calls found.
          • Report size getting too big, too many NtQueryValueKey calls found.
          TimeTypeDescription
          06:07:31API Interceptor5568475x Sleep call for process: 0DrqlQ4JfZ.exe modified
          No context
          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
          ax-0001.ax-msedge.nethttps://tr171139818.amoliani.com/c/mm14r39/e-v_xxa-/imz77nt3npsGet hashmaliciousUnknownBrowse
          • 150.171.28.10
          http://img1.wsimg.com/blobby/go/9b6ed793-452c-4f8f-8f80-6847f4d114d7/downloads/71318864754.pdfGet hashmaliciousUnknownBrowse
          • 150.171.28.10
          FW_ Carr & Jeanne Biggerstaff has sent you an ecard.msgGet hashmaliciousUnknownBrowse
          • 150.171.27.10
          SecuredOnedrive.ClientSetup.exeGet hashmaliciousScreenConnect ToolBrowse
          • 150.171.27.10
          installer64v3.2.0.msiGet hashmaliciousUnknownBrowse
          • 150.171.28.10
          https://online-ops.mypasschange.com/landingPage/2/fbb0559ebe1911efb53c0242ac190102Get hashmaliciousUnknownBrowse
          • 150.171.28.10
          skript.batGet hashmaliciousVidarBrowse
          • 150.171.28.10
          ERTL09tA59.exeGet hashmaliciousLummaCBrowse
          • 150.171.28.10
          vJPhYDClT5.exeGet hashmaliciousUnknownBrowse
          • 150.171.27.10
          GtEVo1eO2p.exeGet hashmaliciousLummaCBrowse
          • 150.171.28.10
          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
          XIAOZHIYUN1-AS-APICIDCNETWORKUSRXxeYma4d5.exeGet hashmaliciousGhostRatBrowse
          • 23.235.165.54
          vcimanagement.armv7l.elfGet hashmaliciousGafgyt, MiraiBrowse
          • 156.253.103.137
          vcimanagement.mipsel.elfGet hashmaliciousGafgyt, MiraiBrowse
          • 156.254.252.201
          vcimanagement.mips.elfGet hashmaliciousGafgyt, MiraiBrowse
          • 156.234.199.209
          vcimanagement.x86.elfGet hashmaliciousGafgyt, MiraiBrowse
          • 156.255.154.138
          vcimanagement.m68k.elfGet hashmaliciousGafgyt, MiraiBrowse
          • 156.241.23.75
          Wk6IMAhBNF.exeGet hashmaliciousGhostRatBrowse
          • 103.199.100.130
          aQ7bSXduYp.exeGet hashmaliciousGhostRat, NitolBrowse
          • 156.225.22.155
          mipsel.nn.elfGet hashmaliciousMirai, OkiruBrowse
          • 103.199.102.178
          nsharm.elfGet hashmaliciousMiraiBrowse
          • 156.234.199.255
          No context
          No context
          Process:C:\Users\user\Desktop\0DrqlQ4JfZ.exe
          File Type:data
          Category:dropped
          Size (bytes):30
          Entropy (8bit):2.6616157143988106
          Encrypted:false
          SSDEEP:3:tblM6lEjln:tbhEZn
          MD5:AE50B29A0B8DCC411F24F1863B0EAFDE
          SHA1:D415A55627B1ADED8E4B2CBBA402F816B0461155
          SHA-256:6B4BBBCE480FBC50D39A8EC4B72CDB7D781B151921E063DD899FD9B736ADCF68
          SHA-512:D9A9BA42D99BE32D26667060BE1D523DCD20EAFA187A67F7919002CC6DA349FD058053C9C6F721D6FDB730EA02FBAA3013E51C0C653368BD6B3F57A4C0FCABA8
          Malicious:true
          Preview:C.:.\.P.r.o.g.r.a.m.D.a.t.a.\.
          File type:PE32+ executable (GUI) x86-64, for MS Windows
          Entropy (8bit):6.060220895795208
          TrID:
          • Win64 Executable GUI (202006/5) 92.65%
          • Win64 Executable (generic) (12005/4) 5.51%
          • Generic Win/DOS Executable (2004/3) 0.92%
          • DOS Executable Generic (2002/1) 0.92%
          • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
          File name:0DrqlQ4JfZ.exe
          File size:390'656 bytes
          MD5:de3f0f8cbac7723e54298baec915e2ba
          SHA1:0bc6ae31882e2856b2ea52c56985409a58920b36
          SHA256:6e797fb47dd3d5bb42fb578ea9dcd64a11af9e82902bffd1aa5ea3226498f1f0
          SHA512:3cce067c130d28a1d90f63f03372b6e0fcc8db9a15f2bd7a2cdd3024af200b29969e5a6e01665ade5b451847eeab029bdf1dc9fca1e5078f8553c8ff62093c82
          SSDEEP:6144:Wvy/g/Oe2CZNHfXmv9m7tvT7DYewsPJimwi9vrBP2kjLjNy:v/KlpTXmv9mpvv0iPJPtr9bNy
          TLSH:FB847E49FB9409F8E467C138C9A34916EBB27C5913A09BDF33A4466A2F237D05D3EB11
          File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......B..R............M.......M.......M.......M........O.......O.......O..S...M.......M...........3...MN......MN......Rich...........
          Icon Hash:90cececece8e8eb0
          Entrypoint:0x14001e25c
          Entrypoint Section:.text
          Digitally signed:false
          Imagebase:0x140000000
          Subsystem:windows gui
          Image File Characteristics:EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE
          DLL Characteristics:HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
          Time Stamp:0x6763E623 [Thu Dec 19 09:23:47 2024 UTC]
          TLS Callbacks:
          CLR (.Net) Version:
          OS Version Major:6
          OS Version Minor:0
          File Version Major:6
          File Version Minor:0
          Subsystem Version Major:6
          Subsystem Version Minor:0
          Import Hash:1db3bac59c066f9b53b8b3b6b99b874b
          Instruction
          dec eax
          sub esp, 28h
          call 00007F4D4CC732E0h
          dec eax
          add esp, 28h
          jmp 00007F4D4CC72B37h
          int3
          int3
          dec eax
          sub esp, 28h
          dec ebp
          mov eax, dword ptr [ecx+38h]
          dec eax
          mov ecx, edx
          dec ecx
          mov edx, ecx
          call 00007F4D4CC72CD2h
          mov eax, 00000001h
          dec eax
          add esp, 28h
          ret
          int3
          int3
          int3
          inc eax
          push ebx
          inc ebp
          mov ebx, dword ptr [eax]
          dec eax
          mov ebx, edx
          inc ecx
          and ebx, FFFFFFF8h
          dec esp
          mov ecx, ecx
          inc ecx
          test byte ptr [eax], 00000004h
          dec esp
          mov edx, ecx
          je 00007F4D4CC72CD5h
          inc ecx
          mov eax, dword ptr [eax+08h]
          dec ebp
          arpl word ptr [eax+04h], dx
          neg eax
          dec esp
          add edx, ecx
          dec eax
          arpl ax, cx
          dec esp
          and edx, ecx
          dec ecx
          arpl bx, ax
          dec edx
          mov edx, dword ptr [eax+edx]
          dec eax
          mov eax, dword ptr [ebx+10h]
          mov ecx, dword ptr [eax+08h]
          dec eax
          mov eax, dword ptr [ebx+08h]
          test byte ptr [ecx+eax+03h], 0000000Fh
          je 00007F4D4CC72CCDh
          movzx eax, byte ptr [ecx+eax+03h]
          and eax, FFFFFFF0h
          dec esp
          add ecx, eax
          dec esp
          xor ecx, edx
          dec ecx
          mov ecx, ecx
          pop ebx
          jmp 00007F4D4CC72CDAh
          int3
          int3
          int3
          int3
          int3
          int3
          int3
          int3
          int3
          int3
          int3
          nop word ptr [eax+eax+00000000h]
          dec eax
          cmp ecx, dword ptr [00036D39h]
          jne 00007F4D4CC72CD2h
          dec eax
          rol ecx, 10h
          test cx, FFFFh
          jne 00007F4D4CC72CC3h
          ret
          dec eax
          ror ecx, 10h
          jmp 00007F4D4CC733DBh
          int3
          int3
          dec eax
          mov dword ptr [esp+00h], ebx
          NameVirtual AddressVirtual Size Is in Section
          IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
          IMAGE_DIRECTORY_ENTRY_IMPORT0x524000x104.rdata
          IMAGE_DIRECTORY_ENTRY_RESOURCE0x00x0
          IMAGE_DIRECTORY_ENTRY_EXCEPTION0x600000x3450.pdata
          IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
          IMAGE_DIRECTORY_ENTRY_BASERELOC0x640000xc8c.reloc
          IMAGE_DIRECTORY_ENTRY_DEBUG0x4c7c00x38.rdata
          IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
          IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
          IMAGE_DIRECTORY_ENTRY_TLS0x4c9800x28.rdata
          IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x4c6800x140.rdata
          IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
          IMAGE_DIRECTORY_ENTRY_IAT0x3f0000x920.rdata
          IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
          IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
          IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
          NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
          .text0x10000x3df700x3e0002b6c6c8b93239d65e2449c4cc33eda20False0.5452683971774194data6.461526088950339IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
          .rdata0x3f0000x151e80x15200ad010f8391ca2f1e0867e51f80b4b406False0.4156804733727811data4.936188857579959IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
          .data0x550000xaa9c0x7c009fdc2e38fdd2e633e5add479069c6669False0.10657132056451613DOS executable (block device driver \377\3)1.5860246065129546IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
          .pdata0x600000x34500x3600b6a68cd5b1e86136baf9e34e01cfad8bFalse0.4622395833333333data5.530289196450094IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
          .reloc0x640000xc8c0xe00a952b87812e4781581800f8699e0d5a4False0.49302455357142855data5.228153224182403IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
          DLLImport
          KERNEL32.dllQueryDosDeviceW, WriteProcessMemory, GetCommandLineW, GetCurrentProcess, WriteFile, OutputDebugStringA, GetModuleFileNameW, GetProcessId, CreateMutexW, GetLocaleInfoW, LocalAlloc, CreateFileW, GetVersionExW, K32GetProcessImageFileNameW, GetSystemDirectoryW, ResumeThread, GetModuleHandleA, OpenProcess, GetLogicalDriveStringsW, CreateToolhelp32Snapshot, MultiByteToWideChar, Process32NextW, GetDiskFreeSpaceExW, GetSystemDirectoryA, LoadLibraryA, lstrcatW, GlobalAlloc, Process32FirstW, GlobalFree, GetSystemInfo, LoadLibraryW, GetLocalTime, VirtualProtectEx, GetThreadContext, GetProcAddress, VirtualAllocEx, LocalFree, ExitProcess, GetCurrentProcessId, GlobalMemoryStatusEx, CreateProcessW, GetModuleHandleW, FreeLibrary, GetConsoleWindow, lstrcpyW, CreateRemoteThread, CreateProcessA, SetThreadContext, GetModuleFileNameA, GetTickCount, lstrcmpW, GetDriveTypeW, GetExitCodeProcess, SetFilePointer, ReleaseMutex, GlobalSize, DeleteFileW, GlobalLock, GetFileSize, GlobalUnlock, FindFirstFileW, ExpandEnvironmentStringsW, FindClose, GetFileAttributesW, TerminateThread, VirtualProtect, IsBadReadPtr, CreateThread, IsDebuggerPresent, SetUnhandledExceptionFilter, WriteConsoleW, GetCurrentThreadId, GetConsoleMode, GetConsoleOutputCP, FlushFileBuffers, SetFilePointerEx, SetStdHandle, SetEnvironmentVariableW, FreeEnvironmentStringsW, GetEnvironmentStringsW, GetOEMCP, GetACP, IsValidCodePage, FindNextFileW, FindFirstFileExW, GetTimeZoneInformation, EnumSystemLocalesW, GetUserDefaultLCID, IsValidLocale, LCMapStringW, CompareStringW, FlsFree, FlsSetValue, GetStartupInfoW, CreateWaitableTimerW, SetWaitableTimer, TryEnterCriticalSection, WideCharToMultiByte, ResetEvent, CreateEventW, lstrlenW, CancelIo, GetNativeSystemInfo, SetLastError, lstrcmpiW, CreateEventA, CloseHandle, SetEvent, Sleep, WaitForSingleObject, LeaveCriticalSection, InitializeCriticalSectionAndSpinCount, EnterCriticalSection, HeapCreate, HeapFree, GetProcessHeap, DeleteCriticalSection, HeapDestroy, DecodePointer, HeapAlloc, HeapReAlloc, GetLastError, HeapSize, InitializeCriticalSectionEx, VirtualAlloc, VirtualFree, FlsGetValue, FlsAlloc, GetFileType, GetCommandLineA, GetStdHandle, VirtualQuery, GetModuleHandleExW, FreeLibraryAndExitThread, ExitThread, LoadLibraryExW, TlsFree, TlsSetValue, TlsGetValue, TlsAlloc, RtlPcToFileHeader, RtlUnwindEx, lstrcpyA, CreateFileA, GetSystemDefaultLangID, DeviceIoControl, TerminateProcess, InitializeSListHead, GetSystemTimeAsFileTime, QueryPerformanceCounter, IsProcessorFeaturePresent, UnhandledExceptionFilter, RtlVirtualUnwind, RtlLookupFunctionEntry, RtlCaptureContext, SleepConditionVariableSRW, WakeAllConditionVariable, AcquireSRWLockExclusive, ReleaseSRWLockExclusive, GetCPInfo, LCMapStringEx, EncodePointer, CompareStringEx, GetStringTypeW, RaiseException, OutputDebugStringW, SwitchToThread
          USER32.dllGetForegroundWindow, GetLastInputInfo, GetClipboardData, GetWindowTextW, GetKeyState, ReleaseDC, GetDesktopWindow, SetClipboardData, CloseClipboard, wsprintfW, ExitWindowsEx, ShowWindow, PostThreadMessageA, GetInputState, GetDC, GetSystemMetrics, EmptyClipboard, MsgWaitForMultipleObjects, DispatchMessageW, PeekMessageW, TranslateMessage, OpenClipboard
          GDI32.dllCreateCompatibleBitmap, SelectObject, CreateDIBSection, SetDIBColorTable, CreateCompatibleDC, StretchBlt, GetDIBits, GetDeviceCaps, GetObjectW, SetStretchBltMode, DeleteObject, DeleteDC
          ADVAPI32.dllRegQueryInfoKeyW, RegQueryValueExW, AllocateAndInitializeSid, FreeSid, CheckTokenMembership, ClearEventLogW, CloseEventLog, OpenEventLogW, LookupPrivilegeValueW, AdjustTokenPrivileges, GetCurrentHwProfileW, RegCloseKey, GetSidSubAuthorityCount, GetSidSubAuthority, RegEnumKeyExW, RegSetValueExW, OpenProcessToken, RegOpenKeyExW, RegCreateKeyW, RegDeleteValueW, LookupAccountSidW, GetTokenInformation
          SHELL32.dllSHGetFolderPathW
          ole32.dllCreateStreamOnHGlobal, GetHGlobalFromStream, CoCreateInstance, CoUninitialize, CoInitialize
          OLEAUT32.dllSysFreeString, SysAllocString, SysStringLen
          WS2_32.dllselect, WSAStartup, send, socket, connect, recv, htons, setsockopt, WSAIoctl, gethostbyname, WSAGetLastError, WSAEnumNetworkEvents, WSAWaitForMultipleEvents, WSAResetEvent, WSAEventSelect, WSASetLastError, WSACloseEvent, shutdown, gethostname, inet_ntoa, WSACleanup, closesocket, WSACreateEvent
          WINMM.dlltimeGetTime
          gdiplus.dllGdipDisposeImage, GdipCreateBitmapFromHBITMAP, GdipGetImagePixelFormat, GdiplusShutdown, GdipDrawImageI, GdipFree, GdipSaveImageToStream, GdipGetImageWidth, GdipGetImagePalette, GdipDeleteGraphics, GdipGetImageEncodersSize, GdipGetImageGraphicsContext, GdipBitmapLockBits, GdipCreateBitmapFromScan0, GdipAlloc, GdiplusStartup, GdipGetImageHeight, GdipGetImageEncoders, GdipGetImagePaletteSize, GdipCloneImage, GdipBitmapUnlockBits, GdipCreateBitmapFromStream
          dxgi.dllCreateDXGIFactory
          DINPUT8.dllDirectInput8Create
          TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
          2025-01-02T12:07:04.869764+01002052875ET MALWARE Anonymous RAT CnC Checkin1192.168.2.44973023.226.57.674433TCP
          2025-01-02T12:08:08.084808+01002052875ET MALWARE Anonymous RAT CnC Checkin1192.168.2.44973023.226.57.674433TCP
          2025-01-02T12:09:12.069235+01002052875ET MALWARE Anonymous RAT CnC Checkin1192.168.2.44973023.226.57.674433TCP
          2025-01-02T12:10:18.743756+01002052875ET MALWARE Anonymous RAT CnC Checkin1192.168.2.45000623.226.57.6710443TCP
          TimestampSource PortDest PortSource IPDest IP
          Jan 2, 2025 12:07:03.368633032 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:03.373617887 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:03.373713017 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:04.124125004 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:04.129090071 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:04.129102945 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:04.129111052 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:04.129122019 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:04.440392017 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:04.490853071 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:04.864835978 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:04.869721889 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:04.869735956 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:04.869745016 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:04.869764090 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:04.874536991 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:19.631607056 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:19.636398077 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:19.934623003 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:19.975195885 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:35.678464890 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:35.683270931 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:35.981189013 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:36.022090912 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:36.393193960 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:36.393209934 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:36.393219948 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:36.393285036 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:36.393724918 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:36.398546934 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:36.398555994 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:36.398566008 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:36.711783886 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:36.711797953 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:36.711818933 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:36.711829901 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:36.711841106 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:36.711848021 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:36.711905956 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:36.711939096 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:36.711951971 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:36.711962938 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:36.711982012 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:36.712012053 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:36.712704897 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:36.712718010 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:36.712769032 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:36.712954998 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:36.712969065 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:36.712982893 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:36.713000059 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:36.713007927 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:36.713012934 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:36.713037014 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:36.756469011 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:36.922961950 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:36.922985077 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:36.922996044 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:36.923058033 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:36.923082113 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:36.923135042 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:36.923319101 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:36.923331022 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:36.923342943 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:36.923374891 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:36.923383951 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:36.923388004 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:36.923402071 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:36.923422098 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:36.923441887 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:36.924149990 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:36.924160004 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:36.924170971 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:36.924197912 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:36.924243927 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:36.924254894 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:36.924266100 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:36.924288988 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:36.924309015 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:36.925081968 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:36.925093889 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:36.925103903 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:36.925132036 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:36.925141096 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:36.925152063 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:36.925162077 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:36.925192118 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:36.925213099 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:36.925997972 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:36.926009893 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:36.926021099 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:36.926048994 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:36.975331068 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.134181976 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.134196043 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.134283066 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.134318113 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.134351969 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.134363890 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.134396076 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.134438038 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.134449959 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.134462118 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.134483099 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.134506941 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.134568930 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.134579897 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.134589911 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.134618998 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.134712934 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.134754896 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.134758949 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.134771109 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.134800911 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.134896994 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.134908915 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.134918928 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.134931087 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.134943962 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.134970903 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.135481119 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.135493040 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.135502100 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.135531902 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.135545969 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.135557890 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.135566950 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.135580063 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.135590076 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.135627985 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.135663986 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.135704041 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.136384010 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.136394978 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.136409044 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.136441946 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.136456013 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.136466980 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.136476040 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.136488914 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.136504889 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.136543036 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.136639118 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.136687040 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.137201071 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.137226105 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.137237072 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.137269020 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.137382030 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.137392998 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.137403965 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.137415886 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.137425900 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.137449980 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.178494930 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.344844103 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.344883919 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.344897985 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.344928026 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.345000982 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.345012903 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.345022917 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.345046997 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.345071077 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.345108986 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.345120907 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.345175982 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.345201969 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.345213890 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.345237017 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.345243931 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.345426083 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.345436096 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.345479965 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.345480919 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.345525026 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.345541954 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.345552921 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.345587015 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.345650911 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.345662117 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.345671892 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.345684052 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.345698118 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.345733881 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.345767975 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.346054077 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.346062899 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.346096992 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.346187115 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.346198082 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.346210003 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.346230984 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.346259117 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.346281052 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.346291065 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.346302032 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.346314907 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.346363068 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.346363068 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.346472025 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.346482992 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.346497059 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.346508980 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.346518993 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.346524954 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.346529007 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.346548080 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.346577883 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.347079992 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.347090960 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.347100973 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.347122908 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.347158909 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.347171068 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.347181082 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.347193003 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.347218037 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.347373962 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.347385883 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.347397089 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.347407103 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.347420931 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.347453117 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.347778082 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.347824097 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.347834110 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.347876072 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.347887039 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.347923040 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.347965002 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.347980022 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.347991943 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.348032951 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.348057032 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.348112106 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.348123074 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.348133087 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.348159075 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.348218918 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.348229885 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.348239899 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.348268032 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.348279953 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.348699093 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.348756075 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.348766088 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.348800898 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.348855972 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.348866940 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.348876953 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.348898888 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.348915100 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.349013090 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.349025011 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.349034071 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.349045038 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.349060059 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.349066019 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.349073887 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.349082947 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.349112988 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.349240065 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.349682093 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.349699020 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.349709988 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.349724054 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.349761963 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.555775881 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.555849075 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.555860043 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.555869102 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.555891037 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.555907011 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.555913925 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.555938005 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.555948973 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.555964947 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.555974960 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.555999994 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.556071997 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.556082964 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.556092978 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.556121111 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.556133986 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.556145906 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.556170940 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.556210995 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.556250095 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.556263924 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.556276083 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.556308031 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.556344032 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.556355953 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.556365967 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.556389093 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.556493044 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.556504011 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.556514025 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.556538105 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.556555986 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.556586981 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.556597948 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.556607962 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.556627989 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.556662083 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.556708097 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.556782961 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.556826115 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.556837082 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.556847095 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.556864023 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.556889057 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.556922913 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.556934118 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.556973934 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.556983948 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.556996107 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.557034016 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.557079077 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.557090044 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.557101011 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.557112932 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.557125092 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.557126045 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.557161093 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.557266951 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.557279110 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.557316065 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.557481050 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.557492018 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.557502985 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.557528019 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.557543993 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.557554960 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.557565928 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.557575941 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.557588100 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.557602882 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.557627916 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.557740927 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.557751894 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.557760954 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.557773113 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.557801008 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.557811975 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.557892084 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.557904005 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.557923079 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.557933092 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.557935953 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.557944059 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.557955027 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.557965994 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.557965994 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.557977915 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.557990074 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.557997942 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.558021069 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.558052063 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.558067083 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.558089972 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.558461905 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.558474064 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.558482885 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.558504105 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.558521986 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.558528900 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.558533907 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.558545113 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.558557034 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.558568954 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.558595896 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.558753014 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.558764935 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.558775902 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.558794975 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.558805943 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.558805943 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.558819056 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.558826923 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.558830976 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.558842897 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.558847904 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.558854103 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.558877945 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.560827971 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.560838938 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.560849905 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.560866117 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.560880899 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.560957909 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.560969114 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.560978889 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.560990095 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.561001062 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.561002016 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.561028004 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.561151981 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.561161995 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.561172009 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.561182022 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.561183929 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.561194897 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.561202049 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.561208010 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.561232090 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.561294079 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.561304092 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.561316013 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.561328888 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.561336040 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.561348915 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.561383009 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.561398029 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.561408997 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.561428070 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.561444044 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.561456919 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.561469078 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.561477900 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.561489105 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.561501980 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.561525106 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.561801910 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.561813116 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.561822891 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.561834097 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.561845064 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.561847925 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.561856031 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.561870098 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.561870098 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.561899900 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.561928988 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.561940908 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.561952114 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.561969995 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.561981916 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.642678022 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.642700911 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.642709970 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.642769098 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.642769098 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.642792940 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.642805099 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.642811060 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.642838955 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.642852068 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.642900944 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.642940044 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.642963886 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.642972946 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.642980099 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.643003941 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.643028975 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.643039942 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.643069983 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.643100023 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.643110991 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.643137932 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.643165112 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.643176079 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.643187046 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.643197060 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.643205881 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.643232107 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.643309116 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.643325090 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.643336058 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.643347025 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.643356085 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.643358946 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.643371105 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.643383026 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.643387079 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.643409014 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.643430948 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.643548012 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.643558979 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.643568993 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.643579006 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.643590927 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.643598080 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.643620968 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.643631935 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.643644094 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.643654108 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.643663883 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.643676996 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.643677950 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.643687963 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.643702984 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.643738031 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.766844988 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.766891003 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.766922951 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.766937971 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.766977072 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.766988993 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.766999960 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.767013073 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.767038107 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.767054081 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.767066002 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.767095089 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.767117977 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.767143011 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.767177105 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.767201900 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.767256975 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.767292023 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.767355919 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.767436028 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.767476082 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.767482996 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.767515898 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.767525911 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.767545938 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.767632961 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.767672062 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.767682076 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.767731905 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.767765999 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.767800093 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.767833948 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.767873049 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.767935991 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.767990112 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.768002033 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.768013954 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.768028975 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.768055916 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.768074989 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.768085003 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.768129110 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.768160105 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.768170118 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.768181086 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.768207073 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.768361092 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.768373013 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.768382072 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.768390894 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.768398046 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.768402100 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.768414021 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.768424988 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.768440008 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.768470049 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.768552065 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.768563032 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.768600941 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.768688917 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.768699884 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.768709898 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.768721104 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.768733025 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.768737078 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.768752098 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.768757105 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.768764973 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.768776894 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.768788099 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.768788099 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.768802881 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.768815041 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.768815041 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.768826962 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.768837929 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.768840075 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.768851042 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.768872023 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.768888950 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.769372940 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.769385099 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.769395113 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.769412041 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.769423008 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.769426107 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.769433975 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.769444942 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.769450903 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.769455910 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.769467115 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.769471884 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.769479036 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.769490004 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.769490004 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.769501925 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.769512892 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.769524097 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.769524097 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.769536972 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.769543886 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.769550085 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.769562006 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.769567013 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.769577026 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.769587994 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.769593954 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.769598961 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.769610882 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.769623995 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.769620895 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.769635916 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.769639969 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.769654989 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.770278931 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.770289898 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.770299911 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.770309925 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.770317078 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.770320892 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.770332098 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.770344019 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.770353079 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.770355940 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.770365000 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.770376921 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.770387888 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.770390034 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.770400047 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.770411015 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.770417929 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.770421982 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.770433903 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.770437002 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.770446062 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.770456076 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.770456076 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.770469904 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.770483971 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.770483971 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.770498037 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.770509005 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.770509005 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.770522118 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.770534039 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.770539999 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.770546913 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.770562887 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.770586967 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.771281004 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.771291971 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.771301985 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.771322012 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.771331072 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.771333933 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.771346092 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.771358013 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.771358967 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.771369934 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.771378994 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.771389961 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.771389961 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.771403074 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.771413088 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.771415949 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.771423101 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.771433115 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.771433115 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.771444082 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.771451950 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.771456003 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.771467924 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.771475077 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.771478891 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.771490097 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.771493912 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.771503925 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.771512985 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.771550894 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.853801012 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.853878021 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.853903055 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.853914976 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.853919983 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.853952885 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.853975058 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.854058027 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.854100943 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.854191065 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.854289055 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.854327917 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.854329109 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.854391098 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.854403019 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.854434013 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.854446888 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.854482889 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.854515076 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.854526043 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.854537964 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.854549885 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.854562044 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.854563951 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.854590893 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.854693890 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.854706049 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.854717970 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.854737997 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.854751110 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.854840994 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.854852915 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.854863882 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.854875088 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.854887962 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.854888916 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.854901075 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.854928970 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.854957104 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.855122089 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.855133057 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.855144024 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.855150938 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.855156898 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.855161905 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.855173111 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.855184078 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.855200052 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.855205059 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.855227947 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.855597019 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.855607986 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.855618000 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.855631113 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.855637074 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.855643034 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.855654001 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.855659962 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.855665922 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.855679035 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.855688095 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.855696917 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.855710030 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.855710983 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.855721951 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.855735064 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.855740070 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.855747938 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.855761051 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.855772018 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.855801105 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.855964899 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.855977058 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.855988979 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.856009960 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.856025934 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.856148005 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.856159925 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.856172085 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.856192112 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.856204987 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.856204987 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.856219053 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.856230974 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.856234074 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.856244087 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.856256962 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.856260061 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.856268883 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.856287003 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.856288910 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.856300116 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.856307030 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.856313944 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.856327057 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.856339931 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.856344938 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.856357098 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.856363058 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.856368065 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.856379032 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.856390953 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.856400967 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.856404066 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.856420040 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.856451035 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.857059002 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.857070923 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.857081890 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.857095957 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.857104063 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.857115984 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.857127905 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.857137918 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.857141018 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.857153893 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.857165098 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.857170105 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.857177973 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.857188940 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.857193947 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.857202053 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.857212067 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.857213974 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.857228994 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.857240915 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.857245922 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.857253075 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.857264996 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.857280016 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.857291937 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.857302904 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.857302904 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.857304096 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.857316971 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.857319117 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.857323885 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.857336998 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.857347965 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.857355118 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.857373953 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.857389927 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.857903957 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.857914925 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.857923985 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.857939005 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.857949972 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.857961893 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.857971907 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.857975006 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.857984066 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.857995987 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.858027935 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.940711021 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.977770090 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.977782011 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.977792025 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.977816105 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.977826118 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.977838039 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.977839947 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.977850914 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.977860928 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.977880001 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.977890968 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.977907896 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.977947950 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.977988958 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.978008986 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.978018999 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.978029966 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.978051901 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.978060961 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.978075981 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.978085041 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.978096008 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.978121996 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.978125095 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.978137970 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.978147030 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.978176117 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.978277922 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.978290081 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.978317976 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.978436947 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.978446960 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.978465080 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.978475094 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.978476048 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.978486061 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.978498936 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.978501081 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.978509903 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.978523970 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.978527069 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.978538036 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.978547096 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.978593111 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.978779078 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.978789091 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.978794098 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.978806973 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.978816986 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.978823900 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.978828907 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.978841066 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.978849888 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.978852034 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.978863955 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.978871107 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.978874922 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.978884935 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.978889942 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.978929996 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.979099035 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.979110003 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.979119062 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:37.979140043 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.979166985 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.996493101 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:37.997548103 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:38.001256943 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:38.002403975 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:38.002470016 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:38.029980898 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:38.034796000 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:38.904067993 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:38.959713936 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:39.209784031 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:39.214534044 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.277931929 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:39.282838106 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.282847881 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.282893896 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.282895088 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:39.282912970 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.282936096 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:39.282963037 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:39.282984018 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.282991886 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.283030987 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:39.283099890 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.283109903 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.283123970 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.283133030 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.283153057 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:39.283183098 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:39.287686110 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.287736893 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.287736893 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:39.287744999 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.287792921 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:39.287817001 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.287826061 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.287854910 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.287868977 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:39.287898064 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:39.287902117 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.287941933 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:39.287966967 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.288007975 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:39.288105965 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.288152933 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:39.288407087 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.288485050 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:39.292525053 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.292577982 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:39.292655945 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.292699099 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.292706013 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:39.292747021 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.292748928 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:39.292788029 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.292798996 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:39.292834044 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:39.292859077 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.292887926 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.292949915 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.292983055 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.293034077 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.293044090 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.293112040 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.293121099 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.293129921 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.293292046 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.293299913 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.293318033 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.293328047 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.293397903 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.293406963 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.293463945 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.293546915 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.293555021 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.293610096 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.293621063 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.293644905 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.293653011 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.293658018 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.297388077 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.297396898 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.297435045 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.297451973 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.297544003 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.297553062 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.297604084 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.297612906 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.297647953 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.297657013 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.297700882 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.297708988 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.297753096 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.297797918 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.297852993 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.297862053 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.297873020 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.337064028 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:39.341880083 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.405667067 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:39.410521030 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.410530090 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.410546064 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.410727978 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.410737038 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.448646069 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:39.453537941 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.453552008 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.453560114 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.453646898 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.453656912 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.453671932 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.496028900 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:39.502701998 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.502713919 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.502722025 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.502994061 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.503001928 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.503010035 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.559616089 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:39.566365957 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.566375017 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.566382885 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.566390991 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.566500902 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.566509962 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.615959883 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:39.620794058 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.645566940 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:39.650454998 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.686075926 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:39.690853119 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.742532015 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:39.747402906 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.747479916 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.770711899 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:39.775499105 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.786393881 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:39.791222095 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.817914963 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:39.822758913 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.848525047 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:39.853411913 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.888464928 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:39.893409014 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.928616047 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:39.933562994 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.957580090 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:39.962388992 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:39.997762918 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:40.002723932 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:40.046606064 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:40.051462889 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:40.084404945 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:40.089221954 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:40.116761923 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:40.121633053 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:40.146693945 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:40.151546001 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:40.177629948 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:40.182480097 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:40.220405102 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:40.225233078 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:40.265697002 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:40.270633936 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:40.303904057 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:40.308785915 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:40.352960110 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:40.357831001 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:40.377258062 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:40.382105112 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:40.404376984 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:40.409224033 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:40.444221020 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:40.449039936 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:40.482353926 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:40.487262964 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:40.514352083 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:40.520543098 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:40.545738935 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:40.550604105 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:40.608810902 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:40.613595009 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:40.639219046 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:40.644097090 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:40.669639111 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:40.674520016 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:40.710108995 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:40.714921951 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:40.747462034 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:40.752305031 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:40.787897110 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:40.792716980 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:40.826674938 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:40.831556082 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:40.857072115 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:40.861871004 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:40.889347076 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:40.894182920 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:40.937077999 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:40.941936970 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:40.975713015 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:40.981816053 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:41.015925884 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:41.020791054 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:41.053564072 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:41.058312893 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:41.100498915 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:41.105638027 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:41.139015913 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:41.143812895 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:41.178546906 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:41.183360100 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:41.217113018 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:41.222021103 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:41.249783993 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:41.255382061 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:41.284473896 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:41.290091991 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:41.311042070 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:41.317401886 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:41.341607094 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:41.346512079 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:41.381721973 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:41.386554003 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:41.428642988 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:41.433439970 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:41.475471020 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:41.481893063 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:41.522245884 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:41.527209997 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:41.570277929 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:41.575083017 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:41.616372108 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:41.621251106 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:41.663100958 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:41.667865992 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:41.701838017 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:41.706640959 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:41.741173983 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:41.746031046 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:41.780694008 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:41.785530090 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:41.810868979 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:41.815676928 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:41.850430012 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:41.855247021 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:41.897314072 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:41.902209044 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:41.937158108 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:41.941968918 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:41.973118067 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:41.977900028 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:42.006618977 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:42.011461973 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:42.053495884 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:42.058377981 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:42.100450039 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:42.105258942 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:42.147382021 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:42.152179956 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:42.194259882 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:42.199067116 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:42.241017103 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:42.245839119 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:42.287905931 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:42.292746067 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:42.334955931 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:42.339801073 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:42.374066114 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:42.378858089 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:42.404452085 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:42.409338951 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:42.437094927 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:42.441900015 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:42.475528002 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:42.480370998 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:42.514311075 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:42.519156933 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:42.544658899 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:42.549473047 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:42.584773064 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:42.589668036 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:42.632036924 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:42.636847973 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:42.678620100 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:42.683434963 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:42.725527048 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:42.730325937 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:42.772313118 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:42.777076960 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:42.819247007 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:42.824223995 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:42.859891891 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:42.864675045 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:42.890583992 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:42.895360947 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:42.928513050 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:42.933382988 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:42.975687981 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:42.981093884 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:43.022336006 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:43.027163982 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:43.069184065 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:43.074032068 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:43.116134882 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:43.120924950 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:43.162914038 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:43.167808056 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:43.209800959 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:43.359159946 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:43.359252930 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:43.364011049 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:43.389334917 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:43.394144058 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:43.421112061 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:43.425923109 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:43.452795982 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:43.457631111 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:43.491038084 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:43.495840073 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:43.538065910 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:43.542980909 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:43.542990923 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:43.542998075 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:43.543020010 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:43.593833923 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:43.598649979 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:43.598663092 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:43.598671913 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:43.598798990 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:43.598808050 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:43.631931067 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:43.636743069 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:43.678617001 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:43.684520006 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:43.709822893 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:43.714596987 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:43.756719112 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:43.761534929 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:43.812612057 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:43.817429066 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:43.817437887 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:43.817473888 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:43.817584038 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:43.817595959 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:43.850560904 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:43.855400085 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:43.889573097 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:43.894610882 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:43.904797077 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:43.909605026 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:43.944152117 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:43.948995113 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:43.991036892 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:43.995955944 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:44.031505108 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:44.036422014 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:44.061219931 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:44.066031933 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:44.100415945 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:44.105284929 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:44.147363901 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:44.152128935 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:44.188652039 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:44.193492889 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:44.219343901 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:44.224208117 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:44.256649971 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:44.261719942 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:44.303518057 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:44.308337927 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:44.350545883 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:44.355422020 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:44.397439003 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:44.402261019 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:44.436793089 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:44.441673994 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:44.484357119 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:44.489535093 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:44.489542961 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:44.489553928 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:44.522387028 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:44.527154922 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:44.569148064 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:44.573944092 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:44.616111994 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:44.620997906 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:44.654565096 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:44.659409046 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:44.694298983 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:44.699111938 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:44.741131067 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:44.745950937 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:44.788075924 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:44.792948008 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:44.834970951 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:44.839898109 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:44.874603987 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:44.879455090 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:44.904433966 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:44.909321070 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:44.944302082 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:44.949150085 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:44.991127968 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:44.995955944 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:45.043665886 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:45.048444986 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:45.072010994 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:45.250853062 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:45.264307976 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:45.264317989 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:45.264324903 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:45.264503956 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:45.264513016 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:45.264516115 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:45.313432932 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:45.319644928 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:45.319655895 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:45.319663048 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:45.319674015 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:45.319681883 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:45.319691896 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:45.360521078 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:45.367161989 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:45.367180109 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:45.367580891 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:45.369469881 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:45.369478941 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:45.369642973 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:45.431435108 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:45.438093901 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:45.438107014 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:45.438116074 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:45.440324068 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:45.440331936 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:45.440335035 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:45.446573973 CET44334973723.226.57.67192.168.2.4
          Jan 2, 2025 12:07:45.446696997 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:45.446809053 CET497374433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:46.753889084 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:46.758723021 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:52.053503990 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:07:52.058347940 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:52.356215954 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:07:52.397205114 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:08:08.084808111 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:08:08.089641094 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:08:08.387383938 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:08:08.428409100 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:08:24.444128990 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:08:24.448879957 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:08:24.746865988 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:08:24.834688902 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:08:40.069246054 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:08:40.074079990 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:08:40.518789053 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:08:40.569125891 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:08:55.959826946 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:08:55.964811087 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:08:56.262536049 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:08:56.303507090 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:09:12.069235086 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:09:12.074172020 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:09:12.372181892 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:09:12.428565025 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:09:28.230220079 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:09:28.230384111 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:09:28.235205889 CET44334973023.226.57.67192.168.2.4
          Jan 2, 2025 12:09:28.235263109 CET497304433192.168.2.423.226.57.67
          Jan 2, 2025 12:09:33.382406950 CET5000410443192.168.2.423.226.57.67
          Jan 2, 2025 12:09:33.387336969 CET104435000423.226.57.67192.168.2.4
          Jan 2, 2025 12:09:33.387398958 CET5000410443192.168.2.423.226.57.67
          Jan 2, 2025 12:09:34.476470947 CET5000410443192.168.2.423.226.57.67
          Jan 2, 2025 12:09:34.481393099 CET104435000423.226.57.67192.168.2.4
          Jan 2, 2025 12:09:34.481406927 CET104435000423.226.57.67192.168.2.4
          Jan 2, 2025 12:09:34.481419086 CET104435000423.226.57.67192.168.2.4
          Jan 2, 2025 12:09:34.481571913 CET104435000423.226.57.67192.168.2.4
          Jan 2, 2025 12:09:35.041724920 CET104435000423.226.57.67192.168.2.4
          Jan 2, 2025 12:09:35.084837914 CET5000410443192.168.2.423.226.57.67
          Jan 2, 2025 12:09:35.195769072 CET5000410443192.168.2.423.226.57.67
          Jan 2, 2025 12:09:35.200592041 CET104435000423.226.57.67192.168.2.4
          Jan 2, 2025 12:09:35.200603962 CET104435000423.226.57.67192.168.2.4
          Jan 2, 2025 12:09:35.200615883 CET104435000423.226.57.67192.168.2.4
          Jan 2, 2025 12:09:35.200643063 CET5000410443192.168.2.423.226.57.67
          Jan 2, 2025 12:09:35.205373049 CET104435000423.226.57.67192.168.2.4
          Jan 2, 2025 12:09:49.835047007 CET5000410443192.168.2.423.226.57.67
          Jan 2, 2025 12:09:49.835117102 CET5000410443192.168.2.423.226.57.67
          Jan 2, 2025 12:09:49.841543913 CET104435000423.226.57.67192.168.2.4
          Jan 2, 2025 12:09:49.841593027 CET5000410443192.168.2.423.226.57.67
          Jan 2, 2025 12:09:54.804070950 CET500054433192.168.2.423.226.57.67
          Jan 2, 2025 12:09:54.809000015 CET44335000523.226.57.67192.168.2.4
          Jan 2, 2025 12:09:54.810734034 CET500054433192.168.2.423.226.57.67
          Jan 2, 2025 12:09:55.611442089 CET500054433192.168.2.423.226.57.67
          Jan 2, 2025 12:09:55.616508007 CET44335000523.226.57.67192.168.2.4
          Jan 2, 2025 12:09:55.616544008 CET44335000523.226.57.67192.168.2.4
          Jan 2, 2025 12:09:55.616559982 CET44335000523.226.57.67192.168.2.4
          Jan 2, 2025 12:09:55.616580009 CET44335000523.226.57.67192.168.2.4
          Jan 2, 2025 12:09:55.968511105 CET44335000523.226.57.67192.168.2.4
          Jan 2, 2025 12:09:56.022406101 CET500054433192.168.2.423.226.57.67
          Jan 2, 2025 12:09:56.094578981 CET500054433192.168.2.423.226.57.67
          Jan 2, 2025 12:09:56.099737883 CET44335000523.226.57.67192.168.2.4
          Jan 2, 2025 12:09:56.099791050 CET44335000523.226.57.67192.168.2.4
          Jan 2, 2025 12:09:56.099822998 CET44335000523.226.57.67192.168.2.4
          Jan 2, 2025 12:09:56.099858999 CET500054433192.168.2.423.226.57.67
          Jan 2, 2025 12:09:56.104732990 CET44335000523.226.57.67192.168.2.4
          Jan 2, 2025 12:10:11.616270065 CET500054433192.168.2.423.226.57.67
          Jan 2, 2025 12:10:11.616368055 CET500054433192.168.2.423.226.57.67
          Jan 2, 2025 12:10:11.621400118 CET44335000523.226.57.67192.168.2.4
          Jan 2, 2025 12:10:11.622323036 CET500054433192.168.2.423.226.57.67
          Jan 2, 2025 12:10:16.713884115 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:16.718921900 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:16.719011068 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:18.067531109 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:18.072599888 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:18.072671890 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:18.072715044 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:18.072757959 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:18.643193960 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:18.694303989 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:18.738641024 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:18.743709087 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:18.743756056 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:18.743777037 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:18.743817091 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:18.748661041 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:23.912121058 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:23.912192106 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:23.912242889 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:23.912311077 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:23.912345886 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:23.912400961 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:23.912683964 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:23.917536020 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:23.917696953 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:23.917737961 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.237920046 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.237972975 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.238039970 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.238073111 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.238115072 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.238162994 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.238209963 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.238240957 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.238291025 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.238308907 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.238362074 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.238416910 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.238430023 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.238471985 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.238519907 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.238728046 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.238775015 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.238845110 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.238857985 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.238903046 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.238950968 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.239335060 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.243396997 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.243457079 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.243484974 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.243526936 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.243613958 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.457086086 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.457186937 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.457253933 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.457313061 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.457376957 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.457422972 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.457472086 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.457485914 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.457524061 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.457552910 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.457598925 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.457643032 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.457698107 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.457712889 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.457748890 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.457777977 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.457859039 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.457906008 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.457952023 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.457969904 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.458023071 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.458034992 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.458221912 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.458287001 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.458337069 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.458353996 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.458410025 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.458422899 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.458466053 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.458512068 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.458571911 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.458982944 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.459036112 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.459063053 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.459110022 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.459156036 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.459209919 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.459223032 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.459260941 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.459285975 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.459361076 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.459408045 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.459469080 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.459856033 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.459927082 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.459939957 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.506808996 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.675980091 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.676076889 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.676146030 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.676167965 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.676214933 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.676280975 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.676327944 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.676347971 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.676419020 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.676448107 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.676492929 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.676538944 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.676598072 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.676618099 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.676671028 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.676697969 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.676759958 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.676808119 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.676856041 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.676868916 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.676898003 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.676953077 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.677000046 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.677046061 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.677090883 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.677110910 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.677156925 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.677175045 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.677220106 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.677263021 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.677288055 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.677328110 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.677542925 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.677594900 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.677623034 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.677670002 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.677690029 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.677748919 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.677795887 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.677840948 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.677859068 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.677902937 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.677923918 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.677968025 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.678014040 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.678056002 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.678077936 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.678138018 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.678394079 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.678440094 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.678503036 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.678555012 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.678569078 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.678601027 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.678631067 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.678690910 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.678738117 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.678782940 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.678801060 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.678847075 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.678865910 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.678913116 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.679234028 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.679289103 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.679332972 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.679385900 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.679413080 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.679459095 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.679503918 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.679554939 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.679582119 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.679627895 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.679646969 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.679692030 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.679735899 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.679780006 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.679801941 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.679843903 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.680191040 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.680238008 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.683264971 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.766983032 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.767052889 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.767136097 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.895391941 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.895482063 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.895530939 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.895561934 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.895613909 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.895679951 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.895730972 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.895750046 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.895808935 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.895823002 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.895849943 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.895869970 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.895889044 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.895910978 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.895917892 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.895940065 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.895947933 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.895966053 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.895987034 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.896002054 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.896009922 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.896028996 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.896039009 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.896070004 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.896075964 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.896095037 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.896111965 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.896132946 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.896157026 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.896172047 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.896178961 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.896198034 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.896218061 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.896234989 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.896259069 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.896265984 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.896281958 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.896300077 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.896320105 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.896346092 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.896356106 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.896373034 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.896382093 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.896399021 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.896418095 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.896437883 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.896452904 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.896482944 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.896498919 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.896517038 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.896538973 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.896559000 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.896573067 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.896583080 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.896599054 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.896605968 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.896905899 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.896934986 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.896949053 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.896958113 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.896975040 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.897085905 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.897104979 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.897129059 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.897135973 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.897152901 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.897192955 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.897377014 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.897396088 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.897418022 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.897437096 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.897448063 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.897458076 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.897475004 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.897492886 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.897515059 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.897530079 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.897558928 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.897727966 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.897746086 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.897768974 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.897789955 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.897804022 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.897813082 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.897829056 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.897839069 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.897859097 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.897871971 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.897881031 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.897901058 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.897943020 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.898341894 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.898360014 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.898380995 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.898399115 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.898412943 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.898420095 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.898437977 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.898457050 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.898477077 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.898489952 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.898523092 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.898538113 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.898672104 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.898689985 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.898711920 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.898727894 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.898741007 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.898756027 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.898766994 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.898786068 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.898799896 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.898808002 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.898825884 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.898864031 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.899228096 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.899266005 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.899283886 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.899305105 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.899393082 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.899413109 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.899430037 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.899440050 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.899454117 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.899540901 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.899555922 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.899578094 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.899594069 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.899620056 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.899673939 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.899703026 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.899729967 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.899744987 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.899753094 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.899771929 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.899794102 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.899807930 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.899821043 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.899828911 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.900274038 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.900291920 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.900319099 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.900327921 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.900355101 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.986027956 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.986140966 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.986164093 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.986202002 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.986219883 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.986241102 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.986258030 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.986270905 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.986290932 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.986304045 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.986321926 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.986342907 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.986361980 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.986377954 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:24.986390114 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:24.986404896 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.038184881 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.114166975 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.114253998 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.114321947 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.114392996 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.114420891 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.114489079 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.114521027 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.114578962 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.114640951 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.114697933 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.114722013 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.114774942 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.114800930 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.114845991 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.114905119 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.114949942 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.114969969 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.115015984 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.115032911 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.115093946 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.115140915 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.115190983 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.115217924 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.115266085 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.115283966 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.115390062 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.115437031 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.115483999 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.115502119 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.115552902 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.115578890 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.115638971 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.115684032 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.115730047 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.115748882 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.115794897 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.115812063 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.115855932 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.115900040 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.115950108 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.115977049 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.116019964 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.116039991 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.116085052 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.116130114 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.116174936 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.116192102 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.116225004 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.116242886 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.116290092 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.116333961 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.116380930 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.116401911 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.116445065 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.116465092 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.116509914 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.116554022 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.116595984 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.116616011 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.116661072 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.116679907 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.116724968 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.116769075 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.116807938 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.116832018 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.116873980 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.116893053 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.116936922 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.116981983 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.117026091 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.117044926 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.117086887 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.117108107 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.117153883 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.117197990 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.117238045 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.117260933 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.117306948 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.117352962 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.117372036 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.117418051 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.117438078 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.117481947 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.117526054 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.117567062 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.117590904 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.117634058 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.117655993 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.117700100 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.117743969 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.117788076 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.117808104 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.117850065 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.117872953 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.117918015 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.122843027 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.122884989 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.122909069 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.122936010 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.122984886 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.123028994 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.123090029 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.123136044 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.123153925 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.123207092 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.123239040 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.123285055 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.123353004 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.123399973 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.123461008 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.123522043 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.123574972 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.123588085 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.123619080 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.123666048 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.123728991 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.123773098 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.123825073 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.123846054 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.123873949 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.123919964 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.123961926 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.124021053 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.124068975 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.124085903 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.124176025 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.124196053 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.124258995 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.124304056 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.124347925 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.124372005 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.124397993 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.124442101 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.124488115 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.124531984 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.124583960 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.124597073 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.124629021 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.124658108 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.124702930 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.124746084 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.124799013 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.124810934 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.124839067 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.124869108 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.124913931 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.124958038 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.125005007 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.125021935 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.125072956 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.125086069 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.125129938 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.125174046 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.125219107 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.125238895 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.125293016 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.125305891 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.125349045 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.125392914 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.125442028 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.125466108 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.125508070 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.125529051 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.125574112 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.125617027 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.125663996 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.125683069 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.125725985 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.125746012 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.125790119 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.125833988 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.125879049 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.125896931 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.125938892 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.125962019 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.126007080 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.126271963 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.205085039 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.205142975 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.205224037 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.205282927 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.205348969 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.205396891 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.205435991 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.205523014 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.205573082 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.205631971 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.205674887 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.205704927 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.205749035 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.205796957 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.205837011 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.205895901 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.205924034 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.205965996 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.206001043 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.206043959 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.206088066 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.206130981 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.206172943 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.206223965 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.206249952 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.206311941 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.206357956 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.206408024 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.206434011 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.206478119 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.206499100 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.206541061 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.206607103 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.206648111 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.206671953 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.206724882 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.206738949 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.206795931 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.206840992 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.206885099 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.206906080 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.206950903 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.206969023 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.207014084 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.207077026 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.207123041 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.207142115 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.207195044 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.207221985 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.207269907 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.207334042 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.207376957 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.207416058 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.207458019 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.207473993 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.207516909 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.207580090 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.207634926 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.207648039 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.207676888 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.207722902 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.207767963 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.207812071 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.207858086 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.207875967 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.207921028 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.207940102 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.207983971 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.208029985 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.208081007 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.208107948 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.208151102 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.208173990 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.208226919 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.208276987 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.208323002 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.208340883 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.208380938 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.208405972 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.208451033 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.208494902 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.208534956 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.208559036 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.208605051 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.208622932 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.208667040 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.208713055 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.208754063 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.208775043 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.208821058 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.208838940 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.208884001 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.208929062 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.208972931 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.208992958 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.209039927 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.209060907 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.209105015 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.209150076 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.209202051 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.209214926 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.209244967 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.209275007 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.209321022 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.209363937 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.209383965 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.209429026 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.209472895 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.209517002 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.209541082 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.209558010 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.209594965 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.209654093 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.209697008 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.209749937 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.209763050 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.209801912 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.209830046 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.209878922 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.209923983 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.209948063 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.209985018 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.210030079 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.210052967 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.210082054 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.210135937 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.210148096 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.210191011 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.210243940 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.210257053 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.210299015 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.210331917 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.210390091 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.210432053 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.210458994 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.210484028 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.210520029 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.210566044 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.210588932 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.210633993 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.210685968 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.210702896 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.210747957 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.210793972 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.210846901 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.210860014 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.210906982 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.210923910 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.256835938 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.332829952 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.332917929 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.332973003 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.333003044 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.333051920 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.333097935 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.333118916 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.333158970 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.333209991 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.333237886 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.333301067 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.333339930 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.333380938 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.333424091 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.333487988 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.333524942 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.333568096 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.333630085 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.333657026 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.333730936 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.333792925 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.333822012 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.333879948 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.333934069 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.333961010 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.334007025 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.334059954 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.334073067 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.334131956 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.334186077 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.334213018 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.334260941 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.334307909 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.334331036 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.334431887 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.334481001 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.334510088 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.334544897 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.334608078 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.334628105 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.334672928 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.334721088 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.334774017 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.334800959 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.334851027 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.334870100 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.334932089 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.334985971 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.335000038 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.335042000 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.335098982 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.335128069 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.335187912 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.335232019 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.335256100 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.335303068 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.335362911 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.335386992 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.335439920 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.335484982 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.335506916 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.335551977 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.335613966 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.335634947 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.335676908 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.335725069 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.335741043 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.335803032 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.335850954 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.335867882 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.335916042 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.335963011 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.335983992 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.336028099 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.336085081 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.336097956 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.336158991 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.336198092 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.336224079 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.336289883 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.336334944 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.336354971 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.336395979 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.336447954 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.336460114 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.336503029 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.336549044 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.336569071 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.336612940 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.336663008 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.336682081 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.336741924 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.336796999 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.336810112 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.336853981 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.336909056 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.336921930 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.336965084 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.337009907 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.337035894 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.337074041 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.337122917 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.337138891 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.337184906 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.337230921 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.337259054 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.337296009 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.337341070 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.337367058 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.337404013 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.337455034 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.337474108 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.337512016 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.337555885 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.337577105 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.337624073 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.337676048 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.337692976 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.337737083 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.337781906 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.337804079 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.337846994 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.337891102 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.337909937 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.337953091 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.338006020 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.338020086 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.338061094 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.338104963 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.338125944 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.338171005 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.338222980 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.338236094 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.338278055 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.338325024 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.338345051 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.338387966 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.338440895 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.338454008 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.338495970 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.338541031 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.338566065 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.338596106 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.338629961 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.338659048 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.338704109 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.338757992 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.338771105 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.338814020 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.338864088 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.338896036 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.338929892 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.338974953 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.339013100 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.339040995 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.339085102 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.339123011 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.339152098 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.339198112 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.339240074 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.339263916 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.339309931 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.339361906 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.339385986 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.339426994 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.339452028 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.339498043 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.339540005 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.339564085 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.339610100 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.339653969 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.339684963 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.339720011 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.339806080 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.423794031 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.423846006 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.423902988 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.423933983 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.423980951 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.424036026 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.424048901 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.424091101 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.424134970 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.424158096 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.424197912 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.424253941 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.424267054 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.424310923 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.424385071 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.424417973 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.424463987 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.424511909 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.424535990 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.424590111 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.424624920 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.424653053 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.424704075 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.424761057 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.424802065 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.424850941 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.424890041 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.424915075 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.424959898 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.425004959 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.425029039 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.425059080 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.425101995 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.425124884 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.438288927 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.439619064 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.443136930 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.444552898 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:25.444632053 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.476169109 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:25.481046915 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.342257023 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.397438049 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:26.647563934 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:26.652512074 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.719913960 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:26.724773884 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.724796057 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.724827051 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:26.724838972 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.724847078 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:26.724858999 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.724878073 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.724895000 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:26.724915981 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:26.724947929 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.724978924 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.724994898 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.725013018 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.725022078 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:26.725043058 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:26.725054026 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.725063086 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:26.725101948 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:26.729610920 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.729655027 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:26.729718924 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.729737043 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.729773045 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:26.729829073 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.729852915 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.729871988 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:26.729891062 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:26.729893923 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.729931116 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.729969025 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:26.729978085 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.729985952 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:26.730019093 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.730029106 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:26.730058908 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:26.730093956 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.730110884 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.730130911 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:26.730139017 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.730149031 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:26.730185032 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:26.734468937 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.734515905 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:26.734528065 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.734563112 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.734581947 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:26.734611034 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:26.734636068 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.734709978 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.734714985 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:26.734755039 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:26.734814882 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.734834909 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.734869957 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:26.734911919 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.734992981 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.735080004 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.735105991 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.735205889 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.735224962 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.735280037 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.735296965 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.735357046 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.735373974 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.735389948 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.735405922 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.735466957 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.735482931 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.735498905 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.735515118 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.735531092 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.735547066 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.735563993 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.735579967 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.739372969 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.739389896 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.739415884 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.739432096 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.739464998 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.739480972 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.739506006 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.739533901 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.739609003 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.739626884 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.739653111 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.739667892 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.739713907 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.739729881 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.739748001 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.739805937 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.739823103 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.739839077 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.739865065 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.739878893 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.739906073 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.739922047 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.800003052 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:26.804860115 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.804888010 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.804904938 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.804924011 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.805002928 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.805020094 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.828789949 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:26.833648920 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.833667994 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.833686113 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.833720922 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.833738089 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.923448086 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:26.928302050 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.928322077 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.928340912 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.928423882 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.971204996 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:26.975963116 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:26.976063967 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:27.003215075 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:27.007997036 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:27.038674116 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:27.043428898 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:27.088291883 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:27.093087912 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:27.135448933 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:27.140265942 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:27.192611933 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:27.197469950 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:27.247960091 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:27.252775908 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:27.276489973 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:27.281246901 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:27.305610895 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:27.310411930 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:27.338248968 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:27.343075037 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:27.381012917 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:27.385807991 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:27.511348009 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:27.516225100 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:27.639259100 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:27.644139051 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:27.743343115 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:27.748492002 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:27.772530079 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:27.777446985 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:27.809304953 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:27.814182043 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:27.841275930 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:27.846240997 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:27.901384115 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:27.906194925 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:27.940047026 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:27.944860935 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:27.974265099 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:27.979082108 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:28.002985954 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:28.007890940 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:28.036005974 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:28.040813923 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:28.076508045 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:28.081357956 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:28.207248926 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:28.212064028 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:28.306935072 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:28.311877012 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:28.332115889 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:28.336988926 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:28.379771948 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:28.384685040 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:28.407248974 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:28.412144899 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:28.421890974 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:28.426685095 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:28.437433004 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:28.442275047 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:28.488050938 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:28.493045092 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:28.493077040 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:28.493094921 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:28.493290901 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:28.493319988 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:28.533642054 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:28.538676023 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:28.538738966 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:28.538779020 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:28.538841009 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:28.538880110 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:28.538939953 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:28.567212105 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:28.572228909 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:28.572274923 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:28.572315931 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:28.572380066 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:28.572417021 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:28.572457075 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:28.618002892 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:28.623004913 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:28.623049974 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:28.623090029 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:28.623169899 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:28.623212099 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:28.623267889 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:28.676712990 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:28.681642056 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:28.681706905 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:28.681746006 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:28.681859016 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:28.681899071 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:28.681941986 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:28.705919981 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:28.710841894 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:28.718627930 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:28.723540068 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:28.752171993 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:28.757162094 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:28.768729925 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:28.773685932 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:28.784362078 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:28.789272070 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:28.798533916 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:28.803391933 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:28.812310934 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:28.817147017 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:28.827367067 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:28.832340956 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:28.858803988 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:28.863862038 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:28.874455929 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:28.879367113 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:28.892219067 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:28.897250891 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:29.008758068 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:29.013886929 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:29.013930082 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:29.070924997 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:29.076105118 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:29.110129118 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:29.115053892 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:29.144464970 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:29.149509907 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:29.175339937 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:29.180238962 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:29.229033947 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:29.233891010 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:29.297125101 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:29.302161932 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:29.323340893 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:29.328231096 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:29.357105017 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:29.361947060 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:29.376899958 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:29.381831884 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:29.390847921 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:29.395704031 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:29.420706987 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:29.425677061 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:29.451373100 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:29.456223965 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:29.467147112 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:29.472088099 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:29.498461008 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:29.503360987 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:29.529891014 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:29.534768105 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:29.545855045 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:29.550789118 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:29.560894012 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:29.565799952 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:29.593734980 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:29.598683119 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:29.641634941 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:29.646526098 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:29.671155930 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:29.676120043 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:29.686454058 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:29.691376925 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:29.701790094 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:29.706665039 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:29.733449936 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:29.738313913 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:29.748907089 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:29.753818989 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:29.780491114 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:29.785408974 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:29.795383930 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:29.800307035 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:29.811131001 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:29.816050053 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:29.842696905 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:29.847589970 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:29.873490095 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:29.878433943 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:29.889144897 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:29.894040108 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:29.905661106 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:29.910554886 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:29.938044071 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:29.942986012 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:29.973807096 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:29.978666067 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:29.983844995 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:29.988744020 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:30.015258074 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:30.020117044 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:30.045557022 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:30.050503016 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:30.060625076 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:30.065499067 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:30.098725080 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:30.103682041 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:30.127413034 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:30.132280111 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:30.155004978 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:30.159935951 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:30.189933062 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:30.194844007 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:30.217324018 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:30.222167015 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:30.233023882 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:30.237848997 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:30.248394966 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:30.253235102 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:30.282479048 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:30.287350893 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:30.317568064 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:30.322422981 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:30.327357054 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:30.332226038 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:30.358587027 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:30.363483906 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:30.373719931 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:30.378567934 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:30.389147997 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:30.394011021 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:30.421957970 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:30.426856995 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:30.451586962 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:30.456448078 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:30.487816095 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:30.492734909 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:30.518851995 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:30.523756981 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:30.545991898 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:30.550899029 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:30.576878071 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:30.582164049 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:30.611799955 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:30.616739988 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:30.648245096 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:30.653182983 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:30.687480927 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:30.692451000 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:30.703634024 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:30.708460093 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:30.719532013 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:30.724354982 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:30.751238108 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:30.756181002 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:30.766355038 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:30.771195889 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:30.780939102 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:30.785909891 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:30.813939095 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:30.818861961 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:30.828979969 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:30.833901882 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:30.845494986 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:30.850368023 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:30.874946117 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:30.879801989 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:30.906299114 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:30.911365032 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:30.936845064 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:30.941663027 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:30.953613043 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:30.958580017 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:30.988933086 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:30.993822098 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:30.999407053 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:31.004779100 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:31.030147076 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:31.035083055 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:31.045598030 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:31.050587893 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:31.076174974 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:31.081242085 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:31.092838049 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:31.097774029 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:31.108831882 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:31.113627911 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:31.124706030 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:31.129468918 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:31.156287909 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:31.161067009 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:31.186228037 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:31.191014051 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:31.201529026 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:31.206382036 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:31.233618975 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:31.238481045 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:31.270354033 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:31.275181055 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:31.280409098 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:31.285271883 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:31.312916040 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:31.317789078 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:31.360049963 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:31.364917994 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:31.391155958 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:31.395912886 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:31.455883980 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:31.460678101 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:31.483282089 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:31.488130093 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:31.515686989 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:31.520709991 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:31.545878887 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:31.551107883 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:31.561306953 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:31.566309929 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:31.592097044 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:31.597029924 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:31.608177900 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:31.613087893 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:31.624171972 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:31.629103899 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:31.736615896 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:31.741569996 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:31.751121044 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:31.756052017 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:31.792525053 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:31.797465086 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:31.828278065 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:31.833188057 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:31.846442938 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:31.851366997 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:31.897459030 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:31.902379990 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:31.921977997 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:31.926801920 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:31.958937883 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:31.968859911 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:32.025821924 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:32.030842066 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:32.063182116 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:32.068125010 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:32.077233076 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:32.082091093 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:32.108207941 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:32.113125086 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:32.140160084 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:32.145044088 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:32.171801090 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:32.176783085 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:32.186028957 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:32.190939903 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:32.217955112 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:32.222899914 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:32.232953072 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:32.237817049 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:32.248903990 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:32.253729105 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:32.280260086 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:32.285093069 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:32.311598063 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:32.316436052 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:32.344046116 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:32.348856926 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:32.395374060 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:32.400198936 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:32.405267000 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:32.410048962 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:32.420870066 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:32.425705910 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:32.451786995 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:32.456635952 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:32.483867884 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:32.488677979 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:32.498470068 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:32.503266096 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:32.532598019 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:32.537437916 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:32.563239098 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:32.568104982 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:32.578658104 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:32.583530903 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:32.594198942 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:32.599028111 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:32.626390934 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:32.631187916 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:32.642621040 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:32.647406101 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:32.675486088 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:32.680289984 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:32.726874113 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:32.731697083 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:32.766221046 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:32.771081924 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:32.781184912 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:32.785954952 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:32.811135054 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:32.816034079 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:32.842547894 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:32.847346067 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:32.857695103 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:32.862492085 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:32.873370886 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:32.878190994 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:32.904910088 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:32.909823895 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:32.920581102 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:32.925453901 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:32.935970068 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:32.940841913 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:32.951898098 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:32.956737995 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:32.967385054 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:32.972254038 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:32.998424053 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:33.003451109 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:33.016216040 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:33.021024942 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:33.066134930 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:33.071037054 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:33.092770100 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:33.097657919 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:33.108134985 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:33.113099098 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:33.123610020 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:33.128544092 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:33.155045033 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:33.159976959 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:33.170646906 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:33.175563097 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:33.186182976 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:33.203016043 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:33.203063011 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:33.207875013 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:33.217909098 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:33.222687006 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:33.235016108 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:33.239864111 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:33.249836922 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:33.258390903 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:33.280337095 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:33.285186052 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:33.311702013 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:33.316575050 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:33.343977928 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:33.348875999 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:33.359407902 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:33.364326000 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:33.412545919 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:33.417406082 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:33.421410084 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:33.426265955 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:33.452445984 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:33.457328081 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:33.468952894 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:33.473790884 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:33.499258995 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:33.504066944 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:33.529877901 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:33.534718037 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:33.545700073 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:33.550496101 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:33.561392069 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:33.566252947 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:33.592967033 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:33.597839117 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:33.623871088 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:33.628829956 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:33.639326096 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:33.644208908 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:33.670747995 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:33.675688982 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:33.705236912 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:33.710129976 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:33.738014936 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:33.742845058 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:33.748303890 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:33.753118992 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:33.763873100 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:33.768773079 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:33.795533895 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:33.800373077 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:33.811131001 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:33.815937042 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:33.842510939 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:33.847348928 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:33.857800007 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:33.862603903 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:33.889552116 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:33.894366980 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:33.905878067 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:33.910698891 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:33.936105013 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:33.940943003 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:33.951626062 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:33.956487894 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:33.967437983 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:33.972227097 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:33.998538017 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:34.003401995 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:34.014405012 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:34.019176006 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:34.030225992 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:34.035000086 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:34.046926022 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:34.051703930 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:34.098268986 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:34.103106022 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:34.141632080 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:34.146554947 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:34.155172110 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:34.159948111 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:34.186121941 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:34.190995932 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:34.201690912 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:34.207974911 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:34.217600107 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:34.222410917 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:34.248672009 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:34.253505945 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:34.264854908 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:34.269630909 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:34.279908895 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:34.284702063 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:34.311356068 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:34.316190958 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:34.326728106 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:34.331572056 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:34.337662935 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:34.342477083 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:34.342516899 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:34.347328901 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:34.374350071 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:34.379249096 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:34.388144970 CET104435000723.226.57.67192.168.2.4
          Jan 2, 2025 12:10:34.388211012 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:34.388309956 CET5000710443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:34.652780056 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:34.694331884 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:35.663234949 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:35.668133974 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:45.776554108 CET104435000623.226.57.67192.168.2.4
          Jan 2, 2025 12:10:45.819375992 CET5000610443192.168.2.423.226.57.67
          Jan 2, 2025 12:10:46.341161013 CET5000610443192.168.2.423.226.57.67
          TimestampSource PortDest PortSource IPDest IP
          Jan 2, 2025 12:10:55.496804953 CET5749753192.168.2.41.1.1.1
          Jan 2, 2025 12:12:56.500883102 CET5373853192.168.2.41.1.1.1
          TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
          Jan 2, 2025 12:10:55.496804953 CET192.168.2.41.1.1.10x50e9Standard query (0)api.msn.comA (IP address)IN (0x0001)false
          Jan 2, 2025 12:12:56.500883102 CET192.168.2.41.1.1.10x65e0Standard query (0)tse1.mm.bing.netA (IP address)IN (0x0001)false
          TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
          Jan 2, 2025 12:10:55.503990889 CET1.1.1.1192.168.2.40x50e9No error (0)api.msn.comapi-msn-com.a-0003.a-msedge.netCNAME (Canonical name)IN (0x0001)false
          Jan 2, 2025 12:12:56.507643938 CET1.1.1.1192.168.2.40x65e0No error (0)tse1.mm.bing.netmm-mm.bing.net.trafficmanager.netCNAME (Canonical name)IN (0x0001)false
          Jan 2, 2025 12:12:56.507643938 CET1.1.1.1192.168.2.40x65e0No error (0)ax-0001.ax-msedge.net150.171.28.10A (IP address)IN (0x0001)false
          Jan 2, 2025 12:12:56.507643938 CET1.1.1.1192.168.2.40x65e0No error (0)ax-0001.ax-msedge.net150.171.27.10A (IP address)IN (0x0001)false

          Click to jump to process

          Click to jump to process

          Click to dive into process behavior distribution

          Click to jump to process

          Target ID:0
          Start time:06:06:56
          Start date:02/01/2025
          Path:C:\Users\user\Desktop\0DrqlQ4JfZ.exe
          Wow64 process (32bit):false
          Commandline:"C:\Users\user\Desktop\0DrqlQ4JfZ.exe"
          Imagebase:0x7ff600ac0000
          File size:390'656 bytes
          MD5 hash:DE3F0F8CBAC7723E54298BAEC915E2BA
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:true

          Target ID:5
          Start time:06:10:44
          Start date:02/01/2025
          Path:C:\Windows\System32\LogonUI.exe
          Wow64 process (32bit):false
          Commandline:"LogonUI.exe" /flags:0x4 /state0:0xa3f52855 /state1:0x41c64e6d
          Imagebase:0x7ff75ff10000
          File size:13'824 bytes
          MD5 hash:893144FE49AA16124B5BD3034E79BBC6
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:moderate
          Has exited:true

          Target ID:10
          Start time:06:10:46
          Start date:02/01/2025
          Path:C:\Windows\System32\cdd.dll
          Wow64 process (32bit):false
          Commandline:
          Imagebase:0x7ff6c74c0000
          File size:267'264 bytes
          MD5 hash:9B684213A399B4E286982BDAD6CF3D07
          Has elevated privileges:
          Has administrator privileges:
          Programmed in:C, C++ or other language
          Reputation:moderate
          Has exited:false

          Target ID:11
          Start time:06:10:46
          Start date:02/01/2025
          Path:C:\Windows\System32\LogonUI.exe
          Wow64 process (32bit):false
          Commandline:"LogonUI.exe" /flags:0x2 /state0:0xa3f5c855 /state1:0x41c64e6d
          Imagebase:0x7ff75ff10000
          File size:13'824 bytes
          MD5 hash:893144FE49AA16124B5BD3034E79BBC6
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:moderate
          Has exited:true

          Target ID:13
          Start time:06:10:46
          Start date:02/01/2025
          Path:C:\Windows\System32\fontdrvhost.exe
          Wow64 process (32bit):true
          Commandline:"fontdrvhost.exe"
          Imagebase:0xc0000
          File size:827'408 bytes
          MD5 hash:BBCB897697B3442657C7D6E3EDDBD25F
          Has elevated privileges:false
          Has administrator privileges:false
          Programmed in:C, C++ or other language
          Reputation:moderate
          Has exited:true

          Target ID:17
          Start time:06:10:47
          Start date:02/01/2025
          Path:C:\Windows\System32\cdd.dll
          Wow64 process (32bit):
          Commandline:
          Imagebase:
          File size:267'264 bytes
          MD5 hash:9B684213A399B4E286982BDAD6CF3D07
          Has elevated privileges:
          Has administrator privileges:
          Programmed in:C, C++ or other language
          Reputation:moderate
          Has exited:false

          Target ID:18
          Start time:06:10:47
          Start date:02/01/2025
          Path:C:\Windows\System32\LogonUI.exe
          Wow64 process (32bit):false
          Commandline:"LogonUI.exe" /flags:0x2 /state0:0xa3f64055 /state1:0x41c64e6d
          Imagebase:0x7ff75ff10000
          File size:13'824 bytes
          MD5 hash:893144FE49AA16124B5BD3034E79BBC6
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:moderate
          Has exited:true

          Target ID:20
          Start time:06:10:47
          Start date:02/01/2025
          Path:C:\Windows\System32\fontdrvhost.exe
          Wow64 process (32bit):false
          Commandline:"fontdrvhost.exe"
          Imagebase:0x7ff72c440000
          File size:827'408 bytes
          MD5 hash:BBCB897697B3442657C7D6E3EDDBD25F
          Has elevated privileges:false
          Has administrator privileges:false
          Programmed in:C, C++ or other language
          Reputation:moderate
          Has exited:true

          Target ID:24
          Start time:06:10:49
          Start date:02/01/2025
          Path:C:\Windows\System32\cdd.dll
          Wow64 process (32bit):
          Commandline:
          Imagebase:
          File size:267'264 bytes
          MD5 hash:9B684213A399B4E286982BDAD6CF3D07
          Has elevated privileges:
          Has administrator privileges:
          Programmed in:C, C++ or other language
          Reputation:moderate
          Has exited:false

          Target ID:25
          Start time:06:10:49
          Start date:02/01/2025
          Path:C:\Windows\System32\LogonUI.exe
          Wow64 process (32bit):false
          Commandline:"LogonUI.exe" /flags:0x2 /state0:0xa3f6b855 /state1:0x41c64e6d
          Imagebase:0x7ff75ff10000
          File size:13'824 bytes
          MD5 hash:893144FE49AA16124B5BD3034E79BBC6
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:moderate
          Has exited:true

          Target ID:26
          Start time:06:10:49
          Start date:02/01/2025
          Path:C:\Windows\System32\fontdrvhost.exe
          Wow64 process (32bit):false
          Commandline:"fontdrvhost.exe"
          Imagebase:0x7ff72c440000
          File size:827'408 bytes
          MD5 hash:BBCB897697B3442657C7D6E3EDDBD25F
          Has elevated privileges:false
          Has administrator privileges:false
          Programmed in:C, C++ or other language
          Reputation:moderate
          Has exited:true

          Target ID:31
          Start time:06:10:50
          Start date:02/01/2025
          Path:C:\Windows\System32\cdd.dll
          Wow64 process (32bit):
          Commandline:
          Imagebase:
          File size:267'264 bytes
          MD5 hash:9B684213A399B4E286982BDAD6CF3D07
          Has elevated privileges:
          Has administrator privileges:
          Programmed in:C, C++ or other language
          Has exited:false

          Target ID:32
          Start time:06:10:50
          Start date:02/01/2025
          Path:C:\Windows\System32\LogonUI.exe
          Wow64 process (32bit):false
          Commandline:"LogonUI.exe" /flags:0x2 /state0:0xa3f7b055 /state1:0x41c64e6d
          Imagebase:0x7ff75ff10000
          File size:13'824 bytes
          MD5 hash:893144FE49AA16124B5BD3034E79BBC6
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Has exited:true

          Target ID:33
          Start time:06:10:50
          Start date:02/01/2025
          Path:C:\Windows\System32\fontdrvhost.exe
          Wow64 process (32bit):false
          Commandline:"fontdrvhost.exe"
          Imagebase:0x7ff72c440000
          File size:827'408 bytes
          MD5 hash:BBCB897697B3442657C7D6E3EDDBD25F
          Has elevated privileges:false
          Has administrator privileges:false
          Programmed in:C, C++ or other language
          Has exited:true

          Target ID:38
          Start time:06:10:52
          Start date:02/01/2025
          Path:C:\Windows\System32\cdd.dll
          Wow64 process (32bit):
          Commandline:
          Imagebase:
          File size:267'264 bytes
          MD5 hash:9B684213A399B4E286982BDAD6CF3D07
          Has elevated privileges:
          Has administrator privileges:
          Programmed in:C, C++ or other language
          Has exited:false

          Target ID:39
          Start time:06:10:52
          Start date:02/01/2025
          Path:C:\Windows\System32\LogonUI.exe
          Wow64 process (32bit):false
          Commandline:"LogonUI.exe" /flags:0x2 /state0:0xa3f02855 /state1:0x41c64e6d
          Imagebase:0x7ff75ff10000
          File size:13'824 bytes
          MD5 hash:893144FE49AA16124B5BD3034E79BBC6
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Has exited:true

          Target ID:40
          Start time:06:10:52
          Start date:02/01/2025
          Path:C:\Windows\System32\fontdrvhost.exe
          Wow64 process (32bit):false
          Commandline:"fontdrvhost.exe"
          Imagebase:0x7ff72c440000
          File size:827'408 bytes
          MD5 hash:BBCB897697B3442657C7D6E3EDDBD25F
          Has elevated privileges:false
          Has administrator privileges:false
          Programmed in:C, C++ or other language
          Has exited:true

          Reset < >

            Execution Graph

            Execution Coverage:9.4%
            Dynamic/Decrypted Code Coverage:0%
            Signature Coverage:42.6%
            Total number of Nodes:1325
            Total number of Limit Nodes:57
            execution_graph 22755 7ff600aceff2 187 API calls 22756 7ff600ac3ff0 WaitForSingleObject Sleep WaitForSingleObject WaitForSingleObject Sleep 22757 7ff600af73ec 54 API calls 4 library calls 22671 7ff600af09e8 12 API calls 22759 7ff600afa7e4 67 API calls 22720 7ff600af52e0 60 API calls 5 library calls 22761 7ff600afcfe0 RtlUnwindEx __GSHandlerCheck_SEH __GSHandlerCheckCommon 22762 7ff600acb3e0 CloseHandle RtlPcToFileHeader RaiseException 21140 7ff600adb5e0 21198 7ff600ae9ebc 21140->21198 21143 7ff600adb653 21146 7ff600adb72f GetLocalTime wsprintfW SetUnhandledExceptionFilter 21143->21146 21147 7ff600adb660 GetCurrentProcess OpenProcessToken 21143->21147 21144 7ff600adb623 21145 7ff600addfb8 std::_Facet_Register 49 API calls 21144->21145 21148 7ff600adb62d 21145->21148 21206 7ff600ae8be0 21146->21206 21149 7ff600adb6d4 GetModuleHandleA GetProcAddress 21147->21149 21150 7ff600adb67f LookupPrivilegeValueW AdjustTokenPrivileges CloseHandle 21147->21150 21152 7ff600ae8be0 52 API calls 21148->21152 21149->21146 21153 7ff600adb6f9 GetCurrentProcessId OpenProcess 21149->21153 21150->21149 21156 7ff600adb64a CloseHandle 21152->21156 21153->21146 21156->21143 21159 7ff600adb7cc 21160 7ff600addfb8 std::_Facet_Register 49 API calls 21159->21160 21161 7ff600adb7d9 21160->21161 21231 7ff600acb410 CreateEventW 21161->21231 21163 7ff600adb7e8 21264 7ff600adae60 RegOpenKeyExW 21163->21264 21166 7ff600adb85a CheckTokenMembership 21168 7ff600adb874 21166->21168 21169 7ff600adb87b FreeSid 21166->21169 21167 7ff600adb888 21170 7ff600adb891 RegOpenKeyExW RegDeleteValueW RegSetValueExW RegCloseKey 21167->21170 21181 7ff600adb90c 21167->21181 21168->21169 21169->21167 21170->21181 21171 7ff600ae8a40 47 API calls std::_Locinfo::_Locinfo_ctor 21171->21181 21172 7ff600ae9ebc ProcessCodePage 47 API calls 21173 7ff600adba23 SleepEx 21172->21173 21174 7ff600ae9ebc ProcessCodePage 47 API calls 21173->21174 21174->21181 21175 7ff600ae9ebc ProcessCodePage 47 API calls 21175->21181 21176 7ff600adba98 CreateEventA 21310 7ff600ae8a40 21176->21310 21179 7ff600adbb49 Sleep 21183 7ff600adbb3d 21179->21183 21180 7ff600adbb7f Sleep 21180->21181 21181->21171 21181->21172 21181->21175 21181->21176 21182 7ff600adbbe9 CloseHandle 21181->21182 21181->21183 21184 7ff600adbbfd 21181->21184 21297 7ff600ac3820 ResetEvent timeGetTime socket 21181->21297 21319 7ff600ac6370 21181->21319 21182->21181 21183->21179 21183->21180 21183->21182 21444 7ff600ae3ff8 21184->21444 21199 7ff600ae9eec 21198->21199 21449 7ff600ae9720 21199->21449 21203 7ff600adb60b SleepEx 21203->21143 21203->21144 21204 7ff600ae9f40 21204->21203 21469 7ff600ae3bec 47 API calls 2 library calls 21204->21469 21207 7ff600ae8c00 21206->21207 21208 7ff600ae8c17 21206->21208 21485 7ff600ae8d9c 11 API calls _get_daylight 21207->21485 21478 7ff600ae8b7c 21208->21478 21212 7ff600ae8c05 21486 7ff600ae3fd8 47 API calls _invalid_parameter_noinfo_noreturn 21212->21486 21214 7ff600ae8c2a CreateThread 21215 7ff600adb7aa CloseHandle 21214->21215 21216 7ff600ae8c5a GetLastError 21214->21216 21224 7ff600addfb8 21215->21224 21487 7ff600ae8d10 11 API calls 2 library calls 21216->21487 21218 7ff600ae8c67 21219 7ff600ae8c70 CloseHandle 21218->21219 21220 7ff600ae8c76 21218->21220 21219->21220 21221 7ff600ae8c85 21220->21221 21222 7ff600ae8c7f FreeLibrary 21220->21222 21488 7ff600aee95c 21221->21488 21222->21221 21225 7ff600addfc3 21224->21225 21225->21224 21226 7ff600adb7bd 21225->21226 21506 7ff600aeccd0 EnterCriticalSection LeaveCriticalSection std::_Facet_Register 21225->21506 21507 7ff600adccb0 RtlPcToFileHeader RaiseException Concurrency::cancel_current_task std::bad_alloc::bad_alloc 21225->21507 21508 7ff600ac19d0 49 API calls Concurrency::cancel_current_task 21225->21508 21230 7ff600ac36e0 WSAStartup CreateEventW 21226->21230 21230->21159 21232 7ff600acb457 21231->21232 21262 7ff600acb7b0 21231->21262 21509 7ff600ac1200 21232->21509 21236 7ff600acb7bb 21527 7ff600ac10f0 RtlPcToFileHeader RaiseException Concurrency::cancel_current_task 21236->21527 21238 7ff600acb7c6 21528 7ff600ac10f0 RtlPcToFileHeader RaiseException Concurrency::cancel_current_task 21238->21528 21239 7ff600acb4d2 HeapCreate 21239->21238 21245 7ff600acb521 ctype 21239->21245 21241 7ff600acb560 InitializeCriticalSectionAndSpinCount 21242 7ff600acb7d1 21241->21242 21243 7ff600acb57d CreateEventW 21241->21243 21529 7ff600ac10f0 RtlPcToFileHeader RaiseException Concurrency::cancel_current_task 21242->21529 21246 7ff600acb7dc 21243->21246 21247 7ff600acb5b8 CreateEventW 21243->21247 21245->21241 21530 7ff600ac10f0 RtlPcToFileHeader RaiseException Concurrency::cancel_current_task 21246->21530 21248 7ff600acb7e7 21247->21248 21249 7ff600acb5d8 CreateEventW 21247->21249 21531 7ff600ac10f0 RtlPcToFileHeader RaiseException Concurrency::cancel_current_task 21248->21531 21251 7ff600acb7f2 21249->21251 21252 7ff600acb5f8 InitializeCriticalSectionAndSpinCount 21249->21252 21532 7ff600ac10f0 RtlPcToFileHeader RaiseException Concurrency::cancel_current_task 21251->21532 21254 7ff600acb7fd 21252->21254 21255 7ff600acb6c1 InitializeCriticalSectionAndSpinCount 21252->21255 21533 7ff600ac10f0 RtlPcToFileHeader RaiseException Concurrency::cancel_current_task 21254->21533 21258 7ff600acb6d5 timeGetTime CreateEventW CreateEventW 21255->21258 21259 7ff600acb7a6 21255->21259 21263 7ff600acb77e 21258->21263 21525 7ff600ac10f0 RtlPcToFileHeader RaiseException Concurrency::cancel_current_task 21259->21525 21526 7ff600ac10f0 RtlPcToFileHeader RaiseException Concurrency::cancel_current_task 21262->21526 21263->21163 21265 7ff600adae9f RegQueryValueExW 21264->21265 21266 7ff600adaecc memcpy_s 21264->21266 21265->21266 21267 7ff600adaf02 RegQueryValueExW lstrlenW 21266->21267 21295 7ff600adb551 AllocateAndInitializeSid 21266->21295 21536 7ff600afda50 21267->21536 21270 7ff600adaff8 lstrlenW 21271 7ff600afda50 memcpy_s 21270->21271 21272 7ff600adb01d lstrlenW lstrlenW 21271->21272 21273 7ff600adb0c8 lstrlenW lstrlenW 21272->21273 21280 7ff600adb04a memcpy_s 21272->21280 21274 7ff600adb15a lstrlenW 21273->21274 21282 7ff600adb0f1 21273->21282 21275 7ff600afda50 memcpy_s 21274->21275 21277 7ff600adb17f lstrlenW lstrlenW 21275->21277 21276 7ff600adaf79 memcpy_s 21276->21270 21278 7ff600adb228 lstrlenW 21277->21278 21286 7ff600adb1ac memcpy_s 21277->21286 21279 7ff600afda50 memcpy_s 21278->21279 21281 7ff600adb24d lstrlenW lstrlenW 21279->21281 21280->21273 21283 7ff600adb2f8 lstrlenW lstrlenW 21281->21283 21290 7ff600adb27a memcpy_s 21281->21290 21282->21274 21284 7ff600adb38a lstrlenW 21283->21284 21292 7ff600adb321 21283->21292 21285 7ff600afda50 memcpy_s 21284->21285 21287 7ff600adb3af lstrlenW lstrlenW 21285->21287 21286->21278 21288 7ff600adb458 lstrlenW 21287->21288 21294 7ff600adb3dc memcpy_s 21287->21294 21289 7ff600afda50 memcpy_s 21288->21289 21291 7ff600adb47d lstrlenW lstrlenW 21289->21291 21290->21283 21293 7ff600adb528 lstrlenW lstrlenW 21291->21293 21296 7ff600adb4aa memcpy_s 21291->21296 21292->21284 21293->21295 21294->21288 21295->21166 21295->21167 21296->21293 21298 7ff600ac3ad9 21297->21298 21299 7ff600ac3893 lstrlenW WideCharToMultiByte 21297->21299 21298->21181 21300 7ff600addff4 21299->21300 21301 7ff600ac38d4 lstrlenW WideCharToMultiByte gethostbyname 21300->21301 21302 7ff600ac391d 21301->21302 21302->21298 21303 7ff600ac392e htons connect 21302->21303 21303->21298 21304 7ff600ac3971 setsockopt setsockopt setsockopt setsockopt 21303->21304 21305 7ff600ac3a37 WSAIoctl 21304->21305 21306 7ff600ac3a86 21304->21306 21305->21306 21307 7ff600ae8be0 52 API calls 21306->21307 21308 7ff600ac3ab0 21307->21308 21309 7ff600ae8be0 52 API calls 21308->21309 21309->21298 21311 7ff600ae8a4d 21310->21311 21312 7ff600ae8a57 21310->21312 21311->21312 21317 7ff600ae8a73 21311->21317 21538 7ff600ae8d9c 11 API calls _get_daylight 21312->21538 21314 7ff600ae8a5f 21539 7ff600ae3fd8 47 API calls _invalid_parameter_noinfo_noreturn 21314->21539 21316 7ff600ae8a6b 21316->21181 21317->21316 21540 7ff600ae8d9c 11 API calls _get_daylight 21317->21540 21320 7ff600ac639d std::_Locinfo::_Locinfo_ctor 21319->21320 21321 7ff600addfb8 std::_Facet_Register 49 API calls 21320->21321 21323 7ff600ac63aa memcpy_s 21321->21323 21322 7ff600ac63de memcpy_s 21325 7ff600ac63f6 gethostname gethostbyname 21322->21325 21323->21322 21324 7ff600ae8a40 std::_Locinfo::_Locinfo_ctor 47 API calls 21323->21324 21324->21322 21326 7ff600ac64cf 8 API calls 21325->21326 21327 7ff600ac6432 inet_ntoa 21325->21327 21328 7ff600ac65be GetProcAddress 21326->21328 21329 7ff600ac66dc GetSystemInfo wsprintfW 21326->21329 21680 7ff600ae91f8 47 API calls 2 library calls 21327->21680 21331 7ff600ac66d3 FreeLibrary 21328->21331 21332 7ff600ac65d7 21328->21332 21333 7ff600ac6720 GetDriveTypeW 21329->21333 21331->21329 21541 7ff600ac3670 21332->21541 21335 7ff600ac6741 GetDiskFreeSpaceExW 21333->21335 21336 7ff600ac6778 21333->21336 21334 7ff600ac6455 21681 7ff600ae91f8 47 API calls 2 library calls 21334->21681 21335->21336 21336->21333 21338 7ff600ac677f GlobalMemoryStatusEx 21336->21338 21340 7ff600ac3670 50 API calls 21338->21340 21342 7ff600ac67e2 21340->21342 21341 7ff600ac6620 21545 7ff600ac9300 GetModuleHandleW GetProcAddress 21341->21545 21344 7ff600ac3670 50 API calls 21342->21344 21343 7ff600ac6480 inet_ntoa 21682 7ff600ae91f8 47 API calls 2 library calls 21343->21682 21346 7ff600ac6806 21344->21346 21549 7ff600ac8f60 CreateDXGIFactory 21346->21549 21347 7ff600ac646d 21347->21326 21347->21343 21683 7ff600ae91f8 47 API calls 2 library calls 21347->21683 21352 7ff600ac6819 GetForegroundWindow 21354 7ff600ac6824 GetWindowTextW 21352->21354 21355 7ff600ac683a lstrlenW 21352->21355 21354->21355 21561 7ff600ac8e30 21355->21561 21357 7ff600ac66c0 RegCloseKey 21360 7ff600addf84 21357->21360 21358 7ff600ac66a2 21358->21357 21361 7ff600ae94e8 std::_Locinfo::_Locinfo_ctor 47 API calls 21358->21361 21359 7ff600ac687a 21362 7ff600ac687f GetLocalTime wsprintfW 21359->21362 21363 7ff600ac68a3 21359->21363 21360->21331 21361->21357 21362->21363 21364 7ff600ae8a40 std::_Locinfo::_Locinfo_ctor 47 API calls 21363->21364 21365 7ff600ac68bb lstrlenW 21364->21365 21366 7ff600ac8e30 6 API calls 21365->21366 21367 7ff600ac68df 21366->21367 21368 7ff600ac68f8 GetModuleHandleW GetProcAddress 21367->21368 21369 7ff600ae8a40 std::_Locinfo::_Locinfo_ctor 47 API calls 21367->21369 21370 7ff600ac6931 GetSystemInfo 21368->21370 21371 7ff600ac692d GetNativeSystemInfo 21368->21371 21369->21368 21372 7ff600ac6937 wsprintfW 21370->21372 21371->21372 21570 7ff600ac8c30 21372->21570 21375 7ff600ac6986 GetCurrentProcessId 21376 7ff600ac6ade CoInitializeEx CoCreateInstance 21375->21376 21377 7ff600ac699c OpenProcess 21375->21377 21378 7ff600ac6c0f 21376->21378 21407 7ff600ac6b15 21376->21407 21379 7ff600ac6ad7 21377->21379 21380 7ff600ac69bd K32GetProcessImageFileNameW 21377->21380 21384 7ff600ae8a40 std::_Locinfo::_Locinfo_ctor 47 API calls 21378->21384 21379->21376 21381 7ff600ac6ace CloseHandle 21380->21381 21382 7ff600ac69db GetLogicalDriveStringsW 21380->21382 21381->21379 21383 7ff600ac6abe lstrcpyW 21382->21383 21400 7ff600ac69f5 21382->21400 21383->21381 21385 7ff600ac6c2b memcpy_s 21384->21385 21387 7ff600ac6c46 RegOpenKeyExW 21385->21387 21386 7ff600ac6a10 lstrcmpiW 21388 7ff600ac6a32 lstrcmpiW 21386->21388 21386->21400 21389 7ff600ac6c75 RegQueryInfoKeyW 21387->21389 21390 7ff600ac6dd2 lstrlenW 21387->21390 21391 7ff600ac6a46 QueryDosDeviceW 21388->21391 21388->21400 21392 7ff600ac6e02 21389->21392 21414 7ff600ac6cd5 memcpy_s 21389->21414 21390->21392 21393 7ff600ac6de4 21390->21393 21391->21381 21394 7ff600ac6a80 lstrlenW 21391->21394 21599 7ff600ac7a60 21392->21599 21590 7ff600ae94e8 21393->21590 21684 7ff600ae934c 53 API calls 3 library calls 21394->21684 21397 7ff600ac6bfe CoUninitialize 21397->21378 21400->21383 21400->21386 21402 7ff600ac6f0d lstrcpyW lstrcatW 21400->21402 21401 7ff600ae94e8 std::_Locinfo::_Locinfo_ctor 47 API calls 21403 7ff600ac6e21 GetTickCount 21401->21403 21402->21381 21617 7ff600ae8e3c GetSystemTimeAsFileTime 21403->21617 21404 7ff600ac6dc7 RegCloseKey 21404->21390 21407->21378 21407->21397 21409 7ff600ac6bb6 SysFreeString 21407->21409 21409->21407 21410 7ff600ac6d34 RegEnumKeyExW lstrlenW 21412 7ff600ac6d77 lstrlenW 21410->21412 21410->21414 21412->21414 21413 7ff600ac6eff 21624 7ff600ac72d0 21413->21624 21414->21390 21414->21404 21414->21410 21416 7ff600ae8dc4 47 API calls std::_Locinfo::_Locinfo_ctor 21414->21416 21416->21414 21417 7ff600ac6f51 lstrlenW 21418 7ff600ac8e30 6 API calls 21417->21418 21419 7ff600ac6f8a 21418->21419 21420 7ff600ac6f93 6 API calls 21419->21420 21421 7ff600ac7067 CreateToolhelp32Snapshot 21419->21421 21422 7ff600ac7018 lstrlenW RegSetValueExW 21420->21422 21423 7ff600ac705a RegCloseKey 21420->21423 21424 7ff600ac7081 memcpy_s 21421->21424 21425 7ff600ac7108 CreateToolhelp32Snapshot 21421->21425 21422->21423 21427 7ff600ac704d RegCloseKey 21422->21427 21423->21421 21430 7ff600ac7095 Process32FirstW 21424->21430 21428 7ff600ac71b8 CreateToolhelp32Snapshot 21425->21428 21429 7ff600ac712b memcpy_s 21425->21429 21427->21423 21432 7ff600ac7264 21428->21432 21433 7ff600ac71db memcpy_s 21428->21433 21434 7ff600ac713f Process32FirstW 21429->21434 21430->21425 21437 7ff600ac70b3 21430->21437 21664 7ff600ac3e30 GetCurrentThreadId 21432->21664 21438 7ff600ac71ef Process32FirstW 21433->21438 21434->21428 21440 7ff600ac715d 21434->21440 21435 7ff600ac729c 21435->21181 21436 7ff600ac70f4 Process32NextW 21436->21425 21436->21437 21437->21425 21437->21436 21438->21432 21442 7ff600ac720d 21438->21442 21439 7ff600ac71a4 Process32NextW 21439->21428 21439->21440 21440->21428 21440->21439 21441 7ff600ac7250 Process32NextW 21441->21432 21441->21442 21442->21432 21442->21441 21982 7ff600ae3e70 47 API calls _invalid_parameter_noinfo_noreturn 21444->21982 21446 7ff600ae4011 21447 7ff600ae4028 _invalid_parameter_noinfo_noreturn 17 API calls 21446->21447 21448 7ff600ae4026 21447->21448 21450 7ff600ae976a 21449->21450 21451 7ff600ae9758 21449->21451 21452 7ff600ae97b4 21450->21452 21455 7ff600ae9778 21450->21455 21470 7ff600ae8d9c 11 API calls _get_daylight 21451->21470 21460 7ff600ae97cf ProcessCodePage 21452->21460 21473 7ff600ae8400 47 API calls 2 library calls 21452->21473 21454 7ff600ae975d 21471 7ff600ae3fd8 47 API calls _invalid_parameter_noinfo_noreturn 21454->21471 21472 7ff600ae3f0c 47 API calls _invalid_parameter_noinfo_noreturn 21455->21472 21459 7ff600ae9b55 21464 7ff600ae9768 21459->21464 21476 7ff600ae8d9c 11 API calls _get_daylight 21459->21476 21460->21459 21474 7ff600ae8d9c 11 API calls _get_daylight 21460->21474 21463 7ff600ae9b4a 21475 7ff600ae3fd8 47 API calls _invalid_parameter_noinfo_noreturn 21463->21475 21464->21204 21468 7ff600ae3bec 47 API calls 2 library calls 21464->21468 21465 7ff600ae9de6 21477 7ff600ae3fd8 47 API calls _invalid_parameter_noinfo_noreturn 21465->21477 21468->21204 21469->21203 21470->21454 21471->21464 21472->21464 21473->21460 21474->21463 21475->21459 21476->21465 21477->21464 21494 7ff600af0a28 21478->21494 21481 7ff600aee95c __free_lconv_mon 11 API calls 21482 7ff600ae8ba8 21481->21482 21483 7ff600ae8bb1 GetModuleHandleExW 21482->21483 21484 7ff600ae8bad 21482->21484 21483->21484 21484->21214 21484->21215 21485->21212 21486->21215 21487->21218 21489 7ff600aee961 RtlFreeHeap 21488->21489 21493 7ff600aee990 21488->21493 21490 7ff600aee97c GetLastError 21489->21490 21489->21493 21491 7ff600aee989 __free_lconv_mon 21490->21491 21505 7ff600ae8d9c 11 API calls _get_daylight 21491->21505 21493->21215 21495 7ff600af0a39 21494->21495 21501 7ff600af0a47 _Getctype 21494->21501 21496 7ff600af0a8a 21495->21496 21495->21501 21504 7ff600ae8d9c 11 API calls _get_daylight 21496->21504 21497 7ff600af0a6e HeapAlloc 21498 7ff600af0a88 21497->21498 21497->21501 21500 7ff600ae8b9e 21498->21500 21500->21481 21501->21496 21501->21497 21503 7ff600aeccd0 EnterCriticalSection LeaveCriticalSection std::_Facet_Register 21501->21503 21503->21501 21504->21500 21505->21493 21506->21225 21508->21225 21510 7ff600ac1221 21509->21510 21511 7ff600ac1270 21509->21511 21534 7ff600addccc AcquireSRWLockExclusive SleepConditionVariableSRW ReleaseSRWLockExclusive 21510->21534 21513 7ff600ac12f3 21511->21513 21535 7ff600addccc AcquireSRWLockExclusive SleepConditionVariableSRW ReleaseSRWLockExclusive 21511->21535 21513->21236 21513->21239 21537 7ff600adaf50 lstrlenW lstrlenW 21536->21537 21537->21270 21537->21276 21538->21314 21539->21316 21540->21314 21542 7ff600ac3695 21541->21542 21685 7ff600ae892c 21542->21685 21546 7ff600ac9341 GetSystemInfo 21545->21546 21547 7ff600ac933d GetNativeSystemInfo 21545->21547 21548 7ff600ac6642 RegOpenKeyExW RegQueryValueExW 21546->21548 21547->21548 21548->21357 21548->21358 21550 7ff600ac92a3 21549->21550 21555 7ff600ac8fba 21549->21555 21551 7ff600ac92d5 21550->21551 21552 7ff600ae3ff8 _invalid_parameter_noinfo_noreturn 47 API calls 21550->21552 21551->21352 21553 7ff600ac92f6 21552->21553 21556 7ff600ae3ff8 _invalid_parameter_noinfo_noreturn 47 API calls 21553->21556 21560 7ff600ac9035 21555->21560 21699 7ff600aca4c0 49 API calls memcpy_s 21555->21699 21557 7ff600ac92fc 21556->21557 21558 7ff600ac3670 50 API calls 21558->21560 21560->21550 21560->21553 21560->21558 21700 7ff600aca4c0 49 API calls memcpy_s 21560->21700 21562 7ff600afda50 memcpy_s 21561->21562 21563 7ff600ac8e71 RegOpenKeyExW 21562->21563 21564 7ff600ac8ea6 21563->21564 21569 7ff600ac8e9c 21563->21569 21565 7ff600ac8f28 RegCloseKey RegCloseKey 21564->21565 21566 7ff600ac8eb4 RegQueryValueExW 21564->21566 21565->21359 21566->21565 21567 7ff600ac8ef3 lstrcmpW 21566->21567 21568 7ff600ac8f10 lstrcpyW 21567->21568 21567->21569 21568->21565 21569->21565 21571 7ff600addff4 21570->21571 21572 7ff600ac8c48 GetCurrentProcessId wsprintfW 21571->21572 21701 7ff600ac8a40 GetCurrentProcessId OpenProcess 21572->21701 21574 7ff600ac8c70 memcpy_s 21575 7ff600ac8c84 GetVersionExW 21574->21575 21576 7ff600ac8df2 21575->21576 21577 7ff600ac8c9f 21575->21577 21578 7ff600ac8df9 wsprintfW 21576->21578 21577->21576 21579 7ff600ac8cb5 GetCurrentProcess OpenProcessToken 21577->21579 21583 7ff600ac8e09 21578->21583 21579->21576 21580 7ff600ac8ce1 GetTokenInformation 21579->21580 21581 7ff600ac8d9c CloseHandle 21580->21581 21582 7ff600ac8d16 GetLastError 21580->21582 21581->21576 21589 7ff600ac8dae 21581->21589 21582->21581 21584 7ff600ac8d21 LocalAlloc 21582->21584 21583->21375 21585 7ff600ac8d43 GetTokenInformation 21584->21585 21586 7ff600ac8d94 21584->21586 21587 7ff600ac8d72 GetSidSubAuthorityCount GetSidSubAuthority 21585->21587 21588 7ff600ac8d8b LocalFree 21585->21588 21586->21581 21587->21588 21588->21586 21589->21578 21589->21583 21593 7ff600ae9505 21590->21593 21591 7ff600ae950a 21596 7ff600ae9520 21591->21596 21821 7ff600ae8d9c 11 API calls _get_daylight 21591->21821 21593->21591 21595 7ff600ae9556 21593->21595 21593->21596 21595->21596 21823 7ff600ae8d9c 11 API calls _get_daylight 21595->21823 21596->21392 21598 7ff600ae9514 21822 7ff600ae3fd8 47 API calls _invalid_parameter_noinfo_noreturn 21598->21822 21608 7ff600ac7a93 memcpy_s 21599->21608 21600 7ff600ac7b7c CoCreateInstance 21601 7ff600ac7da1 lstrlenW 21600->21601 21602 7ff600ac7bad memcpy_s 21600->21602 21603 7ff600ac6e07 21601->21603 21604 7ff600ac7dae lstrcatW 21601->21604 21606 7ff600ac7d8f 21602->21606 21612 7ff600ac7c35 wsprintfW RegOpenKeyExW 21602->21612 21614 7ff600ac7cf7 RegQueryValueExW 21602->21614 21603->21401 21604->21603 21605 7ff600ac7ae4 CreateToolhelp32Snapshot 21607 7ff600ac7afa Process32FirstW 21605->21607 21605->21608 21606->21601 21607->21608 21609 7ff600ac7b4d CloseHandle 21607->21609 21608->21600 21608->21605 21610 7ff600ac7b3f Process32NextW 21608->21610 21611 7ff600ac7de5 CloseHandle 21608->21611 21609->21608 21610->21608 21610->21609 21611->21608 21613 7ff600ac7df5 lstrcatW lstrcatW 21611->21613 21612->21602 21613->21608 21615 7ff600ac7d60 RegCloseKey 21614->21615 21616 7ff600ac7d40 lstrcatW lstrcatW 21614->21616 21615->21602 21616->21615 21618 7ff600ac6e32 21617->21618 21619 7ff600ae91b0 21618->21619 21824 7ff600af1a1c 21619->21824 21622 7ff600ac6e52 wsprintfW GetLocaleInfoW GetSystemDirectoryW GetCurrentHwProfileW 21622->21413 21625 7ff600ac7330 21624->21625 21625->21625 21627 7ff600ac7346 memcpy_s 21625->21627 21939 7ff600aca300 49 API calls 4 library calls 21625->21939 21629 7ff600ac7392 memcpy_s 21627->21629 21940 7ff600aca300 49 API calls 4 library calls 21627->21940 21631 7ff600ac7401 memcpy_s 21629->21631 21941 7ff600aca300 49 API calls 4 library calls 21629->21941 21633 7ff600ac7474 memcpy_s 21631->21633 21942 7ff600aca300 49 API calls 4 library calls 21631->21942 21635 7ff600ac74cf memcpy_s 21633->21635 21943 7ff600aca300 49 API calls 4 library calls 21633->21943 21637 7ff600ac7550 memcpy_s 21635->21637 21944 7ff600aca300 49 API calls 4 library calls 21635->21944 21639 7ff600ac75c0 memcpy_s 21637->21639 21945 7ff600aca300 49 API calls 4 library calls 21637->21945 21933 7ff600ad9be0 21639->21933 21642 7ff600ac772d 21642->21417 21643 7ff600ac76b6 21643->21642 21644 7ff600ac7758 21643->21644 21646 7ff600ae3ff8 _invalid_parameter_noinfo_noreturn 47 API calls 21643->21646 21645 7ff600ae3ff8 _invalid_parameter_noinfo_noreturn 47 API calls 21644->21645 21647 7ff600ac775e CreateMutexExW GetLastError 21645->21647 21646->21644 21648 7ff600ac77c9 21647->21648 21649 7ff600ac7799 21647->21649 21650 7ff600ac7870 9 API calls 21648->21650 21652 7ff600ac77e0 lstrlenW 21648->21652 21651 7ff600ac77a0 Sleep CreateMutexW GetLastError 21649->21651 21653 7ff600ac7924 DeleteFileW 21650->21653 21654 7ff600ac792d ReleaseMutex DirectInput8Create 21650->21654 21651->21648 21651->21651 21655 7ff600ac8e30 6 API calls 21652->21655 21653->21654 21656 7ff600ac7a00 21654->21656 21660 7ff600ac7963 21654->21660 21657 7ff600ac783e 21655->21657 21656->21417 21658 7ff600ac7842 lstrcmpW 21657->21658 21659 7ff600ac7858 SleepEx 21657->21659 21658->21650 21658->21659 21659->21650 21659->21652 21660->21656 21661 7ff600ac7a1f GetTickCount GetKeyState 21660->21661 21946 7ff600acadb0 37 API calls 2 library calls 21661->21946 21665 7ff600ac3e5c 21664->21665 21963 7ff600ac1670 21665->21963 21667 7ff600ac3e9b 21668 7ff600ac1670 2 API calls 21667->21668 21669 7ff600ac3ec4 21668->21669 21970 7ff600ac1500 21669->21970 21671 7ff600ac3efa 21672 7ff600ac3f1a 21671->21672 21677 7ff600ac3f06 21671->21677 21673 7ff600ac3fa1 21672->21673 21674 7ff600ac3f30 send 21672->21674 21672->21677 21976 7ff600ac1730 21673->21976 21674->21672 21675 7ff600ac3f80 send 21675->21673 21675->21677 21677->21673 21677->21675 21678 7ff600ac3fba GetCurrentThreadId 21679 7ff600ac3fca 21678->21679 21679->21435 21680->21334 21681->21347 21682->21347 21683->21347 21684->21400 21687 7ff600ae8965 21685->21687 21686 7ff600ae89a8 21690 7ff600ae89e7 21686->21690 21696 7ff600ae3f0c 47 API calls _invalid_parameter_noinfo_noreturn 21686->21696 21687->21686 21695 7ff600ae4280 50 API calls 2 library calls 21687->21695 21691 7ff600ae8a0d 21690->21691 21697 7ff600ae3bec 47 API calls 2 library calls 21690->21697 21693 7ff600ac36b4 21691->21693 21698 7ff600ae3bec 47 API calls 2 library calls 21691->21698 21693->21341 21695->21686 21696->21690 21697->21691 21698->21693 21699->21555 21700->21560 21702 7ff600ac8a71 OpenProcessToken 21701->21702 21703 7ff600ac8a99 21701->21703 21704 7ff600ac8aaf 21702->21704 21705 7ff600ac8a90 CloseHandle 21702->21705 21703->21574 21740 7ff600ac8710 21704->21740 21705->21703 21707 7ff600ac8acd 21708 7ff600ac8b03 21707->21708 21709 7ff600ac8ae1 SysStringLen 21707->21709 21710 7ff600ac8ae9 21707->21710 21711 7ff600ac8b4c memcpy_s 21708->21711 21712 7ff600addfb8 std::_Facet_Register 49 API calls 21708->21712 21709->21710 21710->21708 21715 7ff600ac8af9 SysStringLen 21710->21715 21714 7ff600ac8b5a CloseHandle CloseHandle 21711->21714 21713 7ff600ac8b1e 21712->21713 21713->21711 21721 7ff600ac8c20 21713->21721 21716 7ff600ac8b88 21714->21716 21719 7ff600ac8baa 21714->21719 21715->21708 21718 7ff600ac8ba1 SysFreeString 21716->21718 21716->21719 21717 7ff600ac8be5 SysFreeString 21720 7ff600ac8bee 21717->21720 21718->21719 21719->21717 21719->21720 21720->21574 21722 7ff600ac8c48 GetCurrentProcessId wsprintfW 21721->21722 21723 7ff600ac8a40 87 API calls 21722->21723 21724 7ff600ac8c70 memcpy_s 21723->21724 21725 7ff600ac8c84 GetVersionExW 21724->21725 21726 7ff600ac8df2 21725->21726 21727 7ff600ac8c9f 21725->21727 21728 7ff600ac8df9 wsprintfW 21726->21728 21727->21726 21729 7ff600ac8cb5 GetCurrentProcess OpenProcessToken 21727->21729 21730 7ff600ac8e09 21728->21730 21729->21726 21731 7ff600ac8ce1 GetTokenInformation 21729->21731 21730->21574 21732 7ff600ac8d9c CloseHandle 21731->21732 21733 7ff600ac8d16 GetLastError 21731->21733 21732->21726 21739 7ff600ac8dae 21732->21739 21733->21732 21734 7ff600ac8d21 LocalAlloc 21733->21734 21735 7ff600ac8d43 GetTokenInformation 21734->21735 21736 7ff600ac8d94 21734->21736 21737 7ff600ac8d72 GetSidSubAuthorityCount GetSidSubAuthority 21735->21737 21738 7ff600ac8d8b LocalFree 21735->21738 21736->21732 21737->21738 21738->21736 21739->21728 21739->21730 21741 7ff600ac8750 21740->21741 21742 7ff600ac8794 21741->21742 21817 7ff600ac6300 21741->21817 21745 7ff600ac87f1 21742->21745 21746 7ff600ac6300 SysFreeString 21742->21746 21774 7ff600ac89ff 21742->21774 21744 7ff600ac875d 21747 7ff600addfb8 std::_Facet_Register 49 API calls 21744->21747 21748 7ff600ac880e GetTokenInformation 21745->21748 21745->21774 21749 7ff600ac87ba 21746->21749 21750 7ff600ac8767 21747->21750 21752 7ff600ac8833 GetLastError 21748->21752 21753 7ff600ac886c GetTokenInformation 21748->21753 21754 7ff600addfb8 std::_Facet_Register 49 API calls 21749->21754 21750->21742 21751 7ff600ac8774 SysAllocString 21750->21751 21751->21742 21751->21774 21755 7ff600ac8842 GetProcessHeap HeapAlloc 21752->21755 21752->21774 21756 7ff600ac889a LookupAccountSidW 21753->21756 21777 7ff600ac88f7 21753->21777 21757 7ff600ac87c4 21754->21757 21755->21753 21755->21774 21759 7ff600ac88d4 GetLastError 21756->21759 21760 7ff600ac891b 21756->21760 21757->21745 21761 7ff600ac87d1 SysAllocString 21757->21761 21758 7ff600ac89eb GetProcessHeap HeapFree 21758->21774 21762 7ff600ac88e1 21759->21762 21763 7ff600ac88fc 21759->21763 21765 7ff600ac896e 21760->21765 21766 7ff600ac6300 SysFreeString 21760->21766 21761->21745 21761->21774 21764 7ff600ae8a40 std::_Locinfo::_Locinfo_ctor 47 API calls 21762->21764 21763->21707 21764->21777 21768 7ff600ac6300 SysFreeString 21765->21768 21765->21774 21765->21777 21767 7ff600ac8935 21766->21767 21769 7ff600addfb8 std::_Facet_Register 49 API calls 21767->21769 21771 7ff600ac899c 21768->21771 21770 7ff600ac893f 21769->21770 21770->21765 21772 7ff600ac894c SysAllocString 21770->21772 21773 7ff600addfb8 std::_Facet_Register 49 API calls 21771->21773 21772->21765 21772->21774 21775 7ff600ac89a6 21773->21775 21778 7ff600ac8a40 GetCurrentProcessId OpenProcess 21774->21778 21776 7ff600ac89b3 SysAllocString 21775->21776 21775->21777 21776->21774 21776->21777 21777->21758 21777->21774 21779 7ff600ac8a71 OpenProcessToken 21778->21779 21780 7ff600ac8a99 21778->21780 21781 7ff600ac8aaf 21779->21781 21782 7ff600ac8a90 CloseHandle 21779->21782 21780->21707 21783 7ff600ac8710 74 API calls 21781->21783 21782->21780 21784 7ff600ac8acd 21783->21784 21785 7ff600ac8b03 21784->21785 21786 7ff600ac8ae1 SysStringLen 21784->21786 21787 7ff600ac8ae9 21784->21787 21788 7ff600ac8b4c memcpy_s 21785->21788 21789 7ff600addfb8 std::_Facet_Register 49 API calls 21785->21789 21786->21787 21787->21785 21791 7ff600ac8af9 SysStringLen 21787->21791 21790 7ff600ac8b5a CloseHandle CloseHandle 21788->21790 21792 7ff600ac8b1e 21789->21792 21793 7ff600ac8b88 21790->21793 21797 7ff600ac8baa 21790->21797 21791->21785 21792->21788 21798 7ff600ac8c20 21792->21798 21796 7ff600ac8ba1 SysFreeString 21793->21796 21793->21797 21794 7ff600ac8be5 SysFreeString 21795 7ff600ac8bee 21794->21795 21795->21707 21796->21797 21797->21794 21797->21795 21799 7ff600ac8c48 GetCurrentProcessId wsprintfW 21798->21799 21800 7ff600ac8a40 74 API calls 21799->21800 21801 7ff600ac8c70 memcpy_s 21800->21801 21802 7ff600ac8c84 GetVersionExW 21801->21802 21803 7ff600ac8df2 21802->21803 21804 7ff600ac8c9f 21802->21804 21805 7ff600ac8df9 wsprintfW 21803->21805 21804->21803 21806 7ff600ac8cb5 GetCurrentProcess OpenProcessToken 21804->21806 21807 7ff600ac8e09 21805->21807 21806->21803 21808 7ff600ac8ce1 GetTokenInformation 21806->21808 21807->21707 21809 7ff600ac8d9c CloseHandle 21808->21809 21810 7ff600ac8d16 GetLastError 21808->21810 21809->21803 21816 7ff600ac8dae 21809->21816 21810->21809 21811 7ff600ac8d21 LocalAlloc 21810->21811 21812 7ff600ac8d43 GetTokenInformation 21811->21812 21813 7ff600ac8d94 21811->21813 21814 7ff600ac8d72 GetSidSubAuthorityCount GetSidSubAuthority 21812->21814 21815 7ff600ac8d8b LocalFree 21812->21815 21813->21809 21814->21815 21815->21813 21816->21805 21816->21807 21818 7ff600ac6315 21817->21818 21819 7ff600ac6339 21817->21819 21818->21819 21820 7ff600ac632c SysFreeString 21818->21820 21819->21744 21820->21819 21821->21598 21822->21596 21823->21598 21864 7ff600aeee88 GetLastError 21824->21864 21826 7ff600af1a27 21827 7ff600af1a4b 21826->21827 21829 7ff600ae91c7 21826->21829 21881 7ff600aef070 21826->21881 21827->21829 21888 7ff600ae8d9c 11 API calls _get_daylight 21827->21888 21829->21622 21833 7ff600ae8eb0 21829->21833 21832 7ff600aee95c __free_lconv_mon 11 API calls 21832->21827 21834 7ff600ae8ee1 21833->21834 21835 7ff600ae8ec6 21833->21835 21834->21835 21836 7ff600ae8efa 21834->21836 21908 7ff600ae8d9c 11 API calls _get_daylight 21835->21908 21838 7ff600ae8f00 21836->21838 21841 7ff600ae8f1d 21836->21841 21910 7ff600ae8d9c 11 API calls _get_daylight 21838->21910 21839 7ff600ae8ecb 21909 7ff600ae3fd8 47 API calls _invalid_parameter_noinfo_noreturn 21839->21909 21892 7ff600af25dc 21841->21892 21847 7ff600ae9197 21904 7ff600ae4028 IsProcessorFeaturePresent 21847->21904 21850 7ff600ae91ac 21852 7ff600af1a1c 12 API calls 21850->21852 21855 7ff600ae91c7 21852->21855 21857 7ff600ae91dc 21855->21857 21858 7ff600ae8eb0 61 API calls 21855->21858 21856 7ff600ae8f61 21859 7ff600ae8f7a 21856->21859 21860 7ff600ae8fda 21856->21860 21857->21622 21858->21857 21863 7ff600ae8ed7 21859->21863 21923 7ff600af2620 47 API calls _isindst 21859->21923 21860->21863 21924 7ff600af2620 47 API calls _isindst 21860->21924 21863->21622 21865 7ff600aeeec9 FlsSetValue 21864->21865 21869 7ff600aeeeac 21864->21869 21866 7ff600aeeedb 21865->21866 21870 7ff600aeeeb9 21865->21870 21868 7ff600af0a28 _Getctype 5 API calls 21866->21868 21867 7ff600aeef35 SetLastError 21867->21826 21871 7ff600aeeeea 21868->21871 21869->21865 21869->21870 21870->21867 21872 7ff600aeef08 FlsSetValue 21871->21872 21873 7ff600aeeef8 FlsSetValue 21871->21873 21875 7ff600aeef14 FlsSetValue 21872->21875 21876 7ff600aeef26 21872->21876 21874 7ff600aeef01 21873->21874 21878 7ff600aee95c __free_lconv_mon 5 API calls 21874->21878 21875->21874 21889 7ff600aeeac0 11 API calls _Getctype 21876->21889 21878->21870 21879 7ff600aeef2e 21880 7ff600aee95c __free_lconv_mon 5 API calls 21879->21880 21880->21867 21882 7ff600aef0bb 21881->21882 21887 7ff600aef07f _Getctype 21881->21887 21891 7ff600ae8d9c 11 API calls _get_daylight 21882->21891 21883 7ff600aef0a2 HeapAlloc 21885 7ff600aef0b9 21883->21885 21883->21887 21885->21832 21887->21882 21887->21883 21890 7ff600aeccd0 EnterCriticalSection LeaveCriticalSection std::_Facet_Register 21887->21890 21888->21829 21889->21879 21890->21887 21891->21885 21893 7ff600af25eb 21892->21893 21897 7ff600ae8f22 21892->21897 21925 7ff600aeae44 EnterCriticalSection 21893->21925 21895 7ff600af25f3 21896 7ff600af244c 61 API calls 21895->21896 21895->21897 21896->21897 21898 7ff600af1704 21897->21898 21899 7ff600ae8f37 21898->21899 21900 7ff600af170d 21898->21900 21899->21847 21911 7ff600af1734 21899->21911 21926 7ff600ae8d9c 11 API calls _get_daylight 21900->21926 21902 7ff600af1712 21927 7ff600ae3fd8 47 API calls _invalid_parameter_noinfo_noreturn 21902->21927 21905 7ff600ae403b 21904->21905 21928 7ff600ae3d0c 14 API calls 2 library calls 21905->21928 21907 7ff600ae4056 GetCurrentProcess TerminateProcess 21908->21839 21909->21863 21910->21863 21912 7ff600af173d 21911->21912 21914 7ff600ae8f48 21911->21914 21929 7ff600ae8d9c 11 API calls _get_daylight 21912->21929 21914->21847 21917 7ff600af1764 21914->21917 21915 7ff600af1742 21930 7ff600ae3fd8 47 API calls _invalid_parameter_noinfo_noreturn 21915->21930 21918 7ff600ae8f59 21917->21918 21919 7ff600af176d 21917->21919 21918->21847 21918->21856 21931 7ff600ae8d9c 11 API calls _get_daylight 21919->21931 21921 7ff600af1772 21932 7ff600ae3fd8 47 API calls _invalid_parameter_noinfo_noreturn 21921->21932 21923->21863 21924->21863 21926->21902 21927->21899 21928->21907 21929->21915 21930->21914 21931->21921 21932->21918 21935 7ff600ad9c0d 21933->21935 21947 7ff600ad9e00 21935->21947 21936 7ff600ad9f50 49 API calls 21937 7ff600ad9d0f 21936->21937 21937->21936 21938 7ff600ac765d MultiByteToWideChar MultiByteToWideChar 21937->21938 21938->21643 21939->21627 21940->21629 21941->21631 21942->21633 21943->21635 21944->21637 21945->21639 21948 7ff600ad9f45 21947->21948 21952 7ff600ad9e29 21947->21952 21962 7ff600ac61c0 49 API calls 21948->21962 21951 7ff600addfb8 std::_Facet_Register 49 API calls 21959 7ff600ad9e74 memcpy_s 21951->21959 21953 7ff600ad9e81 21952->21953 21954 7ff600ad9ebd 21952->21954 21952->21959 21953->21951 21955 7ff600ad9f3f 21953->21955 21956 7ff600addfb8 std::_Facet_Register 49 API calls 21954->21956 21961 7ff600ac19d0 49 API calls Concurrency::cancel_current_task 21955->21961 21956->21959 21957 7ff600ae3ff8 _invalid_parameter_noinfo_noreturn 47 API calls 21957->21955 21959->21957 21960 7ff600ad9f07 memcpy_s 21959->21960 21960->21937 21961->21948 21964 7ff600ac167e 21963->21964 21965 7ff600ac1686 21963->21965 21964->21667 21966 7ff600ac16ac VirtualAlloc 21965->21966 21967 7ff600ac16d6 memcpy_s 21966->21967 21968 7ff600ac1704 21967->21968 21969 7ff600ac16f6 VirtualFree 21967->21969 21968->21667 21969->21968 21971 7ff600ac152a 21970->21971 21972 7ff600ac155b VirtualAlloc 21971->21972 21973 7ff600ac15b5 memcpy_s 21971->21973 21974 7ff600ac1587 memcpy_s 21972->21974 21973->21671 21973->21973 21974->21973 21975 7ff600ac15a7 VirtualFree 21974->21975 21975->21973 21978 7ff600ac174b 21976->21978 21977 7ff600ac17fb 21977->21678 21978->21977 21979 7ff600ac177c VirtualAlloc 21978->21979 21980 7ff600ac17a8 memcpy_s 21979->21980 21981 7ff600ac17be VirtualFree 21980->21981 21981->21678 21982->21446 21983 7ff600ade0e0 22006 7ff600addd80 21983->22006 21986 7ff600ade101 21989 7ff600ade241 21986->21989 21991 7ff600ade11f 21986->21991 21987 7ff600ade237 22026 7ff600ade66c 7 API calls 2 library calls 21987->22026 22027 7ff600ade66c 7 API calls 2 library calls 21989->22027 21992 7ff600ade144 21991->21992 21997 7ff600ade161 __scrt_release_startup_lock 21991->21997 22012 7ff600aecde4 21991->22012 21993 7ff600ade24c BuildCatchObjectHelperInternal 21995 7ff600ade1ca 22016 7ff600aec6ec 21995->22016 21997->21995 22023 7ff600aebfd4 47 API calls 21997->22023 21999 7ff600ade1cf 22022 7ff600adbdf0 10 API calls 21999->22022 22001 7ff600ade1ec 22024 7ff600ade7c0 GetModuleHandleW 22001->22024 22003 7ff600ade1f3 22003->21993 22025 7ff600addf04 7 API calls 22003->22025 22005 7ff600ade20a 22005->21992 22007 7ff600addd88 22006->22007 22008 7ff600addd94 __scrt_dllmain_crt_thread_attach 22007->22008 22009 7ff600addda1 22008->22009 22011 7ff600addd9d 22008->22011 22009->22011 22028 7ff600ae03c8 7 API calls 2 library calls 22009->22028 22011->21986 22011->21987 22013 7ff600aece1a 22012->22013 22014 7ff600aecde9 22012->22014 22013->21997 22014->22013 22029 7ff600ac1000 WSAStartup 22014->22029 22017 7ff600aec6fc 22016->22017 22021 7ff600aec711 22016->22021 22017->22021 22036 7ff600aec3a8 50 API calls __free_lconv_mon 22017->22036 22019 7ff600aec71a 22019->22021 22037 7ff600aec578 12 API calls 3 library calls 22019->22037 22021->21999 22022->22001 22023->21995 22024->22003 22025->22005 22026->21989 22027->21993 22028->22011 22032 7ff600addf6c 22029->22032 22035 7ff600addf30 50 API calls 22032->22035 22034 7ff600ac103a 22034->22014 22035->22034 22036->22019 22037->22021 22674 7ff600af15d8 FreeLibrary 22763 7ff600af5fd4 56 API calls 2 library calls 22799 7ff600ac18d0 47 API calls Concurrency::cancel_current_task 22800 7ff600adc8d4 DeleteCriticalSection ctype 22675 7ff600afedd0 DeleteDC DeleteDC DeleteDC DeleteDC 22764 7ff600acbbd0 GetStringTypeW 22801 7ff600acbcd0 LCMapStringEx __crtLCMapStringW 22676 7ff600add1d0 7 API calls ctype 22765 7ff600ace3c7 ExitProcess 22723 7ff600ace2c8 143 API calls memcpy_s 22802 7ff600ade0c4 48 API calls 2 library calls 22677 7ff600ad1dc0 48 API calls 22725 7ff600ad12c0 HeapFree HeapDestroy HeapCreate HeapDestroy ctype 22767 7ff600acbfc0 GdipDisposeImage GdipFree 22678 7ff600afd1bc 57 API calls 2 library calls 22805 7ff600ac1130 HeapAlloc 22681 7ff600afee30 EnterCriticalSection GdiplusShutdown LeaveCriticalSection 22728 7ff600acb331 17 API calls 22729 7ff600af0728 80 API calls __free_lconv_mon 22730 7ff600afef24 DecodePointer 22683 7ff600adfa24 60 API calls __CxxCallCatchBlock 22731 7ff600acef25 RegOpenKeyExW RegDeleteValueW RegSetValueExW RegCloseKey 22769 7ff600ade824 56 API calls 22771 7ff600ace01f 71 API calls memcpy_s 22772 7ff600ad0c20 15 API calls memcpy_s 22773 7ff600acc020 GdipCloneImage GdipAlloc 22684 7ff600ace217 TerminateThread CloseHandle 22774 7ff600ac5410 36 API calls 22685 7ff600ade20e GetModuleHandleW BuildCatchObjectHelperInternal 22810 7ff600afe110 RegCloseKey RegCloseKey 22776 7ff600acd410 393 API calls 5 library calls 22777 7ff600ad1c10 50 API calls 22687 7ff600af0608 17 API calls 2 library calls 22688 7ff600aebe09 63 API calls 22690 7ff600ac5200 8 API calls memcpy_s 22735 7ff600ac5300 115 API calls 22736 7ff600afcf04 CloseHandle 22691 7ff600adee00 RtlPcToFileHeader RaiseException Concurrency::cancel_current_task _com_error::_com_error 22692 7ff600aeadfc 7 API calls 22779 7ff600addffc 59 API calls 2 library calls 22816 7ff600ac1470 VirtualFree 22817 7ff600ac4470 164 API calls std::_Locinfo::_Locinfo_ctor 22780 7ff600ace36a OpenEventLogW ClearEventLogW CloseEventLog 22818 7ff600ae206c 61 API calls 6 library calls 22696 7ff600ac1160 HeapReAlloc 22698 7ff600acf160 52 API calls 4 library calls 22820 7ff600ac1058 GetLastError IsDebuggerPresent OutputDebugStringW shared_ptr 22739 7ff600ade25c GetSystemTimeAsFileTime GetCurrentThreadId GetCurrentProcessId QueryPerformanceCounter 22781 7ff600ac9f50 49 API calls 22701 7ff600aded50 LocalFree 22821 7ff600ae284a 57 API calls __CxxCallCatchBlock 22702 7ff600ac1140 HeapFree 22743 7ff600ac5640 40 API calls 22822 7ff600ac1040 GetTickCount 22744 7ff600af7e40 57 API calls 4 library calls 22783 7ff600ad0b40 7 API calls 22785 7ff600af573c GetProcessHeap 22706 7ff600ac11b0 HeapDestroy 22745 7ff600aeceb0 GetCommandLineA GetCommandLineW 22707 7ff600afedb0 WSACleanup 22708 7ff600af09ac 57 API calls _isindst 22038 7ff600ae8aa8 22039 7ff600ae8ac5 22038->22039 22040 7ff600ae8ab6 GetLastError ExitThread 22038->22040 22054 7ff600aeed10 GetLastError 22039->22054 22045 7ff600ae8ae3 22051 7ff600ac72d0 116 API calls 22045->22051 22080 7ff600ac3da0 22045->22080 22088 7ff600ac3b00 22045->22088 22108 7ff600accd40 22045->22108 22047 7ff600ae8b02 22161 7ff600ae8cbc 22047->22161 22051->22047 22055 7ff600aeed34 FlsGetValue 22054->22055 22056 7ff600aeed51 FlsSetValue 22054->22056 22057 7ff600aeed4b 22055->22057 22059 7ff600aeed41 22055->22059 22058 7ff600aeed63 22056->22058 22056->22059 22057->22056 22061 7ff600af0a28 _Getctype 11 API calls 22058->22061 22060 7ff600aeedbd SetLastError 22059->22060 22062 7ff600aeeddd 22060->22062 22063 7ff600ae8aca 22060->22063 22064 7ff600aeed72 22061->22064 22166 7ff600ae4078 47 API calls 2 library calls 22062->22166 22076 7ff600af161c 22063->22076 22066 7ff600aeed90 FlsSetValue 22064->22066 22067 7ff600aeed80 FlsSetValue 22064->22067 22068 7ff600aeedae 22066->22068 22069 7ff600aeed9c FlsSetValue 22066->22069 22071 7ff600aeed89 22067->22071 22165 7ff600aeeac0 11 API calls _Getctype 22068->22165 22069->22071 22073 7ff600aee95c __free_lconv_mon 11 API calls 22071->22073 22073->22059 22074 7ff600aeedb6 22075 7ff600aee95c __free_lconv_mon 11 API calls 22074->22075 22075->22060 22077 7ff600ae8ad6 22076->22077 22078 7ff600af162b 22076->22078 22077->22045 22164 7ff600af1350 5 API calls std::_Lockit::_Lockit 22077->22164 22078->22077 22167 7ff600af0d68 5 API calls std::_Lockit::_Lockit 22078->22167 22081 7ff600ac3e22 22080->22081 22085 7ff600ac3db4 22080->22085 22081->22047 22082 7ff600ac3e15 22082->22047 22083 7ff600ac3dc8 SleepEx 22083->22085 22084 7ff600ac3df1 timeGetTime 22084->22085 22085->22082 22085->22083 22086 7ff600ac3e30 10 API calls 22085->22086 22168 7ff600ac37a0 22085->22168 22086->22084 22089 7ff600ac3b18 22088->22089 22090 7ff600ac3c54 22089->22090 22091 7ff600ac3be0 select 22089->22091 22092 7ff600ac3c08 recv 22089->22092 22093 7ff600ac1500 VirtualAlloc VirtualFree 22089->22093 22094 7ff600ac1730 2 API calls 22089->22094 22095 7ff600ae8d9c 11 API calls _get_daylight 22089->22095 22096 7ff600ac3d04 timeGetTime 22089->22096 22171 7ff600acdbef 22089->22171 22179 7ff600ace3e9 GetCurrentProcess OpenProcessToken 22089->22179 22187 7ff600acdc4d 22089->22187 22202 7ff600ace29b 22089->22202 22206 7ff600ace46d GetCurrentProcess OpenProcessToken 22089->22206 22214 7ff600acd9c0 22089->22214 22229 7ff600aceed0 22089->22229 22236 7ff600acde3f 22089->22236 22249 7ff600ace4ee GetCurrentProcess OpenProcessToken 22089->22249 22257 7ff600ac1810 VirtualAlloc VirtualFree memcpy_s 22089->22257 22090->22047 22091->22089 22091->22090 22092->22089 22093->22089 22094->22089 22095->22089 22097 7ff600ac1730 2 API calls 22096->22097 22097->22089 22109 7ff600acd233 22108->22109 22110 7ff600accd78 22108->22110 22572 7ff600ada680 22109->22572 22115 7ff600acd092 22110->22115 22121 7ff600acce26 22110->22121 22119 7ff600addfb8 std::_Facet_Register 49 API calls 22115->22119 22116 7ff600acd375 22118 7ff600addfb8 std::_Facet_Register 49 API calls 22116->22118 22117 7ff600accf09 GetSystemDirectoryA 22568 7ff600ac9f70 22117->22568 22125 7ff600acd393 memcpy_s 22118->22125 22126 7ff600acd09f memcpy_s 22119->22126 22120 7ff600ae8a40 std::_Locinfo::_Locinfo_ctor 47 API calls 22127 7ff600acd27f 22120->22127 22122 7ff600acce8f memcpy_s 22121->22122 22123 7ff600addfb8 std::_Facet_Register 49 API calls 22121->22123 22122->22117 22128 7ff600acd0eb memcpy_s 22123->22128 22136 7ff600ae8a40 std::_Locinfo::_Locinfo_ctor 47 API calls 22125->22136 22137 7ff600ae8a40 std::_Locinfo::_Locinfo_ctor 47 API calls 22126->22137 22130 7ff600ae8a40 std::_Locinfo::_Locinfo_ctor 47 API calls 22127->22130 22140 7ff600ae94e8 std::_Locinfo::_Locinfo_ctor 47 API calls 22128->22140 22133 7ff600acd291 22130->22133 22131 7ff600acd1ae 22134 7ff600addfb8 std::_Facet_Register 49 API calls 22131->22134 22132 7ff600accf7c VirtualAllocEx 22132->22131 22135 7ff600accfa9 WriteProcessMemory 22132->22135 22138 7ff600addfb8 std::_Facet_Register 49 API calls 22133->22138 22141 7ff600acd1bf memcpy_s 22134->22141 22135->22131 22142 7ff600accfca GetThreadContext 22135->22142 22151 7ff600acd080 22136->22151 22137->22151 22139 7ff600acd2a2 memcpy_s 22138->22139 22145 7ff600ac3670 50 API calls 22139->22145 22140->22122 22146 7ff600ac3670 50 API calls 22141->22146 22142->22131 22143 7ff600accfee SetThreadContext 22142->22143 22143->22131 22144 7ff600acd00f ResumeThread 22143->22144 22147 7ff600addfb8 std::_Facet_Register 49 API calls 22144->22147 22148 7ff600acd2df 22145->22148 22146->22151 22149 7ff600acd02b memcpy_s 22147->22149 22153 7ff600acd2f9 22148->22153 22160 7ff600ac3e30 10 API calls 22148->22160 22150 7ff600ac3670 50 API calls 22149->22150 22152 7ff600acd067 22150->22152 22151->22047 22152->22151 22159 7ff600ac3e30 10 API calls 22152->22159 22616 7ff600adad40 22153->22616 22156 7ff600addfb8 std::_Facet_Register 49 API calls 22157 7ff600acd339 memcpy_s 22156->22157 22158 7ff600ac3670 50 API calls 22157->22158 22158->22116 22159->22151 22160->22153 22660 7ff600ae8b18 22161->22660 22164->22045 22165->22074 22167->22077 22169 7ff600ac37af setsockopt CancelIo closesocket SetEvent 22168->22169 22170 7ff600ac381a 22168->22170 22169->22170 22170->22085 22172 7ff600ace2c3 22171->22172 22173 7ff600acdbfb 22171->22173 22172->22089 22174 7ff600acdc19 22173->22174 22175 7ff600ae8a40 std::_Locinfo::_Locinfo_ctor 47 API calls 22173->22175 22174->22172 22258 7ff600acf410 22174->22258 22175->22174 22177 7ff600acdc41 22177->22172 22178 7ff600ac3e30 10 API calls 22177->22178 22178->22172 22180 7ff600ace463 ExitWindowsEx GetCurrentProcess OpenProcessToken 22179->22180 22181 7ff600ace408 LookupPrivilegeValueW AdjustTokenPrivileges GetLastError CloseHandle 22179->22181 22183 7ff600aceffa 22180->22183 22184 7ff600ace598 LookupPrivilegeValueW AdjustTokenPrivileges GetLastError 22180->22184 22181->22180 22183->22089 22185 7ff600ace5f1 CloseHandle 22184->22185 22186 7ff600acef19 CloseHandle 22184->22186 22185->22183 22186->22183 22188 7ff600acdc59 22187->22188 22194 7ff600acdd3d 22187->22194 22189 7ff600addfb8 std::_Facet_Register 49 API calls 22188->22189 22190 7ff600acdc63 memcpy_s 22189->22190 22191 7ff600acdc91 wsprintfW 22190->22191 22192 7ff600acdca6 22190->22192 22191->22192 22193 7ff600acdcf6 memcpy_s 22192->22193 22195 7ff600acddf3 22192->22195 22193->22194 22201 7ff600ac3e30 10 API calls 22193->22201 22194->22089 22196 7ff600ae8a40 std::_Locinfo::_Locinfo_ctor 47 API calls 22195->22196 22197 7ff600acde08 22196->22197 22198 7ff600ae8be0 52 API calls 22197->22198 22199 7ff600acde24 CloseHandle 22198->22199 22200 7ff600acde3a 22199->22200 22200->22194 22201->22194 22203 7ff600ace2a2 22202->22203 22204 7ff600ace2c3 22203->22204 22205 7ff600ac3e30 10 API calls 22203->22205 22204->22089 22205->22204 22207 7ff600ace48c LookupPrivilegeValueW AdjustTokenPrivileges GetLastError CloseHandle 22206->22207 22208 7ff600ace4e7 ExitWindowsEx GetCurrentProcess OpenProcessToken 22206->22208 22207->22208 22210 7ff600ace598 LookupPrivilegeValueW AdjustTokenPrivileges GetLastError 22208->22210 22213 7ff600aceffa 22208->22213 22211 7ff600ace5f1 CloseHandle 22210->22211 22212 7ff600acef19 CloseHandle 22210->22212 22211->22213 22212->22213 22213->22089 22215 7ff600acd9df 22214->22215 22216 7ff600acda2a CloseHandle 22214->22216 22217 7ff600acda0b 22215->22217 22218 7ff600acda44 22215->22218 22216->22218 22217->22216 22219 7ff600ae3ff8 _invalid_parameter_noinfo_noreturn 47 API calls 22218->22219 22220 7ff600acda49 22219->22220 22222 7ff600addfb8 std::_Facet_Register 49 API calls 22220->22222 22228 7ff600acdaf7 22220->22228 22221 7ff600acdb41 RegOpenKeyExW 22223 7ff600acdb7c RegQueryValueExW 22221->22223 22225 7ff600acdbb0 22221->22225 22224 7ff600acda83 memcpy_s 22222->22224 22223->22225 22226 7ff600acda97 GetLastInputInfo GetTickCount wsprintfW 22224->22226 22225->22089 22476 7ff600ac80c0 22226->22476 22228->22221 22228->22225 22230 7ff600addfb8 std::_Facet_Register 49 API calls 22229->22230 22232 7ff600aceeda memcpy_s 22230->22232 22231 7ff600aceffa 22231->22089 22232->22231 22233 7ff600ae8be0 52 API calls 22232->22233 22234 7ff600acef16 CloseHandle 22233->22234 22234->22231 22237 7ff600addfb8 std::_Facet_Register 49 API calls 22236->22237 22238 7ff600acde49 memcpy_s 22237->22238 22239 7ff600addfb8 std::_Facet_Register 49 API calls 22238->22239 22240 7ff600acde9d 22239->22240 22241 7ff600ae8a40 std::_Locinfo::_Locinfo_ctor 47 API calls 22240->22241 22242 7ff600acdeed 22241->22242 22243 7ff600acdefe 22242->22243 22567 7ff600aca4c0 49 API calls memcpy_s 22242->22567 22245 7ff600ae8be0 52 API calls 22243->22245 22246 7ff600acef16 CloseHandle 22245->22246 22248 7ff600aceffa 22246->22248 22248->22089 22250 7ff600ace50d LookupPrivilegeValueW AdjustTokenPrivileges GetLastError CloseHandle 22249->22250 22251 7ff600ace568 ExitWindowsEx GetCurrentProcess OpenProcessToken 22249->22251 22250->22251 22253 7ff600aceffa 22251->22253 22254 7ff600ace598 LookupPrivilegeValueW AdjustTokenPrivileges GetLastError 22251->22254 22253->22089 22255 7ff600ace5f1 CloseHandle 22254->22255 22256 7ff600acef19 CloseHandle 22254->22256 22255->22253 22256->22253 22257->22089 22259 7ff600addfb8 std::_Facet_Register 49 API calls 22258->22259 22260 7ff600acf437 memcpy_s 22259->22260 22261 7ff600acf44b GetLastInputInfo GetTickCount wsprintfW GetForegroundWindow 22260->22261 22262 7ff600acf4b4 CreateToolhelp32Snapshot 22261->22262 22263 7ff600acf4a1 GetWindowTextW 22261->22263 22264 7ff600acf555 CreateToolhelp32Snapshot 22262->22264 22265 7ff600acf4d8 memcpy_s 22262->22265 22263->22262 22267 7ff600acf577 memcpy_s 22264->22267 22290 7ff600acf5f8 CreateToolhelp32Snapshot 22264->22290 22268 7ff600acf4e9 Process32FirstW 22265->22268 22271 7ff600acf58b Process32FirstW 22267->22271 22268->22264 22274 7ff600acf501 22268->22274 22270 7ff600acf61a memcpy_s 22275 7ff600acf62e Process32FirstW 22270->22275 22280 7ff600acf5a9 22271->22280 22271->22290 22273 7ff600acf544 Process32NextW 22273->22264 22273->22274 22274->22264 22274->22273 22284 7ff600acf64c 22275->22284 22295 7ff600acf6a8 RegOpenKeyExW 22275->22295 22276 7ff600acf913 RegOpenKeyExW 22278 7ff600acf9f2 RegOpenKeyExW 22276->22278 22279 7ff600acf951 RegQueryValueExW 22276->22279 22277 7ff600acf6fa RegQueryValueExW 22281 7ff600acf908 RegCloseKey 22277->22281 22291 7ff600acf734 memcpy_s 22277->22291 22282 7ff600acfa30 RegQueryValueExW 22278->22282 22283 7ff600acfad1 7 API calls 22278->22283 22285 7ff600acf9e7 RegCloseKey 22279->22285 22296 7ff600acf986 memcpy_s 22279->22296 22286 7ff600acf5e4 Process32NextW 22280->22286 22280->22290 22281->22276 22287 7ff600acfac6 RegCloseKey 22282->22287 22298 7ff600acfa65 memcpy_s 22282->22298 22288 7ff600acfb91 FindClose 22283->22288 22289 7ff600acfb89 22283->22289 22292 7ff600acf694 Process32NextW 22284->22292 22284->22295 22285->22278 22286->22280 22286->22290 22287->22283 22312 7ff600acfd10 7 API calls 22288->22312 22289->22288 22290->22270 22290->22295 22294 7ff600acf75e RegQueryValueExW 22291->22294 22292->22284 22292->22295 22294->22281 22297 7ff600acf791 22294->22297 22295->22276 22295->22277 22299 7ff600acf9b0 RegQueryValueExW 22296->22299 22332 7ff600ad1310 49 API calls 4 library calls 22297->22332 22302 7ff600acfa8f RegQueryValueExW 22298->22302 22299->22285 22300 7ff600acf9df 22299->22300 22300->22285 22302->22287 22303 7ff600acfabe 22302->22303 22303->22287 22304 7ff600acfbd1 memcpy_s 22309 7ff600acfcbe 22304->22309 22311 7ff600ac3e30 10 API calls 22304->22311 22305 7ff600acf900 22305->22281 22306 7ff600acfcfe 22307 7ff600ae3ff8 _invalid_parameter_noinfo_noreturn 47 API calls 22306->22307 22308 7ff600acfd03 22307->22308 22309->22177 22310 7ff600acf79d 22310->22281 22310->22305 22310->22306 22311->22309 22313 7ff600acfdbe GetSystemMetrics 22312->22313 22314 7ff600acfdaa 22312->22314 22316 7ff600acfdde GetSystemMetrics 22313->22316 22317 7ff600acfe28 GetSystemMetrics 22313->22317 22315 7ff600acfe47 8 API calls 22314->22315 22318 7ff600acff92 memcpy_s 22315->22318 22316->22315 22317->22315 22319 7ff600acffa7 GetDIBits 22318->22319 22320 7ff600acffdf memcpy_s 22319->22320 22321 7ff600addfb8 std::_Facet_Register 49 API calls 22320->22321 22322 7ff600ad0052 22321->22322 22333 7ff600ad0220 GlobalAlloc GlobalLock 22322->22333 22325 7ff600ad0089 DeleteObject DeleteObject ReleaseDC 22329 7ff600ad00b3 22325->22329 22326 7ff600ad011c memcpy_s 22327 7ff600ad015d DeleteObject DeleteObject ReleaseDC 22326->22327 22327->22329 22328 7ff600ae3ff8 _invalid_parameter_noinfo_noreturn 47 API calls 22330 7ff600ad0212 22328->22330 22329->22328 22331 7ff600ad00ed 22329->22331 22331->22304 22332->22310 22381 7ff600afd3b0 22333->22381 22336 7ff600ad029f 22383 7ff600ac61e0 22336->22383 22337 7ff600ad05f1 GlobalFree 22339 7ff600ad0081 22337->22339 22339->22325 22339->22326 22342 7ff600ad02fc 22343 7ff600ad0304 GdipCreateBitmapFromStream 22342->22343 22380 7ff600ad0567 22342->22380 22344 7ff600ad0330 GdipDisposeImage 22343->22344 22345 7ff600ad033b 22343->22345 22344->22380 22401 7ff600acc340 GdipGetImagePixelFormat 22345->22401 22347 7ff600ad05aa 22350 7ff600ac61e0 58 API calls 22347->22350 22348 7ff600ad0586 DeleteObject 22348->22347 22349 7ff600ad0348 GdipDisposeImage 22351 7ff600ad035c CreateStreamOnHGlobal 22349->22351 22349->22380 22352 7ff600ad05af EnterCriticalSection 22350->22352 22353 7ff600ad0379 22351->22353 22351->22380 22354 7ff600ad05c2 EnterCriticalSection 22352->22354 22355 7ff600ad05e7 LeaveCriticalSection 22352->22355 22435 7ff600acc7b0 22353->22435 22357 7ff600ad05d4 GdiplusShutdown 22354->22357 22358 7ff600ad05da LeaveCriticalSection 22354->22358 22355->22337 22357->22358 22358->22355 22359 7ff600ad0386 GetHGlobalFromStream GlobalLock 22360 7ff600ad03ae GlobalFree 22359->22360 22361 7ff600ad043f GlobalSize 22359->22361 22363 7ff600ad03cf DeleteObject 22360->22363 22364 7ff600ad03f1 22360->22364 22366 7ff600ad0452 memcpy_s 22361->22366 22363->22364 22365 7ff600ac61e0 58 API calls 22364->22365 22367 7ff600ad03f6 EnterCriticalSection 22365->22367 22449 7ff600ac9fd0 22366->22449 22369 7ff600ad042e LeaveCriticalSection 22367->22369 22370 7ff600ad0409 EnterCriticalSection 22367->22370 22369->22339 22372 7ff600ad0421 LeaveCriticalSection 22370->22372 22373 7ff600ad041b GdiplusShutdown 22370->22373 22371 7ff600ad0481 22374 7ff600ad0618 22371->22374 22375 7ff600ad0514 22371->22375 22372->22369 22373->22372 22376 7ff600ae3ff8 _invalid_parameter_noinfo_noreturn 47 API calls 22374->22376 22378 7ff600ad0553 GlobalUnlock 22375->22378 22379 7ff600ad052f DeleteObject 22375->22379 22377 7ff600ad061d 22376->22377 22378->22380 22379->22378 22380->22347 22380->22348 22382 7ff600ad0278 GlobalUnlock CreateStreamOnHGlobal 22381->22382 22382->22336 22382->22337 22384 7ff600ac6200 22383->22384 22385 7ff600ac626b EnterCriticalSection LeaveCriticalSection 22383->22385 22463 7ff600addccc AcquireSRWLockExclusive SleepConditionVariableSRW ReleaseSRWLockExclusive 22384->22463 22394 7ff600acc9b0 22385->22394 22395 7ff600ac61e0 58 API calls 22394->22395 22396 7ff600acc9bb 22395->22396 22397 7ff600acc9c4 22396->22397 22398 7ff600acc9cc EnterCriticalSection 22396->22398 22397->22342 22399 7ff600acca23 LeaveCriticalSection 22398->22399 22400 7ff600acc9e9 GdiplusStartup 22398->22400 22399->22342 22400->22399 22403 7ff600acc385 GdipGetImageHeight 22401->22403 22404 7ff600acc402 22403->22404 22405 7ff600acc40f GdipGetImageWidth 22403->22405 22404->22405 22406 7ff600acc424 22405->22406 22464 7ff600acc160 22406->22464 22408 7ff600acc445 22409 7ff600acc461 GdipGetImagePaletteSize 22408->22409 22413 7ff600acc449 ctype 22408->22413 22427 7ff600acc5fc 22408->22427 22420 7ff600acc47a std::_Locinfo::_Locinfo_ctor 22409->22420 22410 7ff600acc6e2 GdipCreateBitmapFromScan0 GdipGetImageGraphicsContext GdipDrawImageI GdipDeleteGraphics GdipDisposeImage 22410->22413 22411 7ff600acc622 GdipBitmapLockBits 22411->22413 22415 7ff600acc66a memcpy_s 22411->22415 22412 7ff600acc6c4 GdipBitmapUnlockBits 22412->22413 22413->22349 22414 7ff600acc78d memcpy_s 22471 7ff600ae8d9c 11 API calls _get_daylight 22414->22471 22415->22412 22415->22414 22417 7ff600acc4e7 GdipGetImagePalette 22424 7ff600acc4fb 22417->22424 22418 7ff600acc799 22472 7ff600ae3fd8 47 API calls _invalid_parameter_noinfo_noreturn 22418->22472 22420->22413 22420->22417 22421 7ff600acc7a4 22473 7ff600ac10f0 RtlPcToFileHeader RaiseException Concurrency::cancel_current_task 22421->22473 22424->22413 22424->22424 22425 7ff600acc5aa SetDIBColorTable 22424->22425 22469 7ff600ac6280 56 API calls 22424->22469 22426 7ff600acc5c4 SelectObject 22425->22426 22425->22427 22470 7ff600ac6280 56 API calls 22426->22470 22427->22410 22427->22411 22429 7ff600acc564 22432 7ff600acc58e SelectObject 22429->22432 22433 7ff600acc586 CreateCompatibleDC 22429->22433 22431 7ff600acc5db 22431->22427 22434 7ff600acc5f3 DeleteDC 22431->22434 22432->22425 22433->22432 22434->22427 22436 7ff600acc9b0 61 API calls 22435->22436 22437 7ff600acc7d4 22436->22437 22438 7ff600acc992 22437->22438 22439 7ff600acc7dc GdipGetImageEncodersSize 22437->22439 22438->22359 22439->22438 22441 7ff600acc7f2 std::_Locinfo::_Locinfo_ctor 22439->22441 22440 7ff600acc86b GdipGetImageEncoders 22442 7ff600acc861 ctype 22440->22442 22443 7ff600acc87f 22440->22443 22441->22440 22441->22442 22442->22359 22443->22442 22444 7ff600acc923 GdipCreateBitmapFromHBITMAP 22443->22444 22445 7ff600acc8f1 GdipCreateBitmapFromScan0 22443->22445 22446 7ff600acc933 GdipSaveImageToStream 22444->22446 22445->22446 22447 7ff600acc95e GdipDisposeImage 22446->22447 22448 7ff600acc951 GdipDisposeImage 22446->22448 22447->22442 22448->22442 22450 7ff600aca0d7 22449->22450 22453 7ff600aca001 22449->22453 22475 7ff600ac61c0 49 API calls 22450->22475 22455 7ff600aca007 memcpy_s 22453->22455 22456 7ff600aca033 22453->22456 22457 7ff600aca08c 22453->22457 22454 7ff600addfb8 std::_Facet_Register 49 API calls 22458 7ff600aca049 22454->22458 22455->22371 22456->22454 22459 7ff600aca0d1 22456->22459 22460 7ff600addfb8 std::_Facet_Register 49 API calls 22457->22460 22458->22455 22462 7ff600ae3ff8 _invalid_parameter_noinfo_noreturn 47 API calls 22458->22462 22474 7ff600ac19d0 49 API calls Concurrency::cancel_current_task 22459->22474 22460->22455 22462->22459 22465 7ff600acc19b memcpy_s 22464->22465 22466 7ff600acc202 CreateDIBSection 22465->22466 22468 7ff600acc249 ctype 22465->22468 22467 7ff600acc227 GetObjectW 22466->22467 22466->22468 22467->22468 22468->22408 22469->22429 22470->22431 22471->22418 22472->22421 22474->22450 22477 7ff600ac8164 memcpy_s 22476->22477 22479 7ff600ac80f6 memcpy_s 22476->22479 22478 7ff600adc400 77 API calls 22477->22478 22481 7ff600ac8185 22478->22481 22513 7ff600adc400 22479->22513 22481->22481 22482 7ff600ac823b 22481->22482 22483 7ff600ac8337 22481->22483 22484 7ff600ac8138 memcpy_s 22481->22484 22512 7ff600ac820f 22481->22512 22527 7ff600ac9de0 49 API calls 4 library calls 22482->22527 22529 7ff600ac9de0 49 API calls 4 library calls 22483->22529 22484->22228 22487 7ff600ae3ff8 _invalid_parameter_noinfo_noreturn 47 API calls 22490 7ff600ac86f5 22487->22490 22488 7ff600ac8256 22492 7ff600ac9fd0 49 API calls 22488->22492 22489 7ff600ac8356 22493 7ff600ac9fd0 49 API calls 22489->22493 22491 7ff600ae3ff8 _invalid_parameter_noinfo_noreturn 47 API calls 22490->22491 22494 7ff600ac86fb 22491->22494 22498 7ff600ac8286 22492->22498 22496 7ff600ac8383 22493->22496 22495 7ff600ae3ff8 _invalid_parameter_noinfo_noreturn 47 API calls 22494->22495 22497 7ff600ac8701 22495->22497 22530 7ff600ac9d20 47 API calls _invalid_parameter_noinfo_noreturn 22496->22530 22501 7ff600ae3ff8 _invalid_parameter_noinfo_noreturn 47 API calls 22497->22501 22528 7ff600ac9d20 47 API calls _invalid_parameter_noinfo_noreturn 22498->22528 22502 7ff600ac8707 22501->22502 22503 7ff600ac8574 OutputDebugStringA 22504 7ff600ac8598 MultiByteToWideChar 22503->22504 22510 7ff600ac8611 memcpy_s 22503->22510 22505 7ff600addff4 22504->22505 22506 7ff600ac85df MultiByteToWideChar 22505->22506 22506->22510 22507 7ff600ac855c 22507->22503 22508 7ff600ac82f3 memcpy_s std::_Locinfo::_Locinfo_ctor 22508->22490 22508->22494 22508->22503 22508->22507 22531 7ff600aca170 49 API calls 4 library calls 22508->22531 22532 7ff600ac9d20 47 API calls _invalid_parameter_noinfo_noreturn 22510->22532 22512->22484 22512->22487 22512->22497 22514 7ff600adc420 wsprintfW CreateFileW 22513->22514 22515 7ff600adc46d DeviceIoControl 22514->22515 22516 7ff600adc629 22514->22516 22517 7ff600adc620 CloseHandle 22515->22517 22519 7ff600adc4b8 ctype 22515->22519 22516->22484 22517->22516 22518 7ff600adc4e2 DeviceIoControl 22518->22519 22522 7ff600adc613 ctype 22518->22522 22519->22517 22519->22518 22520 7ff600adc53c DeviceIoControl 22519->22520 22521 7ff600adc5a0 DeviceIoControl 22519->22521 22523 7ff600adc640 WideCharToMultiByte WideCharToMultiByte 22519->22523 22533 7ff600adc2d0 22519->22533 22520->22517 22520->22519 22521->22519 22521->22522 22522->22517 22523->22519 22526 7ff600adc60f 22526->22516 22527->22488 22528->22508 22529->22489 22530->22508 22531->22508 22532->22512 22535 7ff600adc2f1 22533->22535 22534 7ff600adc3e9 CloseHandle 22534->22514 22534->22526 22535->22534 22535->22535 22536 7ff600adc34f CreateFileA 22535->22536 22536->22534 22537 7ff600adc388 ctype 22536->22537 22538 7ff600adc390 DeviceIoControl 22537->22538 22538->22534 22539 7ff600adc3cb 22538->22539 22542 7ff600adbef0 22539->22542 22543 7ff600adc2b0 CloseHandle 22542->22543 22561 7ff600adbf1d memcpy_s 22542->22561 22544 7ff600adbf60 DeviceIoControl 22546 7ff600adc286 ctype 22544->22546 22544->22561 22545 7ff600adbfac DeviceIoControl 22545->22561 22546->22543 22547 7ff600adc0ae DeviceIoControl 22547->22561 22548 7ff600adc028 GlobalAlloc 22549 7ff600adc040 DeviceIoControl 22548->22549 22548->22561 22552 7ff600adc09b GlobalFree 22549->22552 22549->22561 22550 7ff600adc10e GlobalAlloc 22551 7ff600adc123 DeviceIoControl 22550->22551 22550->22561 22554 7ff600adc161 22551->22554 22555 7ff600adc18c GlobalFree 22551->22555 22552->22561 22553 7ff600adc6e0 WideCharToMultiByte WideCharToMultiByte GetSystemDefaultLangID DeviceIoControl lstrcpyA 22553->22561 22562 7ff600adc640 WideCharToMultiByte 22554->22562 22555->22561 22557 7ff600adc16a GlobalFree 22558 7ff600adc17b 22557->22558 22557->22561 22560 7ff600adc2d0 58 API calls 22558->22560 22558->22561 22560->22558 22561->22544 22561->22545 22561->22546 22561->22547 22561->22548 22561->22550 22561->22552 22561->22553 22566 7ff600adbe90 51 API calls 22561->22566 22563 7ff600adc6ba ctype 22562->22563 22564 7ff600adc681 22562->22564 22563->22557 22564->22563 22565 7ff600adc690 WideCharToMultiByte 22564->22565 22565->22563 22566->22561 22567->22243 22569 7ff600ac9f96 22568->22569 22622 7ff600ae8818 22569->22622 22573 7ff600ada6a3 22572->22573 22574 7ff600ada6c0 SetLastError 22572->22574 22573->22574 22575 7ff600adab8d SetLastError 22573->22575 22579 7ff600ada6d2 22573->22579 22576 7ff600acd242 22574->22576 22575->22576 22576->22151 22608 7ff600adabd0 22576->22608 22577 7ff600ada745 GetNativeSystemInfo 22577->22575 22578 7ff600ada77c VirtualAlloc 22577->22578 22580 7ff600ada7ad VirtualAlloc 22578->22580 22588 7ff600ada7d0 22578->22588 22579->22575 22579->22577 22581 7ff600ada8a7 SetLastError 22580->22581 22580->22588 22581->22576 22582 7ff600ada842 GetProcessHeap HeapAlloc 22583 7ff600ada94c 22582->22583 22584 7ff600ada868 VirtualFree 22582->22584 22586 7ff600ada9af SetLastError 22583->22586 22587 7ff600ada9c7 VirtualAlloc 22583->22587 22584->22581 22585 7ff600ada87e ctype 22584->22585 22585->22581 22589 7ff600ada880 VirtualFree 22585->22589 22603 7ff600ada9ba memcpy_s 22586->22603 22587->22603 22588->22582 22590 7ff600ada806 VirtualAlloc 22588->22590 22591 7ff600ada909 VirtualFree 22588->22591 22589->22585 22593 7ff600ada833 22590->22593 22594 7ff600ada8e0 VirtualFree 22590->22594 22591->22581 22596 7ff600ada91f ctype 22591->22596 22592 7ff600adad40 3 API calls 22592->22603 22593->22582 22593->22588 22598 7ff600ada8ff ctype 22594->22598 22597 7ff600ada920 VirtualFree 22596->22597 22600 7ff600ada947 22596->22600 22597->22596 22598->22594 22599 7ff600ada907 22598->22599 22599->22581 22600->22581 22603->22587 22603->22592 22604 7ff600adaae1 22603->22604 22636 7ff600ada0e0 22603->22636 22641 7ff600ada4b0 22603->22641 22650 7ff600ada220 22603->22650 22605 7ff600adab4e SetLastError 22604->22605 22607 7ff600adab61 22604->22607 22606 7ff600adad40 3 API calls 22605->22606 22606->22607 22607->22575 22609 7ff600adac37 22608->22609 22614 7ff600adac0d 22608->22614 22610 7ff600adad1a SetLastError 22609->22610 22611 7ff600acd256 22609->22611 22610->22611 22611->22116 22611->22120 22612 7ff600adaccd 22659 7ff600aea530 47 API calls 2 library calls 22612->22659 22614->22609 22614->22612 22658 7ff600aea120 47 API calls 3 library calls 22614->22658 22617 7ff600acd328 22616->22617 22618 7ff600adad49 ctype 22616->22618 22617->22156 22619 7ff600adadd4 VirtualFree 22618->22619 22621 7ff600adade3 ctype 22618->22621 22619->22621 22620 7ff600adae25 GetProcessHeap HeapFree 22620->22617 22621->22620 22623 7ff600ae8851 22622->22623 22626 7ff600ae8894 22623->22626 22632 7ff600ae40d0 51 API calls 2 library calls 22623->22632 22628 7ff600ae88d3 22626->22628 22633 7ff600ae3f0c 47 API calls _invalid_parameter_noinfo_noreturn 22626->22633 22627 7ff600ae88f9 22630 7ff600ac9fb8 CreateProcessA 22627->22630 22635 7ff600ae3bec 47 API calls 2 library calls 22627->22635 22628->22627 22634 7ff600ae3bec 47 API calls 2 library calls 22628->22634 22630->22131 22630->22132 22632->22626 22633->22628 22634->22627 22635->22630 22637 7ff600ada121 memcpy_s 22636->22637 22638 7ff600ada1f8 22636->22638 22637->22638 22639 7ff600ada190 VirtualAlloc 22637->22639 22640 7ff600ada1ed SetLastError 22637->22640 22638->22603 22639->22637 22639->22638 22640->22638 22642 7ff600ada5d1 22641->22642 22643 7ff600ada4d7 IsBadReadPtr 22641->22643 22642->22603 22643->22642 22644 7ff600ada4fc 22643->22644 22644->22642 22646 7ff600ada5ed SetLastError 22644->22646 22647 7ff600ada5b7 IsBadReadPtr 22644->22647 22648 7ff600ada5d3 SetLastError 22644->22648 22646->22642 22647->22642 22647->22644 22648->22642 22657 7ff600ada263 22650->22657 22651 7ff600ada408 22652 7ff600ada431 22651->22652 22653 7ff600ada452 VirtualProtect 22651->22653 22654 7ff600ada419 22651->22654 22652->22603 22653->22652 22654->22652 22655 7ff600ada41e VirtualFree 22654->22655 22655->22652 22656 7ff600ada361 VirtualProtect 22656->22652 22656->22657 22657->22651 22657->22656 22658->22612 22659->22609 22661 7ff600aeee88 _get_daylight 11 API calls 22660->22661 22664 7ff600ae8b29 22661->22664 22662 7ff600ae8b70 ExitThread 22663 7ff600ae8b45 22666 7ff600ae8b53 CloseHandle 22663->22666 22667 7ff600ae8b59 22663->22667 22664->22662 22664->22663 22669 7ff600af139c 5 API calls std::_Lockit::_Lockit 22664->22669 22666->22667 22667->22662 22668 7ff600ae8b67 FreeLibraryAndExitThread 22667->22668 22668->22662 22669->22663 22710 7ff600ac11a0 HeapSize 22788 7ff600acefa3 RegOpenKeyExW RegDeleteValueW RegCloseKey 22829 7ff600ac54a0 70 API calls 22830 7ff600ac98a0 83 API calls 22789 7ff600ae03a0 10 API calls 2 library calls 22790 7ff600aea798 60 API calls 5 library calls 22748 7ff600ace697 79 API calls 3 library calls 22713 7ff600af4190 54 API calls 5 library calls 22714 7ff600acbd90 13 API calls 22793 7ff600aecb88 11 API calls 22833 7ff600af8088 55 API calls 4 library calls 22752 7ff600ac1a80 LeaveCriticalSection 22753 7ff600ad1280 8 API calls 22754 7ff600acbe80 12 API calls _Wcrtomb 22794 7ff600ac9380 GetModuleFileNameW GetCommandLineW GetStartupInfoW CreateProcessW ExitProcess 22834 7ff600acc080 64 API calls 22835 7ff600ac1078 InitializeCriticalSectionEx shared_ptr

            Control-flow Graph

            • Executed
            • Not Executed
            control_flow_graph 0 7ff600ac6370-7ff600ac63c4 call 7ff600ade600 call 7ff600addfb8 call 7ff600afda50 7 7ff600ac63de-7ff600ac642c call 7ff600afda50 gethostname gethostbyname 0->7 8 7ff600ac63c6-7ff600ac63d9 call 7ff600ae8a40 0->8 12 7ff600ac64cf-7ff600ac65b8 MultiByteToWideChar * 2 GetLastInputInfo GetTickCount wsprintfW MultiByteToWideChar * 2 LoadLibraryW 7->12 13 7ff600ac6432-7ff600ac647c inet_ntoa call 7ff600ae91f8 * 2 7->13 8->7 14 7ff600ac65be-7ff600ac65d1 GetProcAddress 12->14 15 7ff600ac66dc-7ff600ac6717 GetSystemInfo wsprintfW 12->15 13->12 29 7ff600ac647e 13->29 17 7ff600ac66d3-7ff600ac66d6 FreeLibrary 14->17 18 7ff600ac65d7-7ff600ac6665 call 7ff600ac3670 call 7ff600addff4 call 7ff600ac9300 14->18 19 7ff600ac6720-7ff600ac673f GetDriveTypeW 15->19 17->15 45 7ff600ac6667 18->45 46 7ff600ac666d-7ff600ac66a0 RegOpenKeyExW RegQueryValueExW 18->46 21 7ff600ac6741-7ff600ac6775 GetDiskFreeSpaceExW 19->21 22 7ff600ac6778-7ff600ac677d 19->22 21->22 22->19 25 7ff600ac677f-7ff600ac6822 GlobalMemoryStatusEx call 7ff600ac3670 * 2 call 7ff600ac8f60 GetForegroundWindow 22->25 47 7ff600ac6824-7ff600ac6834 GetWindowTextW 25->47 48 7ff600ac683a-7ff600ac687d lstrlenW call 7ff600ac8e30 25->48 32 7ff600ac6480-7ff600ac64cd inet_ntoa call 7ff600ae91f8 * 2 29->32 32->12 45->46 50 7ff600ac66c0-7ff600ac66ce RegCloseKey call 7ff600addf84 46->50 51 7ff600ac66a2-7ff600ac66a4 46->51 47->48 56 7ff600ac687f-7ff600ac689d GetLocalTime wsprintfW 48->56 57 7ff600ac68a3-7ff600ac68e2 call 7ff600ae8a40 lstrlenW call 7ff600ac8e30 48->57 50->17 51->50 54 7ff600ac66a6-7ff600ac66bb call 7ff600ae94e8 51->54 54->50 56->57 62 7ff600ac68e4-7ff600ac68f3 call 7ff600ae8a40 57->62 63 7ff600ac68f8-7ff600ac692b GetModuleHandleW GetProcAddress 57->63 62->63 65 7ff600ac6931 GetSystemInfo 63->65 66 7ff600ac692d-7ff600ac692f GetNativeSystemInfo 63->66 67 7ff600ac6937-7ff600ac6943 65->67 66->67 68 7ff600ac6951 67->68 69 7ff600ac6945-7ff600ac694f 67->69 70 7ff600ac6956-7ff600ac6996 wsprintfW call 7ff600ac8c30 GetCurrentProcessId 68->70 69->68 69->70 73 7ff600ac6ade-7ff600ac6b0f CoInitializeEx CoCreateInstance 70->73 74 7ff600ac699c-7ff600ac69b7 OpenProcess 70->74 75 7ff600ac6c0f 73->75 76 7ff600ac6b15-7ff600ac6b2a 73->76 77 7ff600ac6ad7 74->77 78 7ff600ac69bd-7ff600ac69d5 K32GetProcessImageFileNameW 74->78 81 7ff600ac6c16-7ff600ac6c6f call 7ff600ae8a40 call 7ff600afda50 RegOpenKeyExW 75->81 82 7ff600ac6b30-7ff600ac6b32 76->82 77->73 79 7ff600ac6ace-7ff600ac6ad1 CloseHandle 78->79 80 7ff600ac69db-7ff600ac69ef GetLogicalDriveStringsW 78->80 79->77 83 7ff600ac6abe-7ff600ac6ac8 lstrcpyW 80->83 84 7ff600ac69f5-7ff600ac69fe 80->84 95 7ff600ac6c75-7ff600ac6ccf RegQueryInfoKeyW 81->95 96 7ff600ac6dd2-7ff600ac6de2 lstrlenW 81->96 82->75 86 7ff600ac6b38-7ff600ac6b65 82->86 83->79 84->83 87 7ff600ac6a04-7ff600ac6a0b 84->87 106 7ff600ac6bfe-7ff600ac6c0d CoUninitialize 86->106 107 7ff600ac6b6b 86->107 90 7ff600ac6a10-7ff600ac6a30 lstrcmpiW 87->90 93 7ff600ac6aae-7ff600ac6ab8 90->93 94 7ff600ac6a32-7ff600ac6a44 lstrcmpiW 90->94 93->83 93->90 94->93 97 7ff600ac6a46-7ff600ac6a7e QueryDosDeviceW 94->97 98 7ff600ac6cd5-7ff600ac6ce7 95->98 99 7ff600ac6e02-7ff600ac6efd call 7ff600ac7a60 call 7ff600ae94e8 GetTickCount call 7ff600ae8e3c call 7ff600ae91b0 wsprintfW GetLocaleInfoW GetSystemDirectoryW GetCurrentHwProfileW 95->99 96->99 100 7ff600ac6de4-7ff600ac6dfd call 7ff600ae94e8 96->100 97->79 102 7ff600ac6a80-7ff600ac6aa8 lstrlenW call 7ff600ae934c 97->102 98->96 103 7ff600ac6ced-7ff600ac6cf0 98->103 137 7ff600ac6eff-7ff600ac6f0b 99->137 138 7ff600ac6f36 99->138 100->99 102->93 115 7ff600ac6f0d-7ff600ac6f31 lstrcpyW lstrcatW 102->115 103->96 109 7ff600ac6cf6-7ff600ac6d0f call 7ff600afda50 103->109 106->75 106->81 111 7ff600ac6b70-7ff600ac6b93 107->111 121 7ff600ac6d15 109->121 122 7ff600ac6dc7-7ff600ac6dcc RegCloseKey 109->122 119 7ff600ac6b95-7ff600ac6bb4 111->119 120 7ff600ac6bcd-7ff600ac6bf8 111->120 115->79 130 7ff600ac6bc2-7ff600ac6bc7 119->130 131 7ff600ac6bb6-7ff600ac6bbc SysFreeString 119->131 120->106 120->111 124 7ff600ac6d20-7ff600ac6d75 call 7ff600afda50 RegEnumKeyExW lstrlenW 121->124 122->96 135 7ff600ac6db9-7ff600ac6dc1 124->135 136 7ff600ac6d77-7ff600ac6d87 lstrlenW 124->136 130->120 131->130 135->122 135->124 136->135 140 7ff600ac6d89-7ff600ac6db4 call 7ff600ae8dc4 * 2 136->140 139 7ff600ac6f3b-7ff600ac6f8d call 7ff600ac72d0 lstrlenW call 7ff600ac8e30 137->139 138->139 148 7ff600ac6f93-7ff600ac7016 GetLocalTime wsprintfW RegOpenKeyExW RegDeleteValueW RegCloseKey RegCreateKeyW 139->148 149 7ff600ac7067-7ff600ac707b CreateToolhelp32Snapshot 139->149 140->135 150 7ff600ac7018-7ff600ac704b lstrlenW RegSetValueExW 148->150 151 7ff600ac705a-7ff600ac7061 RegCloseKey 148->151 152 7ff600ac7081-7ff600ac70b1 call 7ff600afda50 Process32FirstW 149->152 153 7ff600ac7108 149->153 150->151 155 7ff600ac704d-7ff600ac7054 RegCloseKey 150->155 151->149 152->153 162 7ff600ac70b3-7ff600ac70ba 152->162 154 7ff600ac710a-7ff600ac7125 CreateToolhelp32Snapshot 153->154 157 7ff600ac71b8 154->157 158 7ff600ac712b-7ff600ac715b call 7ff600afda50 Process32FirstW 154->158 155->151 160 7ff600ac71ba-7ff600ac71d5 CreateToolhelp32Snapshot 157->160 158->157 169 7ff600ac715d-7ff600ac7168 158->169 164 7ff600ac727f-7ff600ac7299 call 7ff600ac3e30 160->164 165 7ff600ac71db-7ff600ac720b call 7ff600afda50 Process32FirstW 160->165 163 7ff600ac70c0-7ff600ac70cf 162->163 167 7ff600ac70d0-7ff600ac70da 163->167 170 7ff600ac729c-7ff600ac72c0 call 7ff600addf84 164->170 165->164 178 7ff600ac720d-7ff600ac7218 165->178 171 7ff600ac70f4-7ff600ac7106 Process32NextW 167->171 172 7ff600ac70dc-7ff600ac70e4 167->172 174 7ff600ac7170-7ff600ac717e 169->174 171->153 171->163 176 7ff600ac7266-7ff600ac726b 172->176 177 7ff600ac70ea-7ff600ac70f2 172->177 179 7ff600ac7180-7ff600ac718a 174->179 176->154 177->167 177->171 181 7ff600ac7220-7ff600ac722e 178->181 182 7ff600ac71a4-7ff600ac71b6 Process32NextW 179->182 183 7ff600ac718c-7ff600ac7194 179->183 184 7ff600ac7230-7ff600ac723a 181->184 182->157 182->174 185 7ff600ac7270-7ff600ac7275 183->185 186 7ff600ac719a-7ff600ac71a2 183->186 187 7ff600ac7250-7ff600ac7262 Process32NextW 184->187 188 7ff600ac723c-7ff600ac7244 184->188 185->160 186->179 186->182 187->181 191 7ff600ac7264 187->191 189 7ff600ac7246-7ff600ac724e 188->189 190 7ff600ac727a 188->190 189->184 189->187 190->164 191->164
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: Process32lstrlen$CloseCreateInfo$Systemwsprintf$ByteCharFirstHandleMultiNextOpenSnapshotTimeToolhelp32Wide$AddressFreeProcProcessQueryValue$Concurrency::cancel_current_taskCountCurrentDriveFileInstanceLibraryLocalModuleNativeTickWindow_invalid_parameter_noinfoinet_ntoalstrcmpi$DeleteDeviceDirectoryDiskEnumForegroundGlobalImageInitializeInputLastLoadLocaleLogicalMemoryNameProfileSpaceStatusStringStringsTextTypeUninitializegethostbynamegethostnamelstrcpy
            • String ID: %d min$%d.%d$%d.%d.%d$%sFree%d Gb $A:\$AppEvents$B:\$FriendlyName$GetNativeSystemInfo$HDD:%d$INSTALLTIME$Network$ProductName$RtlGetNtVersionNumbers$SOFTWARE\Microsoft\Windows NT\CurrentVersion$Software$Software\Tencent\Plugin\VAS$Telegram.exe$VenGROUP$VenNetwork$VenREMARK$WeChat.exe$WxWork.exe$X64 %s$c23cba79-a592-4af7-a500-4fcf6bee8efd$kernel32.dll$ntdll.dll$x64$x86
            • API String ID: 4136965836-2820081605
            • Opcode ID: ea268c65bd0354d68f3c4d4cf1f9f1f92df9778dd25e6bbadd2adbf6ee75f2b0
            • Instruction ID: 0d7a3f3a673a9fa3833a8128ab059668a60a891ccca533a4f6edcf46eb4a7819
            • Opcode Fuzzy Hash: ea268c65bd0354d68f3c4d4cf1f9f1f92df9778dd25e6bbadd2adbf6ee75f2b0
            • Instruction Fuzzy Hash: 6B926133A08A82A6EB20DF65D8446F93364FF84754FA54632DA4E877A9EF3CD645C700

            Control-flow Graph

            • Executed
            • Not Executed
            control_flow_graph 193 7ff600adb5e0-7ff600adb621 call 7ff600ae9ebc SleepEx 196 7ff600adb653-7ff600adb65a 193->196 197 7ff600adb623-7ff600adb64d call 7ff600addfb8 call 7ff600ae8be0 CloseHandle 193->197 199 7ff600adb72f-7ff600adb858 GetLocalTime wsprintfW SetUnhandledExceptionFilter call 7ff600ae8be0 CloseHandle call 7ff600addfb8 call 7ff600ac36e0 call 7ff600addfb8 call 7ff600acb410 call 7ff600adae60 AllocateAndInitializeSid 196->199 200 7ff600adb660-7ff600adb67d GetCurrentProcess OpenProcessToken 196->200 197->196 219 7ff600adb85a-7ff600adb872 CheckTokenMembership 199->219 220 7ff600adb888-7ff600adb88f 199->220 202 7ff600adb6d4-7ff600adb6f7 GetModuleHandleA GetProcAddress 200->202 203 7ff600adb67f-7ff600adb6ce LookupPrivilegeValueW AdjustTokenPrivileges CloseHandle 200->203 202->199 206 7ff600adb6f9-7ff600adb72a GetCurrentProcessId OpenProcess 202->206 203->202 206->199 221 7ff600adb874 219->221 222 7ff600adb87b-7ff600adb882 FreeSid 219->222 223 7ff600adb891-7ff600adb906 RegOpenKeyExW RegDeleteValueW RegSetValueExW RegCloseKey 220->223 224 7ff600adb90c 220->224 221->222 222->220 223->224 225 7ff600adb913-7ff600adb926 224->225 226 7ff600adb954-7ff600adb978 call 7ff600ae8a40 * 2 225->226 227 7ff600adb928-7ff600adb952 call 7ff600ae8a40 * 2 225->227 236 7ff600adb97e-7ff600adb9a7 226->236 227->236 237 7ff600adb9ec-7ff600adb9f6 236->237 238 7ff600adb9a9-7ff600adb9e5 call 7ff600ae8a40 * 2 236->238 239 7ff600adba06-7ff600adba5b call 7ff600ae9ebc SleepEx call 7ff600ae9ebc call 7ff600ac3820 237->239 240 7ff600adb9f8-7ff600adba00 237->240 238->237 239->225 251 7ff600adba61-7ff600adbb25 call 7ff600ae9ebc CreateEventA call 7ff600ae8a40 call 7ff600ac6370 239->251 240->239 258 7ff600adbb2a-7ff600adbb2d 251->258 259 7ff600adbb2f-7ff600adbb3b 258->259 260 7ff600adbb3d 258->260 265 7ff600adbb8b-7ff600adbba1 259->265 261 7ff600adbb40-7ff600adbb47 260->261 263 7ff600adbb72-7ff600adbb79 261->263 264 7ff600adbb49-7ff600adbb59 Sleep 261->264 267 7ff600adbb7f-7ff600adbb8a Sleep 263->267 264->261 266 7ff600adbb5b-7ff600adbb62 264->266 268 7ff600adbba3-7ff600adbbbb 265->268 269 7ff600adbbe9-7ff600adbbf8 CloseHandle 265->269 266->263 270 7ff600adbb64-7ff600adbb70 266->270 267->265 271 7ff600adbbd2-7ff600adbbe2 call 7ff600addf84 268->271 272 7ff600adbbbd-7ff600adbbd0 268->272 269->225 270->267 271->269 272->271 273 7ff600adbbfd-7ff600adbc24 call 7ff600ae3ff8 IsDebuggerPresent 272->273 279 7ff600adbc31-7ff600adbc54 LoadLibraryW 273->279 280 7ff600adbc26-7ff600adbc30 273->280 281 7ff600adbc60-7ff600adbc7e GetProcAddress 279->281 282 7ff600adbc56-7ff600adbc5b 279->282 283 7ff600adbc93-7ff600adbd45 call 7ff600afda50 GetLocalTime wsprintfW CreateFileW 281->283 284 7ff600adbc80-7ff600adbc8e FreeLibrary 281->284 285 7ff600adbdce-7ff600adbde8 282->285 289 7ff600adbd55-7ff600adbdb0 GetCurrentThreadId GetCurrentProcessId GetCurrentProcess CloseHandle FreeLibrary 283->289 290 7ff600adbd47-7ff600adbd53 FreeLibrary 283->290 286 7ff600adbdc6 284->286 286->285 291 7ff600adbdb6-7ff600adbdbe 289->291 290->291 291->286
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: CloseHandle$ProcessSleep$OpenTokenValue$AddressCurrentFreeLibraryProc$AdjustAllocateCheckCreateDebuggerDeleteEventExceptionFilterInitializeLoadLocalLookupMembershipModulePresentPrivilegePrivilegesTimeUnhandled_invalid_parameter_noinfo_invalid_parameter_noinfo_noreturnwsprintf
            • String ID: !analyze -v$%4d.%2d.%2d-%2d:%2d:%2d$%s-%04d%02d%02d-%02d%02d%02d.dmp$10443$10443$23.226.57.67$23.226.57.67$23.226.57.67$23.226.57.67$4433$DbgHelp.dll$MiniDumpWriteDump$NtDll.dll$NtSetInformationProcess$SOFTWARE$SeDebugPrivilege$VenkernalData_info$loginconfig
            • API String ID: 2641691789-2867827147
            • Opcode ID: f576be90ff469620f617f425041ccbfd0283bf6011902f711b93bc7817aa8828
            • Instruction ID: 093abc1a326b135687ea38f5cec9d35020b04de1cd60acf439d045f4c389f262
            • Opcode Fuzzy Hash: f576be90ff469620f617f425041ccbfd0283bf6011902f711b93bc7817aa8828
            • Instruction Fuzzy Hash: 27226032A18B82EAE7209F61E8442B973A5FF89754F600136D95E87BADDF3DE544C700

            Control-flow Graph

            • Executed
            • Not Executed
            control_flow_graph 294 7ff600acf410-7ff600acf49f call 7ff600addfb8 call 7ff600afda50 GetLastInputInfo GetTickCount wsprintfW GetForegroundWindow 299 7ff600acf4b4-7ff600acf4d6 CreateToolhelp32Snapshot 294->299 300 7ff600acf4a1-7ff600acf4ae GetWindowTextW 294->300 301 7ff600acf555 299->301 302 7ff600acf4d8-7ff600acf4ff call 7ff600afda50 Process32FirstW 299->302 300->299 303 7ff600acf557-7ff600acf571 CreateToolhelp32Snapshot 301->303 302->301 308 7ff600acf501-7ff600acf508 302->308 305 7ff600acf577-7ff600acf5a7 call 7ff600afda50 Process32FirstW 303->305 306 7ff600acf5f8 303->306 305->306 317 7ff600acf5a9 305->317 309 7ff600acf5fa-7ff600acf614 CreateToolhelp32Snapshot 306->309 311 7ff600acf510-7ff600acf517 308->311 312 7ff600acf61a-7ff600acf64a call 7ff600afda50 Process32FirstW 309->312 313 7ff600acf6a8 309->313 315 7ff600acf520-7ff600acf52a 311->315 312->313 327 7ff600acf64c-7ff600acf657 312->327 318 7ff600acf6aa-7ff600acf6f4 RegOpenKeyExW 313->318 319 7ff600acf544-7ff600acf553 Process32NextW 315->319 320 7ff600acf52c-7ff600acf534 315->320 322 7ff600acf5b0-7ff600acf5ba 317->322 323 7ff600acf913-7ff600acf94b RegOpenKeyExW 318->323 324 7ff600acf6fa-7ff600acf72e RegQueryValueExW 318->324 319->301 319->311 325 7ff600acf7f2-7ff600acf7f4 320->325 326 7ff600acf53a-7ff600acf542 320->326 330 7ff600acf5c0-7ff600acf5ca 322->330 328 7ff600acf9f2-7ff600acfa2a RegOpenKeyExW 323->328 329 7ff600acf951-7ff600acf984 RegQueryValueExW 323->329 331 7ff600acf734-7ff600acf78b call 7ff600addff4 call 7ff600afda50 RegQueryValueExW 324->331 332 7ff600acf908-7ff600acf90d RegCloseKey 324->332 325->303 326->315 326->319 336 7ff600acf660-7ff600acf66a 327->336 334 7ff600acfa30-7ff600acfa63 RegQueryValueExW 328->334 335 7ff600acfad1-7ff600acfb87 SHGetFolderPathW lstrcatW CreateFileW lstrlenW WriteFile CloseHandle FindFirstFileW 328->335 337 7ff600acf986-7ff600acf9dd call 7ff600addff4 call 7ff600afda50 RegQueryValueExW 329->337 338 7ff600acf9e7-7ff600acf9ec RegCloseKey 329->338 339 7ff600acf5e4-7ff600acf5f6 Process32NextW 330->339 340 7ff600acf5cc-7ff600acf5d4 330->340 331->332 364 7ff600acf791-7ff600acf7b9 call 7ff600ad1310 331->364 332->323 342 7ff600acfa65-7ff600acfabc call 7ff600addff4 call 7ff600afda50 RegQueryValueExW 334->342 343 7ff600acfac6-7ff600acfacb RegCloseKey 334->343 345 7ff600acfb91-7ff600acfbdc FindClose call 7ff600acfd10 335->345 346 7ff600acfb89 335->346 344 7ff600acf670-7ff600acf67a 336->344 337->338 367 7ff600acf9df 337->367 338->328 339->306 339->322 348 7ff600acf5da-7ff600acf5e2 340->348 349 7ff600acf7f9-7ff600acf7fb 340->349 342->343 374 7ff600acfabe 342->374 343->335 352 7ff600acf694-7ff600acf6a6 Process32NextW 344->352 353 7ff600acf67c-7ff600acf684 344->353 362 7ff600acfbde-7ff600acfbe2 345->362 363 7ff600acfbf8-7ff600acfc20 call 7ff600addff4 345->363 346->345 348->330 348->339 349->309 352->313 352->336 358 7ff600acf800-7ff600acf802 353->358 359 7ff600acf68a-7ff600acf692 353->359 358->318 359->344 359->352 362->363 368 7ff600acfbe4-7ff600acfbf1 362->368 375 7ff600acfc23-7ff600acfc7c 363->375 376 7ff600acf845-7ff600acf855 364->376 377 7ff600acf7bf-7ff600acf7ca 364->377 367->338 368->363 374->343 375->375 380 7ff600acfc7e-7ff600acfcac call 7ff600afd3b0 375->380 378 7ff600acf8cd-7ff600acf8d1 376->378 379 7ff600acf857-7ff600acf85e 376->379 381 7ff600acf7d0-7ff600acf7d9 377->381 378->332 382 7ff600acf8d3-7ff600acf8e5 378->382 383 7ff600acf862-7ff600acf86b 379->383 394 7ff600acfcbe-7ff600acfcc1 380->394 395 7ff600acfcae-7ff600acfcbb call 7ff600ac3e30 380->395 381->376 385 7ff600acf7db 381->385 386 7ff600acf900-7ff600acf903 call 7ff600addf84 382->386 387 7ff600acf8e7-7ff600acf8fa 382->387 383->378 388 7ff600acf86d 383->388 390 7ff600acf7e0-7ff600acf7e4 385->390 386->332 387->386 391 7ff600acfcfe-7ff600acfd03 call 7ff600ae3ff8 387->391 393 7ff600acf870-7ff600acf874 388->393 396 7ff600acf7e6-7ff600acf7ee 390->396 397 7ff600acf807-7ff600acf80a 390->397 400 7ff600acf88b-7ff600acf88e 393->400 401 7ff600acf876-7ff600acf87e 393->401 403 7ff600acfcc3-7ff600acfcc6 call 7ff600addf84 394->403 404 7ff600acfccb-7ff600acfcf4 call 7ff600addf84 394->404 395->394 396->390 402 7ff600acf7f0 396->402 397->376 398 7ff600acf80c-7ff600acf81c 397->398 406 7ff600acf820-7ff600acf826 398->406 400->378 409 7ff600acf890-7ff600acf89d 400->409 401->393 408 7ff600acf880 401->408 402->376 403->404 412 7ff600acf882-7ff600acf886 406->412 413 7ff600acf828-7ff600acf834 406->413 408->378 414 7ff600acf8a0-7ff600acf8a6 409->414 412->381 413->406 417 7ff600acf836-7ff600acf83f 413->417 415 7ff600acfcf5-7ff600acfcf9 414->415 416 7ff600acf8ac-7ff600acf8b8 414->416 415->383 416->414 418 7ff600acf8ba-7ff600acf8c3 416->418 417->376 419 7ff600acf8c5 417->419 418->378 418->419 419->378
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: Process32QueryValue$Close$CreateFirst$FileNextOpenSnapshotToolhelp32$Concurrency::cancel_current_taskFindWindow$CountFolderForegroundHandleInfoInputLastPathTextTickWrite_invalid_parameter_noinfo_noreturnlstrcatlstrlenwsprintf
            • String ID: %d min$C:\ProgramData\Mylnk$C:\Users$OpenAi_Service$SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders$SOFTWARE\Microsoft\Windows\CurrentVersion\Run$Startup$Telegram.exe$WXWork.exe$WeChat.exe$\kernelquick.sys
            • API String ID: 3029130142-1423135667
            • Opcode ID: 67a6eca3fa8730ed3e89a175e2743e3b53aeda9d2a050e997ae5ff35e344876b
            • Instruction ID: 37538a5752677b8eec4689e028235b74b42bff525f4703e7a46e5b5153263171
            • Opcode Fuzzy Hash: 67a6eca3fa8730ed3e89a175e2743e3b53aeda9d2a050e997ae5ff35e344876b
            • Instruction Fuzzy Hash: 5632C233B08686A9EB208F64D404AFD77A5FB85B84F654532DA5E8779AEF3CE144C700
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: lstrlen$QueryValue$Open
            • String ID: 10443$23.226.57.67$23.226.57.67$23.226.57.67$4433$Console$Vendata$o1:$o2:$o3:$p1:$p2:$p3:$t1:$t2:$t3:
            • API String ID: 1772312705-1238094545
            • Opcode ID: e9763d1a573506a6c5f52fab13ecf1f8c208e4fec7a72f7b0df219955d443a2f
            • Instruction ID: ca06c5369a25dc142ec74a104a0736a158d69542940a2c7cda231c152d54851d
            • Opcode Fuzzy Hash: e9763d1a573506a6c5f52fab13ecf1f8c208e4fec7a72f7b0df219955d443a2f
            • Instruction Fuzzy Hash: 4B22D363E2952BE1EA249B14E5546BD73A1FF94745FA64032C90FC2B9BEF3CB1458310

            Control-flow Graph

            • Executed
            • Not Executed
            control_flow_graph 572 7ff600ac72d0-7ff600ac7326 573 7ff600ac7330-7ff600ac7339 572->573 573->573 574 7ff600ac733b-7ff600ac7344 573->574 575 7ff600ac7362-7ff600ac7367 call 7ff600aca300 574->575 576 7ff600ac7346-7ff600ac7360 call 7ff600afd3b0 574->576 580 7ff600ac736c 575->580 576->580 581 7ff600ac7373-7ff600ac737b 580->581 581->581 582 7ff600ac737d-7ff600ac7390 581->582 583 7ff600ac73c5-7ff600ac73d5 call 7ff600aca300 582->583 584 7ff600ac7392-7ff600ac73c3 call 7ff600afd3b0 582->584 588 7ff600ac73da 583->588 584->588 589 7ff600ac73e1-7ff600ac73ea 588->589 589->589 590 7ff600ac73ec-7ff600ac73ff 589->590 591 7ff600ac7401-7ff600ac7432 call 7ff600afd3b0 590->591 592 7ff600ac7434-7ff600ac7444 call 7ff600aca300 590->592 596 7ff600ac7449-7ff600ac744d 591->596 592->596 597 7ff600ac7454-7ff600ac745d 596->597 597->597 598 7ff600ac745f-7ff600ac7472 597->598 599 7ff600ac7474-7ff600ac74a5 call 7ff600afd3b0 598->599 600 7ff600ac74a7-7ff600ac74b4 call 7ff600aca300 598->600 604 7ff600ac74b9-7ff600ac74cd 599->604 600->604 605 7ff600ac74cf-7ff600ac7503 call 7ff600afd3b0 604->605 606 7ff600ac7505-7ff600ac751f call 7ff600aca300 604->606 610 7ff600ac7524-7ff600ac752f 605->610 606->610 611 7ff600ac7530-7ff600ac7539 610->611 611->611 612 7ff600ac753b-7ff600ac754e 611->612 613 7ff600ac7550-7ff600ac7581 call 7ff600afd3b0 612->613 614 7ff600ac7583-7ff600ac7590 call 7ff600aca300 612->614 617 7ff600ac7595-7ff600ac7599 613->617 614->617 619 7ff600ac75a0-7ff600ac75a9 617->619 619->619 620 7ff600ac75ab-7ff600ac75be 619->620 621 7ff600ac75c0-7ff600ac75f1 call 7ff600afd3b0 620->621 622 7ff600ac75f3-7ff600ac7600 call 7ff600aca300 620->622 626 7ff600ac7605-7ff600ac76b4 call 7ff600ad9250 call 7ff600ad9be0 MultiByteToWideChar * 2 621->626 622->626 631 7ff600ac76e3-7ff600ac76fd 626->631 632 7ff600ac76b6-7ff600ac76c7 626->632 633 7ff600ac76ff-7ff600ac7716 631->633 634 7ff600ac7732-7ff600ac7752 631->634 635 7ff600ac76de call 7ff600addf84 632->635 636 7ff600ac76c9-7ff600ac76dc 632->636 639 7ff600ac7718-7ff600ac772b 633->639 640 7ff600ac772d call 7ff600addf84 633->640 635->631 636->635 637 7ff600ac7759-7ff600ac7797 call 7ff600ae3ff8 CreateMutexExW GetLastError 636->637 647 7ff600ac77c9-7ff600ac77d0 637->647 648 7ff600ac7799 637->648 639->640 641 7ff600ac7753-7ff600ac7758 call 7ff600ae3ff8 639->641 640->634 641->637 649 7ff600ac7870-7ff600ac7922 GetModuleHandleW GetConsoleWindow SHGetFolderPathW lstrcatW CreateMutexW WaitForSingleObject CreateFileW GetFileSize CloseHandle 647->649 650 7ff600ac77d6 647->650 651 7ff600ac77a0-7ff600ac77c7 Sleep CreateMutexW GetLastError 648->651 653 7ff600ac7924-7ff600ac7927 DeleteFileW 649->653 654 7ff600ac792d-7ff600ac795d ReleaseMutex DirectInput8Create 649->654 652 7ff600ac77e0-7ff600ac7840 lstrlenW call 7ff600ac8e30 650->652 651->647 651->651 659 7ff600ac7842-7ff600ac7856 lstrcmpW 652->659 660 7ff600ac7858-7ff600ac786a SleepEx 652->660 653->654 656 7ff600ac7a00-7ff600ac7a1e 654->656 657 7ff600ac7963-7ff600ac7983 654->657 657->656 662 7ff600ac7985-7ff600ac799b 657->662 659->649 659->660 660->649 660->652 662->656 664 7ff600ac799d-7ff600ac79b5 662->664 664->656 666 7ff600ac79b7-7ff600ac79ed 664->666 666->656 668 7ff600ac79ef-7ff600ac79fe 666->668 668->656 670 7ff600ac7a1f-7ff600ac7a51 GetTickCount GetKeyState call 7ff600acadb0 668->670
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: ByteCharMultiWide$Concurrency::cancel_current_task_invalid_parameter_noinfo_noreturn
            • String ID: <$X64$\DisplaySessionContainers.log$key$open
            • API String ID: 143101810-941791203
            • Opcode ID: f29b99b45b118f5f79a42678ca975ff307e5e61cf3b77914cf71b692731fc63f
            • Instruction ID: 1fd36d3be218a17a3168e3611233ce443e3a217457da5dee78e2b428d16434a7
            • Opcode Fuzzy Hash: f29b99b45b118f5f79a42678ca975ff307e5e61cf3b77914cf71b692731fc63f
            • Instruction Fuzzy Hash: D422A133B18A86A6EB10CB65E4006AE7365FB84B94F604632EE5E87B9DDF3CD544C740

            Control-flow Graph

            APIs
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: MetricsObjectSystem$Delete$CreateCriticalGlobalSection$EnterRelease$BitmapCapsCompatibleConcurrency::cancel_current_taskDeviceGdipStreamStretch$AllocBitsDesktopDisposeFromGdiplusImageLeaveLockModeSelectShutdownUnlockWindow_invalid_parameter_noinfo_noreturn
            • String ID: $($6$gfff$gfff
            • API String ID: 1610826097-2922166585
            • Opcode ID: 396a75d9fa9336e9a4e12c0fdd0907e1ba5330701357c04f5d803b12fdb2bbf9
            • Instruction ID: 90dba681dcf4fea173a80862f47bbba1eb5f4d7b2517ea486e4ec3aa5de6f41f
            • Opcode Fuzzy Hash: 396a75d9fa9336e9a4e12c0fdd0907e1ba5330701357c04f5d803b12fdb2bbf9
            • Instruction Fuzzy Hash: 0CD1E473A1878186E7159F35E40437AB6A5FF89B84F208236EA4E9775AEF3CD484C740

            Control-flow Graph

            • Executed
            • Not Executed
            control_flow_graph 729 7ff600ac8a40-7ff600ac8a6f GetCurrentProcessId OpenProcess 730 7ff600ac8a71-7ff600ac8a8e OpenProcessToken 729->730 731 7ff600ac8a99-7ff600ac8aae 729->731 732 7ff600ac8aaf-7ff600ac8ad7 call 7ff600ac8710 730->732 733 7ff600ac8a90-7ff600ac8a93 CloseHandle 730->733 736 7ff600ac8b0a 732->736 737 7ff600ac8ad9-7ff600ac8adf 732->737 733->731 740 7ff600ac8b0f-7ff600ac8b12 736->740 738 7ff600ac8ae1-7ff600ac8ae7 SysStringLen 737->738 739 7ff600ac8ae9 737->739 741 7ff600ac8aec-7ff600ac8aef 738->741 739->741 742 7ff600ac8b14-7ff600ac8b29 call 7ff600addfb8 740->742 743 7ff600ac8b4c-7ff600ac8b86 call 7ff600afd3b0 CloseHandle * 2 740->743 741->736 745 7ff600ac8af1-7ff600ac8af7 741->745 751 7ff600ac8b3b 742->751 752 7ff600ac8b2b-7ff600ac8b39 742->752 753 7ff600ac8bce-7ff600ac8bd6 743->753 754 7ff600ac8b88-7ff600ac8b92 743->754 749 7ff600ac8b03-7ff600ac8b08 745->749 750 7ff600ac8af9-7ff600ac8b01 SysStringLen 745->750 749->740 750->740 755 7ff600ac8b3e-7ff600ac8b46 751->755 752->755 756 7ff600ac8c0d-7ff600ac8c1f 753->756 757 7ff600ac8bd8-7ff600ac8be3 753->757 758 7ff600ac8b94-7ff600ac8b9f 754->758 759 7ff600ac8bc9 754->759 755->743 762 7ff600ac8c20-7ff600ac8c99 call 7ff600adeca0 call 7ff600addff4 GetCurrentProcessId wsprintfW call 7ff600ac8a40 call 7ff600afda50 GetVersionExW 755->762 760 7ff600ac8be5-7ff600ac8beb SysFreeString 757->760 761 7ff600ac8bee-7ff600ac8bf5 757->761 763 7ff600ac8ba1-7ff600ac8ba7 SysFreeString 758->763 764 7ff600ac8baa-7ff600ac8bb1 758->764 759->753 760->761 765 7ff600ac8c00-7ff600ac8c08 call 7ff600addf84 761->765 766 7ff600ac8bf7-7ff600ac8bfc call 7ff600addf84 761->766 784 7ff600ac8df2 762->784 785 7ff600ac8c9f-7ff600ac8ca4 762->785 763->764 767 7ff600ac8bb3-7ff600ac8bb8 call 7ff600addf84 764->767 768 7ff600ac8bbc-7ff600ac8bc4 call 7ff600addf84 764->768 765->756 766->765 767->768 768->759 787 7ff600ac8df9-7ff600ac8e03 wsprintfW 784->787 785->784 786 7ff600ac8caa-7ff600ac8caf 785->786 786->784 788 7ff600ac8cb5-7ff600ac8cdb GetCurrentProcess OpenProcessToken 786->788 789 7ff600ac8e09-7ff600ac8e20 call 7ff600addf84 787->789 788->784 790 7ff600ac8ce1-7ff600ac8d10 GetTokenInformation 788->790 792 7ff600ac8d9c-7ff600ac8dac CloseHandle 790->792 793 7ff600ac8d16-7ff600ac8d1f GetLastError 790->793 792->784 795 7ff600ac8dae-7ff600ac8db4 792->795 793->792 796 7ff600ac8d21-7ff600ac8d41 LocalAlloc 793->796 797 7ff600ac8db6-7ff600ac8dbc 795->797 798 7ff600ac8de9-7ff600ac8df0 795->798 799 7ff600ac8d43-7ff600ac8d70 GetTokenInformation 796->799 800 7ff600ac8d94 796->800 801 7ff600ac8dbe-7ff600ac8dc4 797->801 802 7ff600ac8de0-7ff600ac8de7 797->802 798->787 803 7ff600ac8d72-7ff600ac8d89 GetSidSubAuthorityCount GetSidSubAuthority 799->803 804 7ff600ac8d8b-7ff600ac8d8e LocalFree 799->804 800->792 805 7ff600ac8dc6-7ff600ac8dcc 801->805 806 7ff600ac8dd7-7ff600ac8dde 801->806 802->787 803->804 804->800 805->789 807 7ff600ac8dce-7ff600ac8dd5 805->807 806->787 807->787
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: Process$CloseHandleStringToken$CurrentFreeOpen$AuthorityInformationLocalwsprintf$AllocCountErrorLastVersion
            • String ID: -N/$NO/$None/%s$VenNetwork
            • API String ID: 166307840-819860926
            • Opcode ID: 6c7887b962d608019f703872167c8e7ce94f955a74d8e987f4e99f87a0c40281
            • Instruction ID: 10d0499f6671913561b0e767359b5d79588e40743d07ff87034eb89e45267500
            • Opcode Fuzzy Hash: 6c7887b962d608019f703872167c8e7ce94f955a74d8e987f4e99f87a0c40281
            • Instruction Fuzzy Hash: 06B18F33A0DA42A6FB619B61E4506B963A4FF84B80F254835DE4E8779EDF3CE845C700

            Control-flow Graph

            • Executed
            • Not Executed
            control_flow_graph 1115 7ff600ac7a60-7ff600ac7aac call 7ff600afda50 call 7ff600adff40 1120 7ff600ac7ab2-7ff600ac7ac6 1115->1120 1121 7ff600ac7b7c-7ff600ac7ba7 CoCreateInstance 1115->1121 1122 7ff600ac7ad0-7ff600ac7af8 call 7ff600afda50 CreateToolhelp32Snapshot 1120->1122 1123 7ff600ac7da1-7ff600ac7dac lstrlenW 1121->1123 1124 7ff600ac7bad-7ff600ac7bf9 1121->1124 1134 7ff600ac7b56-7ff600ac7b76 call 7ff600adff40 1122->1134 1135 7ff600ac7afa-7ff600ac7b10 Process32FirstW 1122->1135 1126 7ff600ac7dbf-7ff600ac7dc6 1123->1126 1127 7ff600ac7dae-7ff600ac7dbe lstrcatW 1123->1127 1132 7ff600ac7d8f-7ff600ac7d99 1124->1132 1133 7ff600ac7bff-7ff600ac7c1b 1124->1133 1130 7ff600ac7dce-7ff600ac7de4 1126->1130 1131 7ff600ac7dc8 1126->1131 1127->1126 1131->1130 1132->1123 1136 7ff600ac7d9b 1132->1136 1133->1132 1143 7ff600ac7c21-7ff600ac7cdd call 7ff600afda50 wsprintfW RegOpenKeyExW 1133->1143 1134->1121 1134->1122 1137 7ff600ac7b12-7ff600ac7b1c 1135->1137 1138 7ff600ac7b4d-7ff600ac7b50 CloseHandle 1135->1138 1136->1123 1141 7ff600ac7b20-7ff600ac7b2a 1137->1141 1138->1134 1144 7ff600ac7b34-7ff600ac7b39 1141->1144 1145 7ff600ac7b2c-7ff600ac7b32 1141->1145 1151 7ff600ac7ce3-7ff600ac7d3e call 7ff600afda50 RegQueryValueExW 1143->1151 1152 7ff600ac7d6d-7ff600ac7d7f 1143->1152 1147 7ff600ac7b3f-7ff600ac7b4b Process32NextW 1144->1147 1148 7ff600ac7de5-7ff600ac7def CloseHandle 1144->1148 1145->1141 1145->1144 1147->1137 1147->1138 1148->1134 1150 7ff600ac7df5-7ff600ac7e13 lstrcatW * 2 1148->1150 1150->1134 1156 7ff600ac7d60-7ff600ac7d67 RegCloseKey 1151->1156 1157 7ff600ac7d40-7ff600ac7d5a lstrcatW * 2 1151->1157 1155 7ff600ac7d87-7ff600ac7d89 1152->1155 1155->1132 1155->1143 1156->1152 1157->1156
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: lstrcat$Close$CreateHandleProcess32$FirstInstanceNextOpenQuerySnapshotToolhelp32Valuelstrlenwsprintf
            • String ID: CLSID\{%.8X-%.4X-%.4X-%.2X%.2X-%.2X%.2X%.2X%.2X%.2X%.2X}$Windows Defender IOfficeAntiVirus implementation
            • API String ID: 582347850-1583895642
            • Opcode ID: 172064aca06d7bab2ac812725ebad370c198c4fa5686a0e3f00f667ec9231332
            • Instruction ID: c753ffea2071d7fbde9c86799a50149e1c74534664936f8d761cdc8669b8e525
            • Opcode Fuzzy Hash: 172064aca06d7bab2ac812725ebad370c198c4fa5686a0e3f00f667ec9231332
            • Instruction Fuzzy Hash: CAA18233A08A829AE7608F65E8406BE77A5FB85B88F644131DE4E87B5DDF3DD544CB00

            Control-flow Graph

            • Executed
            • Not Executed
            control_flow_graph 1174 7ff600accd40-7ff600accd72 1175 7ff600acd233-7ff600acd248 call 7ff600ada680 1174->1175 1176 7ff600accd78-7ff600accd8e 1174->1176 1185 7ff600acd3e5-7ff600acd403 1175->1185 1186 7ff600acd24e-7ff600acd25c call 7ff600adabd0 1175->1186 1178 7ff600accd94-7ff600accda9 1176->1178 1179 7ff600acce2a-7ff600acce41 1176->1179 1183 7ff600accdb0-7ff600accdb7 1178->1183 1181 7ff600acce93 1179->1181 1182 7ff600acce43-7ff600acce4d 1179->1182 1184 7ff600acce96-7ff600accf76 call 7ff600afda50 * 2 GetSystemDirectoryA call 7ff600ac9f70 CreateProcessA 1181->1184 1187 7ff600acce50-7ff600acce5a 1182->1187 1188 7ff600accdc0-7ff600accdc8 1183->1188 1231 7ff600acd1ae-7ff600acd1ff call 7ff600addfb8 call 7ff600afda50 call 7ff600ac3670 1184->1231 1232 7ff600accf7c-7ff600accfa3 VirtualAllocEx 1184->1232 1205 7ff600acd262-7ff600acd2e4 call 7ff600ae8a40 * 2 call 7ff600addfb8 call 7ff600afda50 call 7ff600ac3670 1186->1205 1206 7ff600acd386-7ff600acd3bf call 7ff600addfb8 call 7ff600afda50 call 7ff600ae8a40 1186->1206 1191 7ff600acce60-7ff600acce6d 1187->1191 1192 7ff600acce0e-7ff600acce12 1188->1192 1193 7ff600accdca-7ff600accdd1 1188->1193 1198 7ff600acce6f-7ff600acce79 1191->1198 1199 7ff600acce7b-7ff600acce7f 1191->1199 1195 7ff600acd088-7ff600acd08c 1192->1195 1196 7ff600acce18-7ff600acce24 1192->1196 1200 7ff600accdd3-7ff600accdda 1193->1200 1201 7ff600acce0b 1193->1201 1203 7ff600acd092-7ff600acd0cf call 7ff600addfb8 call 7ff600afda50 call 7ff600ae8a40 1195->1203 1204 7ff600acce26 1195->1204 1196->1183 1196->1204 1198->1191 1198->1199 1207 7ff600acd0d4-7ff600acd0db 1199->1207 1208 7ff600acce85-7ff600acce8d 1199->1208 1209 7ff600acce05-7ff600acce09 1200->1209 1210 7ff600accddc-7ff600accde4 1200->1210 1201->1192 1252 7ff600acd3c3 1203->1252 1204->1179 1268 7ff600acd2e6-7ff600acd2f6 call 7ff600ac3e30 1205->1268 1269 7ff600acd2f9-7ff600acd323 call 7ff600addf84 call 7ff600adad40 1205->1269 1206->1252 1207->1184 1217 7ff600acd0e1-7ff600acd13c call 7ff600addfb8 call 7ff600afda50 call 7ff600ae94e8 1207->1217 1208->1187 1218 7ff600acce8f 1208->1218 1209->1192 1211 7ff600accdff-7ff600acce03 1210->1211 1212 7ff600accde6-7ff600accdfb 1210->1212 1211->1192 1212->1188 1220 7ff600accdfd 1212->1220 1254 7ff600acd140-7ff600acd191 1217->1254 1218->1181 1220->1192 1270 7ff600acd214-7ff600acd22e call 7ff600addf84 1231->1270 1271 7ff600acd201-7ff600acd20e 1231->1271 1232->1231 1238 7ff600accfa9-7ff600accfc4 WriteProcessMemory 1232->1238 1238->1231 1245 7ff600accfca-7ff600accfe8 GetThreadContext 1238->1245 1245->1231 1251 7ff600accfee-7ff600acd009 SetThreadContext 1245->1251 1251->1231 1256 7ff600acd00f-7ff600acd06b ResumeThread call 7ff600addfb8 call 7ff600afda50 call 7ff600ac3670 1251->1256 1257 7ff600acd3c5-7ff600acd3d2 1252->1257 1258 7ff600acd3d8 1252->1258 1254->1254 1261 7ff600acd193-7ff600acd1a9 1254->1261 1280 7ff600acd080-7ff600acd083 1256->1280 1281 7ff600acd06d-7ff600acd07d call 7ff600ac3e30 1256->1281 1257->1258 1259 7ff600acd3db-7ff600acd3e0 call 7ff600addf84 1258->1259 1259->1185 1261->1184 1268->1269 1284 7ff600acd328-7ff600acd379 call 7ff600addfb8 call 7ff600afda50 call 7ff600ac3670 1269->1284 1270->1185 1271->1270 1280->1259 1281->1280 1284->1206
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: Thread$ContextProcess$AllocCreateDirectoryMemoryResumeSystemVirtualWrite
            • String ID: %s %s$%s%s$@$Windows\System32\svchost.exe$c23cba79-a592-4af7-a500-4fcf6bee8efd$h$nlyloadinmyself$plugmark
            • API String ID: 4033188109-1433058259
            • Opcode ID: e40124f47e0616d75d64940926f98e35d274e86a272478ae1ea058fe275ad7e0
            • Instruction ID: 8c32ff02187ab2b143c68daa3ef732dbfbcdfedbd52d33c163547095992962d3
            • Opcode Fuzzy Hash: e40124f47e0616d75d64940926f98e35d274e86a272478ae1ea058fe275ad7e0
            • Instruction Fuzzy Hash: EE12A063B08A8292E720CF25D4446BD77A1FB99B84F558536DB4E87B9ADF3CD185C300

            Control-flow Graph

            APIs
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: ProcessToken$AdjustCloseCurrentErrorHandleLastLookupOpenPrivilegePrivilegesValue$ExitWindows
            • String ID: SeShutdownPrivilege
            • API String ID: 1423298842-3733053543
            • Opcode ID: 40da0a47c9c7c1cc3a1aa31b778f4d13c03be2ed2b90204a7f89449c4a5765b5
            • Instruction ID: c474e7c0c2ddd0440d17d4da610c4bdbe800c6d7abbb943aef46bff36be2d9fb
            • Opcode Fuzzy Hash: 40da0a47c9c7c1cc3a1aa31b778f4d13c03be2ed2b90204a7f89449c4a5765b5
            • Instruction Fuzzy Hash: FE315E36908E82A9E720CF64E8147BA6364FF84B56F204435DA4E937ADDF3DD189C704

            Control-flow Graph

            • Executed
            • Not Executed
            control_flow_graph 1334 7ff600ada680-7ff600ada6a1 1335 7ff600ada6a3-7ff600ada6ab 1334->1335 1336 7ff600ada6c0-7ff600ada6cd SetLastError 1334->1336 1337 7ff600ada6b1-7ff600ada6be 1335->1337 1338 7ff600adab8d-7ff600adab9a SetLastError 1335->1338 1339 7ff600ada8c4-7ff600ada8d8 1336->1339 1337->1336 1340 7ff600ada6d2-7ff600ada6e0 1337->1340 1338->1339 1340->1338 1341 7ff600ada6e6-7ff600ada6f0 1340->1341 1341->1338 1342 7ff600ada6f6-7ff600ada6fc 1341->1342 1342->1338 1343 7ff600ada702-7ff600ada716 1342->1343 1344 7ff600ada745-7ff600ada776 GetNativeSystemInfo 1343->1344 1345 7ff600ada718-7ff600ada71e 1343->1345 1344->1338 1347 7ff600ada77c-7ff600ada7ab VirtualAlloc 1344->1347 1346 7ff600ada720-7ff600ada727 1345->1346 1348 7ff600ada72f 1346->1348 1349 7ff600ada729-7ff600ada72d 1346->1349 1350 7ff600ada7d0-7ff600ada7ea 1347->1350 1351 7ff600ada7ad-7ff600ada7ca VirtualAlloc 1347->1351 1352 7ff600ada731-7ff600ada743 1348->1352 1349->1352 1354 7ff600ada842-7ff600ada862 GetProcessHeap HeapAlloc 1350->1354 1355 7ff600ada7ec 1350->1355 1351->1350 1353 7ff600ada8a7-7ff600ada8bc SetLastError 1351->1353 1352->1344 1352->1346 1353->1339 1356 7ff600ada94c-7ff600ada9ad 1354->1356 1357 7ff600ada868-7ff600ada87c VirtualFree 1354->1357 1358 7ff600ada7f0-7ff600ada800 call 7ff600ae4070 1355->1358 1360 7ff600ada9af-7ff600ada9b4 SetLastError 1356->1360 1361 7ff600ada9c7-7ff600adaa14 VirtualAlloc call 7ff600afd3b0 call 7ff600ada0e0 1356->1361 1357->1353 1359 7ff600ada87e 1357->1359 1367 7ff600ada806-7ff600ada82d VirtualAlloc 1358->1367 1368 7ff600ada909-7ff600ada91d VirtualFree 1358->1368 1363 7ff600ada880-7ff600ada8a5 VirtualFree call 7ff600ae3bd8 1359->1363 1364 7ff600ada9ba-7ff600ada9c2 call 7ff600adad40 1360->1364 1361->1364 1383 7ff600adaa16-7ff600adaa21 1361->1383 1363->1353 1364->1361 1372 7ff600ada833-7ff600ada840 1367->1372 1373 7ff600ada8e0-7ff600ada905 VirtualFree call 7ff600ae3bd8 1367->1373 1368->1353 1377 7ff600ada91f 1368->1377 1372->1354 1372->1358 1387 7ff600ada907 1373->1387 1378 7ff600ada920-7ff600ada945 VirtualFree call 7ff600ae3bd8 1377->1378 1390 7ff600ada947 1378->1390 1384 7ff600adaa27-7ff600adaa2d 1383->1384 1385 7ff600adaab9 1383->1385 1388 7ff600adaa2f-7ff600adaa31 1384->1388 1389 7ff600adaa36-7ff600adaa49 1384->1389 1391 7ff600adaabe-7ff600adaacb call 7ff600ada4b0 1385->1391 1387->1353 1388->1391 1389->1385 1392 7ff600adaa4b 1389->1392 1390->1353 1391->1364 1396 7ff600adaad1-7ff600adaad4 call 7ff600ada220 1391->1396 1394 7ff600adaa50-7ff600adaa6b 1392->1394 1397 7ff600adaa6d 1394->1397 1398 7ff600adaaac-7ff600adaab7 1394->1398 1401 7ff600adaad9-7ff600adaadb 1396->1401 1400 7ff600adaa70-7ff600adaa81 1397->1400 1398->1385 1398->1394 1402 7ff600adaa83-7ff600adaa86 1400->1402 1403 7ff600adaa8e 1400->1403 1401->1364 1404 7ff600adaae1-7ff600adaaec 1401->1404 1405 7ff600adaa92-7ff600adaaaa 1402->1405 1406 7ff600adaa88-7ff600adaa8c 1402->1406 1403->1405 1407 7ff600adaaee-7ff600adaafa 1404->1407 1408 7ff600adab2a-7ff600adab32 1404->1408 1405->1398 1405->1400 1406->1405 1407->1408 1409 7ff600adaafc-7ff600adab02 1407->1409 1410 7ff600adab34-7ff600adab3b 1408->1410 1411 7ff600adab81-7ff600adab85 1408->1411 1409->1408 1412 7ff600adab04-7ff600adab08 1409->1412 1413 7ff600adab75-7ff600adab79 1410->1413 1414 7ff600adab3d-7ff600adab4c 1410->1414 1411->1338 1415 7ff600adab10-7ff600adab28 1412->1415 1413->1411 1418 7ff600adab4e-7ff600adab61 SetLastError call 7ff600adad40 1414->1418 1419 7ff600adab66-7ff600adab6d 1414->1419 1415->1408 1418->1419 1419->1413
            APIs
            • SetLastError.KERNEL32(?,?,?,?,?,?,?,?,?,00007FF600ACD242), ref: 00007FF600ADA6C5
            • GetNativeSystemInfo.KERNEL32(?,?,?,?,?,?,?,?,?,00007FF600ACD242), ref: 00007FF600ADA74A
            • VirtualAlloc.KERNEL32(?,?,?,?,?,?,?,?,?,00007FF600ACD242), ref: 00007FF600ADA79F
            • VirtualAlloc.KERNEL32(?,?,?,?,?,?,?,?,?,00007FF600ACD242), ref: 00007FF600ADA7BE
            • VirtualAlloc.KERNEL32(?,?,?,?,?,?,?,?,?,00007FF600ACD242), ref: 00007FF600ADA821
            • GetProcessHeap.KERNEL32(?,?,?,?,?,?,?,?,?,00007FF600ACD242), ref: 00007FF600ADA842
            • HeapAlloc.KERNEL32(?,?,?,?,?,?,?,?,?,00007FF600ACD242), ref: 00007FF600ADA856
            • VirtualFree.KERNEL32(?,?,?,?,?,?,?,?,?,00007FF600ACD242), ref: 00007FF600ADA873
            • VirtualFree.KERNEL32(?,?,?,?,?,?,?,?,?,00007FF600ACD242), ref: 00007FF600ADA88F
            • SetLastError.KERNEL32(?,?,?,?,?,?,?,?,?,00007FF600ACD242), ref: 00007FF600ADA8AC
            • SetLastError.KERNEL32(?,?,?,?,?,?,?,?,?,00007FF600ACD242), ref: 00007FF600ADAB92
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: Virtual$Alloc$ErrorLast$FreeHeap$InfoNativeProcessSystem
            • String ID:
            • API String ID: 1282860858-0
            • Opcode ID: 06589e85d6050c9ef5a7f7933ce4176366c98d370b168bd1ab009fbc31871bc3
            • Instruction ID: 43adf64a866aa08139c05e57d4d2df31441d5e58171ee449a5604689867f8e34
            • Opcode Fuzzy Hash: 06589e85d6050c9ef5a7f7933ce4176366c98d370b168bd1ab009fbc31871bc3
            • Instruction Fuzzy Hash: 05D1A033B09A4296EB608F16E45477973A5EF64B84F294036CE4FC779AEE3CE9419301
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: ProcessToken$AdjustCloseCurrentErrorHandleLastLookupOpenPrivilegePrivilegesValue$ExitWindows
            • String ID: SeShutdownPrivilege
            • API String ID: 1423298842-3733053543
            • Opcode ID: a792fc21bd502bb1f53feba3e0ea592908ea8fd6b5dd88df7bff687d3cdc374e
            • Instruction ID: 83f9f935a6ba5e80137068bf972ba4ec6533d49aa6e27f3c9594319423cf0f1d
            • Opcode Fuzzy Hash: a792fc21bd502bb1f53feba3e0ea592908ea8fd6b5dd88df7bff687d3cdc374e
            • Instruction Fuzzy Hash: 24317F36608E8299E720CF64E8147BA6364FF84B56F204036DA4E93BADDF3DD189C704
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: ProcessToken$AdjustCloseCurrentErrorHandleLastLookupOpenPrivilegePrivilegesValue$ExitWindows
            • String ID: SeShutdownPrivilege
            • API String ID: 1423298842-3733053543
            • Opcode ID: c4512c4a51b1fe7d902806900a56825f16f8507878c75a96d79f3f5efe7084bf
            • Instruction ID: 638bdfc8d1ea8877388744cd94630e7273e565b062a509de2b133c1dcdfddb30
            • Opcode Fuzzy Hash: c4512c4a51b1fe7d902806900a56825f16f8507878c75a96d79f3f5efe7084bf
            • Instruction Fuzzy Hash: 2B316D36608E8299E7208F64E8147BA6364FF84B56F204035DA4D93BA9DF3DD189C704
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: Create$Event$CountCriticalInitializeSectionSpin$Heap$ProcessTimetime
            • String ID: <$<
            • API String ID: 2446585644-213342407
            • Opcode ID: 29193acc1e1e8e4bf0335a70b56dbaf268a2d87dce0c9aa4dadcc0b3d1545946
            • Instruction ID: ac55b7ecbd970056656956bc233c5691c0ed3e8d29b7d2bb1ff1906657b28a20
            • Opcode Fuzzy Hash: 29193acc1e1e8e4bf0335a70b56dbaf268a2d87dce0c9aa4dadcc0b3d1545946
            • Instruction Fuzzy Hash: AEB15A73605B819AE7548F35E4857A933A8FB44B08F684538CB4D4B79ADF39A0A0C728
            APIs
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: Thread$Window$CloseConsoleCreateCurrentExceptionFilterHandleInputMessageObjectPostShowSingleSleepStateUnhandledWait
            • String ID:
            • API String ID: 2277684705-0
            • Opcode ID: 1f499c150cbe33159222533ec4b742c736879ee302e7e86ebc66b87cb5efa357
            • Instruction ID: 62faf7e9957242f4773691718653b6b78fb9758cdd5125461d3b884c7b51e59b
            • Opcode Fuzzy Hash: 1f499c150cbe33159222533ec4b742c736879ee302e7e86ebc66b87cb5efa357
            • Instruction Fuzzy Hash: 21012C36E58A42A6E314ABB1FC1457A32A6FF88B12B614135C91FC2379DF3CA445C304
            APIs
            • _get_daylight.LIBCMT ref: 00007FF600AF208D
              • Part of subcall function 00007FF600AF1704: _invalid_parameter_noinfo.LIBCMT ref: 00007FF600AF1718
              • Part of subcall function 00007FF600AEE95C: RtlFreeHeap.NTDLL(?,?,?,00007FF600AF6862,?,?,?,00007FF600AF6BDF,?,?,00000000,00007FF600AF7025,?,?,?,00007FF600AF6F57), ref: 00007FF600AEE972
              • Part of subcall function 00007FF600AEE95C: GetLastError.KERNEL32(?,?,?,00007FF600AF6862,?,?,?,00007FF600AF6BDF,?,?,00000000,00007FF600AF7025,?,?,?,00007FF600AF6F57), ref: 00007FF600AEE97C
              • Part of subcall function 00007FF600AE4028: IsProcessorFeaturePresent.KERNEL32(?,?,?,?,00007FF600AE3FD7,?,?,?,?,?,00007FF600AE3EC2), ref: 00007FF600AE4031
              • Part of subcall function 00007FF600AE4028: GetCurrentProcess.KERNEL32(?,?,?,?,00007FF600AE3FD7,?,?,?,?,?,00007FF600AE3EC2), ref: 00007FF600AE4056
              • Part of subcall function 00007FF600AFA1B4: _invalid_parameter_noinfo.LIBCMT ref: 00007FF600AFA0FF
            • _get_daylight.LIBCMT ref: 00007FF600AF207C
              • Part of subcall function 00007FF600AF1764: _invalid_parameter_noinfo.LIBCMT ref: 00007FF600AF1778
            • _get_daylight.LIBCMT ref: 00007FF600AF22F2
            • _get_daylight.LIBCMT ref: 00007FF600AF2303
            • _get_daylight.LIBCMT ref: 00007FF600AF2314
            • GetTimeZoneInformation.KERNEL32(?,?,?,?,?,?,?,?,?,00000000,?,00007FF600AF2554), ref: 00007FF600AF233B
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: _get_daylight$_invalid_parameter_noinfo$CurrentErrorFeatureFreeHeapInformationLastPresentProcessProcessorTimeZone
            • String ID: Eastern Standard Time$Eastern Summer Time
            • API String ID: 4070488512-239921721
            • Opcode ID: 5190737fcedb8824ad4a2f5adc1dd419c442ee6d8cf329e1688e58de2abb36f5
            • Instruction ID: 38bf88d18febea4b1931d95aec433a4c9686db20d96c7c5d0e36d567f3492ba3
            • Opcode Fuzzy Hash: 5190737fcedb8824ad4a2f5adc1dd419c442ee6d8cf329e1688e58de2abb36f5
            • Instruction Fuzzy Hash: FCD1BF73A48242A6EB20EFA6D4502B96769EF94784F648135EE4DC7B8EDF3CE441C740
            APIs
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: ControlDevice_invalid_parameter_noinfo_noreturn$CreateFilewsprintf
            • String ID:
            • API String ID: 3155671162-0
            • Opcode ID: c18f319fa9844628c6a677c07185de3de66ec9a391fe99c9b2b033250b86490b
            • Instruction ID: e1897eaa49f7d881f187e269123a1a1ed8d1df07f8b2186fdce322a75205f190
            • Opcode Fuzzy Hash: c18f319fa9844628c6a677c07185de3de66ec9a391fe99c9b2b033250b86490b
            • Instruction Fuzzy Hash: CD028F23F18B82A5EB00DBA1E5106BD23A1AB45B98F614635EE5E97BDEDF3CD445C300
            APIs
            • _get_daylight.LIBCMT ref: 00007FF600AF22F2
              • Part of subcall function 00007FF600AF1764: _invalid_parameter_noinfo.LIBCMT ref: 00007FF600AF1778
            • _get_daylight.LIBCMT ref: 00007FF600AF2303
              • Part of subcall function 00007FF600AF1704: _invalid_parameter_noinfo.LIBCMT ref: 00007FF600AF1718
            • _get_daylight.LIBCMT ref: 00007FF600AF2314
              • Part of subcall function 00007FF600AF1734: _invalid_parameter_noinfo.LIBCMT ref: 00007FF600AF1748
              • Part of subcall function 00007FF600AEE95C: RtlFreeHeap.NTDLL(?,?,?,00007FF600AF6862,?,?,?,00007FF600AF6BDF,?,?,00000000,00007FF600AF7025,?,?,?,00007FF600AF6F57), ref: 00007FF600AEE972
              • Part of subcall function 00007FF600AEE95C: GetLastError.KERNEL32(?,?,?,00007FF600AF6862,?,?,?,00007FF600AF6BDF,?,?,00000000,00007FF600AF7025,?,?,?,00007FF600AF6F57), ref: 00007FF600AEE97C
            • GetTimeZoneInformation.KERNEL32(?,?,?,?,?,?,?,?,?,00000000,?,00007FF600AF2554), ref: 00007FF600AF233B
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: _get_daylight_invalid_parameter_noinfo$ErrorFreeHeapInformationLastTimeZone
            • String ID: Eastern Standard Time$Eastern Summer Time
            • API String ID: 3458911817-239921721
            • Opcode ID: 2133f9b6c4e90f95ebb1c2c4b763d73db315d9997485f014e8f6b7b9b98ca04f
            • Instruction ID: d9ca5c2365bdd277bea2bfd169fd71d600e4f4418b66333962782fd71e4e39fd
            • Opcode Fuzzy Hash: 2133f9b6c4e90f95ebb1c2c4b763d73db315d9997485f014e8f6b7b9b98ca04f
            • Instruction Fuzzy Hash: 24519E73A48642A6E720EF62E8906B97764BF48784FA44135EA5EC779ADF3CE4008740
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: InfoSystem$AddressHandleModuleNativeProc
            • String ID: GetNativeSystemInfo$kernel32.dll
            • API String ID: 3433367815-192647395
            • Opcode ID: 06b04ae401ee5d5c7cc9b92bd00cef418c8d008ef26561d2b8b72a7f6fbba0c7
            • Instruction ID: 33c8ba6887b50af1411a7301d7452455d6e35469f03e7f8287f54801bc03e663
            • Opcode Fuzzy Hash: 06b04ae401ee5d5c7cc9b92bd00cef418c8d008ef26561d2b8b72a7f6fbba0c7
            • Instruction Fuzzy Hash: D9F09617E1CBC293EA61A710D8002B63361FFA8700FA15735E98E8179AEF1CE6D4C700
            APIs
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: _get_daylight$_isindst$_invalid_parameter_noinfo
            • String ID:
            • API String ID: 1405656091-0
            • Opcode ID: 94003a780ed234a965d2311ace6d53ea410cbd1e40622ac1b689e0d0deb2975f
            • Instruction ID: e2dd7549004448a7b327af81c10de39cf68d7488352929e5e9e7e8d465eb7d67
            • Opcode Fuzzy Hash: 94003a780ed234a965d2311ace6d53ea410cbd1e40622ac1b689e0d0deb2975f
            • Instruction Fuzzy Hash: 1491D5B3B043869BEB588F65C9012B963A5EB54B88F548139DA0DCB78EFF3CE5418700
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: ControlCreateDeviceFile
            • String ID: L$\\.\
            • API String ID: 107608037-1891537229
            • Opcode ID: 21bc0f6301598303c13827e0319026f3a4049949566ec9a53abc1aeea47cf04e
            • Instruction ID: ea2457b511ba57c8b1146a5e8cdaf2a48deca04f66c7f008258112f6661ccba3
            • Opcode Fuzzy Hash: 21bc0f6301598303c13827e0319026f3a4049949566ec9a53abc1aeea47cf04e
            • Instruction Fuzzy Hash: 2D31A26260D78195EB508F11B450379BB94EB85BE4F588335EBAA4BBCADF3CD505C700
            APIs
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: Virtual$AllocFreeTimerecvselecttime
            • String ID:
            • API String ID: 1996171534-0
            • Opcode ID: d85a249508b5bedee75b0bfb18c11ed9529f242c5de80f6903cc256f38a76d27
            • Instruction ID: 778b1c2af71a3c49c0af6416722e147ca9d56c152b3afa2a6beb89179625d5d6
            • Opcode Fuzzy Hash: d85a249508b5bedee75b0bfb18c11ed9529f242c5de80f6903cc256f38a76d27
            • Instruction Fuzzy Hash: 40719073A18A8592EB219F28D4047BD73A0FB95B88F259635CF4D8375AEF38E584C740
            APIs
            • VirtualFree.KERNELBASE(?,?,00000000,00007FF600ADA9C2,?,?,?,?,?,?,?,?,?,00007FF600ACD242), ref: 00007FF600ADADE0
            • GetProcessHeap.KERNEL32(?,?,00000000,00007FF600ADA9C2,?,?,?,?,?,?,?,?,?,00007FF600ACD242), ref: 00007FF600ADAE25
            • HeapFree.KERNEL32(?,?,00000000,00007FF600ADA9C2,?,?,?,?,?,?,?,?,?,00007FF600ACD242), ref: 00007FF600ADAE33
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: FreeHeap$ProcessVirtual
            • String ID:
            • API String ID: 190046822-0
            • Opcode ID: 89341820e01ce081605b96941eb1c7c686150c012882ba8243d161a74a304d71
            • Instruction ID: d1be2cb2424facbb6bebd2eff3c9f1330014b710222c7dfff1d4bbdda041d40f
            • Opcode Fuzzy Hash: 89341820e01ce081605b96941eb1c7c686150c012882ba8243d161a74a304d71
            • Instruction Fuzzy Hash: CD317E37B05B41A6EB54DB56E1402697370FB98B81F585032DF8E93B59CF38E4A2C700
            APIs
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: Virtual$AllocFree
            • String ID:
            • API String ID: 2087232378-0
            • Opcode ID: bdec6c309521b78e3869a161020c8be31cfe41798d2485b5db3fb8b25cd2d730
            • Instruction ID: 62f7847ad6b8ccf8f5f32185296bb3c915a40d6518f26f8ab7aa07c0c17a34d3
            • Opcode Fuzzy Hash: bdec6c309521b78e3869a161020c8be31cfe41798d2485b5db3fb8b25cd2d730
            • Instruction Fuzzy Hash: 0D41E333708A459AEB09CF2AE450A79A795FB85F84F254539EE0EC774AEF38D841C740

            Control-flow Graph

            • Executed
            • Not Executed
            control_flow_graph 808 7ff600ad0220-7ff600ad0299 GlobalAlloc GlobalLock call 7ff600afd3b0 GlobalUnlock CreateStreamOnHGlobal 811 7ff600ad029f-7ff600ad02fe call 7ff600ac61e0 EnterCriticalSection LeaveCriticalSection call 7ff600acc9b0 808->811 812 7ff600ad05f1-7ff600ad05fa GlobalFree 808->812 818 7ff600ad0304-7ff600ad032e GdipCreateBitmapFromStream 811->818 819 7ff600ad056e-7ff600ad0584 811->819 814 7ff600ad05fd-7ff600ad0617 812->814 820 7ff600ad0330-7ff600ad0336 GdipDisposeImage 818->820 821 7ff600ad033b-7ff600ad0356 call 7ff600acc340 GdipDisposeImage 818->821 824 7ff600ad05aa-7ff600ad05c0 call 7ff600ac61e0 EnterCriticalSection 819->824 825 7ff600ad0586-7ff600ad05a4 DeleteObject 819->825 820->819 821->819 828 7ff600ad035c-7ff600ad0373 CreateStreamOnHGlobal 821->828 831 7ff600ad05c2-7ff600ad05d2 EnterCriticalSection 824->831 832 7ff600ad05e7-7ff600ad05eb LeaveCriticalSection 824->832 825->824 828->819 830 7ff600ad0379-7ff600ad03a8 call 7ff600acc7b0 GetHGlobalFromStream GlobalLock 828->830 837 7ff600ad03ae-7ff600ad03cd GlobalFree 830->837 838 7ff600ad043f-7ff600ad0488 GlobalSize call 7ff600addff4 call 7ff600afd3b0 call 7ff600ac9fd0 830->838 834 7ff600ad05d4 GdiplusShutdown 831->834 835 7ff600ad05da-7ff600ad05e1 LeaveCriticalSection 831->835 832->812 834->835 835->832 842 7ff600ad03cf-7ff600ad03eb DeleteObject 837->842 843 7ff600ad03f1-7ff600ad0407 call 7ff600ac61e0 EnterCriticalSection 837->843 854 7ff600ad04de 838->854 855 7ff600ad048a-7ff600ad0492 838->855 842->843 849 7ff600ad042e-7ff600ad043a LeaveCriticalSection 843->849 850 7ff600ad0409-7ff600ad0419 EnterCriticalSection 843->850 849->814 852 7ff600ad0421-7ff600ad0428 LeaveCriticalSection 850->852 853 7ff600ad041b GdiplusShutdown 850->853 852->849 853->852 858 7ff600ad04e2-7ff600ad04e6 854->858 856 7ff600ad04c4-7ff600ad04dc 855->856 857 7ff600ad0494-7ff600ad04a1 855->857 856->858 859 7ff600ad04a3-7ff600ad04b6 857->859 860 7ff600ad04bf call 7ff600addf84 857->860 861 7ff600ad04e8-7ff600ad04f9 858->861 862 7ff600ad0519-7ff600ad052d call 7ff600addf84 858->862 863 7ff600ad04bc 859->863 864 7ff600ad0618-7ff600ad061f call 7ff600ae3ff8 859->864 860->856 866 7ff600ad0514 call 7ff600addf84 861->866 867 7ff600ad04fb-7ff600ad050e 861->867 873 7ff600ad0553-7ff600ad0561 GlobalUnlock 862->873 874 7ff600ad052f-7ff600ad054d DeleteObject 862->874 863->860 866->862 867->864 867->866 875 7ff600ad0567 873->875 874->873 875->819
            APIs
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: CriticalSection$Global$EnterLeave$Stream$CreateGdip$DeleteDisposeFreeFromGdiplusImageLockObjectShutdown$AllocBitmapErrorInitializeLastUnlock_invalid_parameter_noinfo_noreturn
            • String ID:
            • API String ID: 953580087-0
            • Opcode ID: 371ea4069b5b3ca6924937f5e99e0e9cdbd069c4b4962dec36c48b59051ce9fd
            • Instruction ID: 272ac774a5d6b30dbab0fd12556cc923ecc8cbdea42e908baeafa27e4dc6ecac
            • Opcode Fuzzy Hash: 371ea4069b5b3ca6924937f5e99e0e9cdbd069c4b4962dec36c48b59051ce9fd
            • Instruction Fuzzy Hash: E8C11927B04B42A9EB00DBA5E4142AD3375FB44B99F204236CE5E97B9ADF38D459C344

            Control-flow Graph

            • Executed
            • Not Executed
            control_flow_graph 876 7ff600acc340-7ff600acc383 GdipGetImagePixelFormat 877 7ff600acc385 876->877 878 7ff600acc387-7ff600acc3a4 876->878 877->878 879 7ff600acc3a6-7ff600acc3b3 878->879 880 7ff600acc3b9-7ff600acc3c4 878->880 879->880 881 7ff600acc3db-7ff600acc400 GdipGetImageHeight 880->881 882 7ff600acc3c6-7ff600acc3d4 880->882 883 7ff600acc402-7ff600acc40c 881->883 884 7ff600acc40f-7ff600acc422 GdipGetImageWidth 881->884 882->881 883->884 885 7ff600acc424 884->885 886 7ff600acc426-7ff600acc447 call 7ff600acc160 884->886 885->886 889 7ff600acc453-7ff600acc45b 886->889 890 7ff600acc449-7ff600acc44e 886->890 892 7ff600acc461-7ff600acc478 GdipGetImagePaletteSize 889->892 893 7ff600acc60d-7ff600acc61c 889->893 891 7ff600acc773-7ff600acc78c 890->891 894 7ff600acc47a 892->894 895 7ff600acc47c-7ff600acc487 892->895 896 7ff600acc6e2-7ff600acc74d GdipCreateBitmapFromScan0 GdipGetImageGraphicsContext GdipDrawImageI GdipDeleteGraphics GdipDisposeImage 893->896 897 7ff600acc622-7ff600acc64e GdipBitmapLockBits 893->897 894->895 900 7ff600acc4ba-7ff600acc4c6 call 7ff600ae4070 895->900 901 7ff600acc489-7ff600acc492 call 7ff600acb2e0 895->901 902 7ff600acc753-7ff600acc756 896->902 898 7ff600acc650-7ff600acc65a 897->898 899 7ff600acc66a-7ff600acc686 897->899 898->902 904 7ff600acc6c4-7ff600acc6db GdipBitmapUnlockBits 899->904 905 7ff600acc688-7ff600acc68b 899->905 915 7ff600acc4cd-7ff600acc4d4 900->915 916 7ff600acc4c8-7ff600acc4cb 900->916 901->900 919 7ff600acc494-7ff600acc49b 901->919 907 7ff600acc770 902->907 908 7ff600acc758 902->908 904->902 912 7ff600acc6dd-7ff600acc6e0 904->912 910 7ff600acc6ad-7ff600acc6c2 905->910 911 7ff600acc68d-7ff600acc690 905->911 907->891 914 7ff600acc760-7ff600acc76e call 7ff600ae3bd8 908->914 910->904 910->905 917 7ff600acc794-7ff600acc7af call 7ff600ae8d9c call 7ff600ae3fd8 call 7ff600ac10f0 911->917 918 7ff600acc696-7ff600acc69f 911->918 912->902 914->907 922 7ff600acc4d7-7ff600acc4da 915->922 916->922 924 7ff600acc6a5-7ff600acc6a8 call 7ff600afd3b0 918->924 925 7ff600acc78d-7ff600acc78f call 7ff600afda50 918->925 926 7ff600acc49d 919->926 927 7ff600acc4a7-7ff600acc4b8 call 7ff600ade600 919->927 929 7ff600acc4dc-7ff600acc4e2 922->929 930 7ff600acc4e7-7ff600acc4f9 GdipGetImagePalette 922->930 924->910 925->917 926->927 927->922 929->902 934 7ff600acc4ff-7ff600acc50a 930->934 935 7ff600acc4fb 930->935 939 7ff600acc65f-7ff600acc665 934->939 940 7ff600acc510-7ff600acc515 934->940 935->934 939->902 942 7ff600acc555-7ff600acc55d 940->942 943 7ff600acc517 940->943 946 7ff600acc55f-7ff600acc56a call 7ff600ac6280 942->946 947 7ff600acc5aa-7ff600acc5c2 SetDIBColorTable 942->947 945 7ff600acc520-7ff600acc553 943->945 945->942 945->945 953 7ff600acc570-7ff600acc57d 946->953 948 7ff600acc5c4-7ff600acc5de SelectObject call 7ff600ac6280 947->948 949 7ff600acc607 947->949 957 7ff600acc5e0-7ff600acc5ea 948->957 949->893 955 7ff600acc58e-7ff600acc5a6 SelectObject 953->955 956 7ff600acc57f-7ff600acc584 953->956 955->947 956->953 958 7ff600acc586-7ff600acc588 CreateCompatibleDC 956->958 959 7ff600acc5fc-7ff600acc603 957->959 960 7ff600acc5ec-7ff600acc5f1 957->960 958->955 959->949 960->957 961 7ff600acc5f3-7ff600acc5f6 DeleteDC 960->961 961->959
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: Gdip$Image$Bitmap$BitsCreateDeleteGraphicsObjectPaletteSelect$ColorCompatibleContextDisposeDrawFormatFromHeightLockPixelScan0SizeTableUnlockWidth_invalid_parameter_noinfo
            • String ID: &
            • API String ID: 4034434136-3042966939
            • Opcode ID: 239e805813e04336424a29340b1b3b4cd56234119952a51b41bc6ad9426f54d6
            • Instruction ID: ebb55ff8fda1e3b1df77286b07b77f13037188c4ce9b61e8c86d84261b1bd88e
            • Opcode Fuzzy Hash: 239e805813e04336424a29340b1b3b4cd56234119952a51b41bc6ad9426f54d6
            • Instruction Fuzzy Hash: F8D1E273604782AAEB608F21D544ABD37A4FB04BA8F128435DF1D97B4ADF38E541C740

            Control-flow Graph

            • Executed
            • Not Executed
            control_flow_graph 962 7ff600ac8710-7ff600ac874e 963 7ff600ac8755-7ff600ac8772 call 7ff600ac6300 call 7ff600addfb8 962->963 964 7ff600ac8750-7ff600ac8753 962->964 977 7ff600ac8774-7ff600ac878e SysAllocString 963->977 978 7ff600ac8796 963->978 964->963 965 7ff600ac87a5-7ff600ac87ab 964->965 967 7ff600ac87b2-7ff600ac87cf call 7ff600ac6300 call 7ff600addfb8 965->967 968 7ff600ac87ad-7ff600ac87b0 965->968 995 7ff600ac87f3 967->995 996 7ff600ac87d1-7ff600ac87eb SysAllocString 967->996 968->967 970 7ff600ac8802-7ff600ac8808 968->970 973 7ff600ac880e-7ff600ac8831 GetTokenInformation 970->973 974 7ff600ac89ff 970->974 979 7ff600ac8833-7ff600ac883c GetLastError 973->979 980 7ff600ac886c-7ff600ac8894 GetTokenInformation 973->980 988 7ff600ac8a06-7ff600ac8a10 call 7ff600adeca0 974->988 982 7ff600ac8794 977->982 983 7ff600ac8a11-7ff600ac8a1b call 7ff600adeca0 977->983 985 7ff600ac8799-7ff600ac879f 978->985 979->974 984 7ff600ac8842-7ff600ac8866 GetProcessHeap HeapAlloc 979->984 986 7ff600ac889a-7ff600ac88d2 LookupAccountSidW 980->986 987 7ff600ac89e6-7ff600ac89e9 980->987 982->985 1004 7ff600ac8a1c-7ff600ac8a26 call 7ff600adeca0 983->1004 984->974 984->980 985->965 985->988 991 7ff600ac88d4-7ff600ac88df GetLastError 986->991 992 7ff600ac891b-7ff600ac8921 986->992 987->974 990 7ff600ac89eb-7ff600ac89f9 GetProcessHeap HeapFree 987->990 988->983 990->974 997 7ff600ac88e1-7ff600ac88f7 call 7ff600ae8a40 991->997 998 7ff600ac88fc-7ff600ac891a 991->998 1001 7ff600ac8923-7ff600ac892b 992->1001 1002 7ff600ac892d-7ff600ac894a call 7ff600ac6300 call 7ff600addfb8 992->1002 1005 7ff600ac87f6-7ff600ac87fc 995->1005 1003 7ff600ac87f1 996->1003 996->1004 997->987 1001->1002 1007 7ff600ac897f-7ff600ac8985 1001->1007 1023 7ff600ac8970 1002->1023 1024 7ff600ac894c-7ff600ac8968 SysAllocString 1002->1024 1003->1005 1017 7ff600ac8a27-7ff600ac8a31 call 7ff600adeca0 1004->1017 1005->970 1005->988 1010 7ff600ac8994-7ff600ac89b1 call 7ff600ac6300 call 7ff600addfb8 1007->1010 1011 7ff600ac8987-7ff600ac8992 1007->1011 1031 7ff600ac89b3-7ff600ac89d2 SysAllocString 1010->1031 1032 7ff600ac89d6 1010->1032 1011->1010 1015 7ff600ac89e1 1011->1015 1015->987 1026 7ff600ac8a32-7ff600ac8a6f call 7ff600adeca0 GetCurrentProcessId OpenProcess 1017->1026 1028 7ff600ac8973-7ff600ac8979 1023->1028 1024->1017 1027 7ff600ac896e 1024->1027 1037 7ff600ac8a71-7ff600ac8a8e OpenProcessToken 1026->1037 1038 7ff600ac8a99-7ff600ac8aae 1026->1038 1027->1028 1028->988 1028->1007 1031->1026 1034 7ff600ac89d4 1031->1034 1035 7ff600ac89d9-7ff600ac89df 1032->1035 1034->1035 1035->988 1035->1015 1039 7ff600ac8aaf-7ff600ac8ad7 call 7ff600ac8710 1037->1039 1040 7ff600ac8a90-7ff600ac8a93 CloseHandle 1037->1040 1043 7ff600ac8b0a 1039->1043 1044 7ff600ac8ad9-7ff600ac8adf 1039->1044 1040->1038 1047 7ff600ac8b0f-7ff600ac8b12 1043->1047 1045 7ff600ac8ae1-7ff600ac8ae7 SysStringLen 1044->1045 1046 7ff600ac8ae9 1044->1046 1048 7ff600ac8aec-7ff600ac8aef 1045->1048 1046->1048 1049 7ff600ac8b14-7ff600ac8b29 call 7ff600addfb8 1047->1049 1050 7ff600ac8b4c-7ff600ac8b86 call 7ff600afd3b0 CloseHandle * 2 1047->1050 1048->1043 1052 7ff600ac8af1-7ff600ac8af7 1048->1052 1058 7ff600ac8b3b 1049->1058 1059 7ff600ac8b2b-7ff600ac8b39 1049->1059 1060 7ff600ac8bce-7ff600ac8bd6 1050->1060 1061 7ff600ac8b88-7ff600ac8b92 1050->1061 1056 7ff600ac8b03-7ff600ac8b08 1052->1056 1057 7ff600ac8af9-7ff600ac8b01 SysStringLen 1052->1057 1056->1047 1057->1047 1062 7ff600ac8b3e-7ff600ac8b46 1058->1062 1059->1062 1063 7ff600ac8c0d-7ff600ac8c1f 1060->1063 1064 7ff600ac8bd8-7ff600ac8be3 1060->1064 1065 7ff600ac8b94-7ff600ac8b9f 1061->1065 1066 7ff600ac8bc9 1061->1066 1062->1050 1069 7ff600ac8c20-7ff600ac8c99 call 7ff600adeca0 call 7ff600addff4 GetCurrentProcessId wsprintfW call 7ff600ac8a40 call 7ff600afda50 GetVersionExW 1062->1069 1067 7ff600ac8be5-7ff600ac8beb SysFreeString 1064->1067 1068 7ff600ac8bee-7ff600ac8bf5 1064->1068 1070 7ff600ac8ba1-7ff600ac8ba7 SysFreeString 1065->1070 1071 7ff600ac8baa-7ff600ac8bb1 1065->1071 1066->1060 1067->1068 1072 7ff600ac8c00-7ff600ac8c08 call 7ff600addf84 1068->1072 1073 7ff600ac8bf7-7ff600ac8bfc call 7ff600addf84 1068->1073 1091 7ff600ac8df2 1069->1091 1092 7ff600ac8c9f-7ff600ac8ca4 1069->1092 1070->1071 1074 7ff600ac8bb3-7ff600ac8bb8 call 7ff600addf84 1071->1074 1075 7ff600ac8bbc-7ff600ac8bc4 call 7ff600addf84 1071->1075 1072->1063 1073->1072 1074->1075 1075->1066 1094 7ff600ac8df9-7ff600ac8e03 wsprintfW 1091->1094 1092->1091 1093 7ff600ac8caa-7ff600ac8caf 1092->1093 1093->1091 1095 7ff600ac8cb5-7ff600ac8cdb GetCurrentProcess OpenProcessToken 1093->1095 1096 7ff600ac8e09-7ff600ac8e20 call 7ff600addf84 1094->1096 1095->1091 1097 7ff600ac8ce1-7ff600ac8d10 GetTokenInformation 1095->1097 1099 7ff600ac8d9c-7ff600ac8dac CloseHandle 1097->1099 1100 7ff600ac8d16-7ff600ac8d1f GetLastError 1097->1100 1099->1091 1102 7ff600ac8dae-7ff600ac8db4 1099->1102 1100->1099 1103 7ff600ac8d21-7ff600ac8d41 LocalAlloc 1100->1103 1104 7ff600ac8db6-7ff600ac8dbc 1102->1104 1105 7ff600ac8de9-7ff600ac8df0 1102->1105 1106 7ff600ac8d43-7ff600ac8d70 GetTokenInformation 1103->1106 1107 7ff600ac8d94 1103->1107 1108 7ff600ac8dbe-7ff600ac8dc4 1104->1108 1109 7ff600ac8de0-7ff600ac8de7 1104->1109 1105->1094 1110 7ff600ac8d72-7ff600ac8d89 GetSidSubAuthorityCount GetSidSubAuthority 1106->1110 1111 7ff600ac8d8b-7ff600ac8d8e LocalFree 1106->1111 1107->1099 1112 7ff600ac8dc6-7ff600ac8dcc 1108->1112 1113 7ff600ac8dd7-7ff600ac8dde 1108->1113 1109->1094 1110->1111 1111->1107 1112->1096 1114 7ff600ac8dce-7ff600ac8dd5 1112->1114 1113->1094 1114->1094
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: AllocProcess$HeapString$Token$ErrorInformationLastOpen$AccountCloseCurrentFreeHandleLookup
            • String ID: NONE_MAPPED
            • API String ID: 1410310566-2950899194
            • Opcode ID: 153f7837cc86bcbbc492fb4a375331227a21e9cb239b2b2f7dd34d1ee50442fc
            • Instruction ID: a27cae985f5404e046c15b37c16ac8eabaa48a70a30f8c3677c8dcac90807c57
            • Opcode Fuzzy Hash: 153f7837cc86bcbbc492fb4a375331227a21e9cb239b2b2f7dd34d1ee50442fc
            • Instruction Fuzzy Hash: F1A1A533609B42A6FA659B51E41067962E5FF84B80F6A4836DE4D8779AEF3CE844C310

            Control-flow Graph

            APIs
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: setsockopt$ByteCharMultiWidelstrlen$EventIoctlResetTimeconnectgethostbynamehtonssockettime
            • String ID: 0u
            • API String ID: 3082052849-3203441087
            • Opcode ID: b00b2f847c602c05c07fd1ee8bf7bb8e34ca4a0b5b9ccfebd140f7c7f5224909
            • Instruction ID: 8c61ffa97022679a295123a0cf95cd0db2a262a1093f26d517b8680a12e605c6
            • Opcode Fuzzy Hash: b00b2f847c602c05c07fd1ee8bf7bb8e34ca4a0b5b9ccfebd140f7c7f5224909
            • Instruction Fuzzy Hash: 33715C73608B819AD720DF61F44076AB7A5FB88794F104239EA9E43B69DF3DD119CB04

            Control-flow Graph

            APIs
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: Process$Token$CurrentOpen$AuthorityCloseHandleInformationLocalwsprintf$AllocCountErrorFreeLastVersion
            • String ID: VenNetwork
            • API String ID: 4155081256-3057682757
            • Opcode ID: d41af07cb10934b93d4f2e6b218dfa9c01e9023e3730c69632eb9c3a1c3d5fce
            • Instruction ID: a635f27bd738db33cef6ef12f4c19819e0b090ad017bdc8ea9870474d18cf80a
            • Opcode Fuzzy Hash: d41af07cb10934b93d4f2e6b218dfa9c01e9023e3730c69632eb9c3a1c3d5fce
            • Instruction Fuzzy Hash: DF417F33A0C682A6FB619B61E4447BA6364FF95B81F644435CA4F8379ADF3CE445C704
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: ControlDeviceGlobal$Free$Alloc
            • String ID: - External Hub$%s-%s|
            • API String ID: 3253977144-729331614
            • Opcode ID: 8542d015694a4c052021583ada6e3cfa5bd229d79c2476f491f3809817a3115c
            • Instruction ID: 63677df5598c51420e3e140661a915effba29b9af61fe154a3e6d64990ca2869
            • Opcode Fuzzy Hash: 8542d015694a4c052021583ada6e3cfa5bd229d79c2476f491f3809817a3115c
            • Instruction Fuzzy Hash: FDB1C273A08B8295E760CF60E8403AA77A4FB847A4FA44236DB4E9779ADF3CD545C700
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: CountInfoInputLastOpenQueryTickValue_invalid_parameter_noinfo_noreturnwsprintf
            • String ID: %d min$Console$IpDatespecial
            • API String ID: 357503962-2712035571
            • Opcode ID: 56be587995ba83f121b7bd3a612907d66a221bc6c75ef673ca1255c1a7ca8465
            • Instruction ID: 12a786ca5fafaef614b5a8ad4b1f014304cddcb16b98f354305eae191a284b7c
            • Opcode Fuzzy Hash: 56be587995ba83f121b7bd3a612907d66a221bc6c75ef673ca1255c1a7ca8465
            • Instruction Fuzzy Hash: FC510E33608E81A9EB208F24EC447B933A5FB48B99F654131CA0D8779AEF3DC589C700
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: ControlDevice$ByteCharCloseCreateFileHandleMultiWide$wsprintf
            • String ID: \\.\HCD%d
            • API String ID: 2324936672-2696249065
            • Opcode ID: fba3a6acf6e72ed7b72618c4283ac656f0c243164c030697ae0719591fc402df
            • Instruction ID: 72b031634c79600f0540d9c52265c07fd037ded18c5d6b25ca22814754ccddee
            • Opcode Fuzzy Hash: fba3a6acf6e72ed7b72618c4283ac656f0c243164c030697ae0719591fc402df
            • Instruction Fuzzy Hash: D8518133A0C782A6EB609F10B44077AB794FB85794F642135DA8E87B9AEF3CD505CB00
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: Gdip$Image$BitmapCreateDisposeEncodersFrom$SaveScan0SizeStream
            • String ID: &
            • API String ID: 370471037-3042966939
            • Opcode ID: 28b2eeaec2d98f14f4e8f3b60e7ba4f1bea8e24f035ccc537625c12df49cfb7a
            • Instruction ID: 39d51b232b2f5ff945abb3afa400d8e84b693539482f192bc81fc93c9b2fa57e
            • Opcode Fuzzy Hash: 28b2eeaec2d98f14f4e8f3b60e7ba4f1bea8e24f035ccc537625c12df49cfb7a
            • Instruction Fuzzy Hash: 5251A633B08742A6EB109F6598009B923A5FF44BA4F664631DE1D87B9ADF3CE546C340
            APIs
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: Close$OpenQueryValuelstrcmp
            • String ID:
            • API String ID: 4288439342-0
            • Opcode ID: 9757e75af8232627abeb9f8389a1c3797a9351f61d8f1bccc733d4b1246574e8
            • Instruction ID: 04153feca29367558ed90310afce68047182454cb2723c4401d1bd04729d9a78
            • Opcode Fuzzy Hash: 9757e75af8232627abeb9f8389a1c3797a9351f61d8f1bccc733d4b1246574e8
            • Instruction Fuzzy Hash: 68318633618B8196E760CB65E888AAA73A4FB84B90F604635DA5D83BDDDF3DD804C740
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: _invalid_parameter_noinfo_noreturn$CreateFactory
            • String ID: %s%s %d %d $%s%s %d*%d
            • API String ID: 2331002265-1924168580
            • Opcode ID: fe652329a2bccab07e07443f04fbc38bc44c37eb9ecce26c36fb009454b80e6c
            • Instruction ID: 5b54cc817c268d62dde6d3c0eb0255af4d93e48e8b74ee3c1b78d5c36d120b28
            • Opcode Fuzzy Hash: fe652329a2bccab07e07443f04fbc38bc44c37eb9ecce26c36fb009454b80e6c
            • Instruction Fuzzy Hash: C9A19C33B04A85A5EB10CF69D4446EE7761FB89B98F610632EE9D97B99CF38D041C700
            APIs
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: CloseCreateErrorFreeHandleLastLibraryThread_invalid_parameter_noinfo
            • String ID:
            • API String ID: 2067211477-0
            • Opcode ID: 2bf2d8e4056023ef3a5b5264bbcf8491965b7124c54493676a6e58e8f064e49f
            • Instruction ID: 60a4be4ff66c8408ab3ed512b191b580a606bd99ac3f86c31ae991995f93f3a7
            • Opcode Fuzzy Hash: 2bf2d8e4056023ef3a5b5264bbcf8491965b7124c54493676a6e58e8f064e49f
            • Instruction Fuzzy Hash: CC215037A0A782A5EE54DFA5A810079A3A4AFC9B90F344535DE4D8779EEF3CE4408710
            APIs
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: CurrentThreadsend
            • String ID:
            • API String ID: 302076607-0
            • Opcode ID: 1d5fac0907bdd9d84bc34d83d8396e4accfe818cb4c73ff339665f4c5f5d32ef
            • Instruction ID: 9a74ff7a79920ea545516d447fa45bd635a582f83e9b1a22b47fa371ce6bdc7a
            • Opcode Fuzzy Hash: 1d5fac0907bdd9d84bc34d83d8396e4accfe818cb4c73ff339665f4c5f5d32ef
            • Instruction Fuzzy Hash: E451B133A04B4697EB149F25E44476AB7B0FB84B84F258838CB498BB1ADF38E5528340
            APIs
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: CancelEventclosesocketsetsockopt
            • String ID:
            • API String ID: 852421847-0
            • Opcode ID: 3e6bea74e94700dfcc8d9d47a61c466b5b5c0e1f507d80d6be11655914b66227
            • Instruction ID: 174738c10df9f47991fda5abdbb8ded6601a79c3214cc08a615d3ad794de3444
            • Opcode Fuzzy Hash: 3e6bea74e94700dfcc8d9d47a61c466b5b5c0e1f507d80d6be11655914b66227
            • Instruction Fuzzy Hash: 4AF04632604A8196DB149F65E45432AB330FB88BA4F204335CBAC87BA8CF39E0658740
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: CloseHandlewsprintf
            • String ID: %s_bin
            • API String ID: 3088109604-2665034546
            • Opcode ID: 244c7580eec467afa70b9ee0c9a979b889a49d4b076565b89eb80eb5a3343fb4
            • Instruction ID: 8346425306e4a587d8ee30acc65ed2f744c101747b0037849368470f75e53f09
            • Opcode Fuzzy Hash: 244c7580eec467afa70b9ee0c9a979b889a49d4b076565b89eb80eb5a3343fb4
            • Instruction Fuzzy Hash: 3E51D363B19A96A1EF61DB25C014BB92365EF89B44F668536DA0E877CAEF3CD401C301
            APIs
            • VirtualProtect.KERNEL32(?,?,00000000,?,00007FF600ADAAD9,?,?,?,?,?,?,?,?,?,00007FF600ACD242), ref: 00007FF600ADA3A4
            • VirtualFree.KERNELBASE(?,?,00000000,?,00007FF600ADAAD9,?,?,?,?,?,?,?,?,?,00007FF600ACD242), ref: 00007FF600ADA42E
            • VirtualProtect.KERNEL32(?,?,00000000,?,00007FF600ADAAD9,?,?,?,?,?,?,?,?,?,00007FF600ACD242), ref: 00007FF600ADA495
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: Virtual$Protect$Free
            • String ID:
            • API String ID: 3866829018-0
            • Opcode ID: f0e3e3619a435ed4c6f8b5a79368ecdee668cb236449d597bacc64a0fa136902
            • Instruction ID: 6d971eeb0e756ea5cca5683ac21ddab3b9845c313fad12c2a529dd8c32f552dd
            • Opcode Fuzzy Hash: f0e3e3619a435ed4c6f8b5a79368ecdee668cb236449d597bacc64a0fa136902
            • Instruction Fuzzy Hash: 2F61F0B7B1865196EB20CF57A400AA877A1FB24B80F945032DF4B87B49CF3DE950C701
            APIs
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: ByteCharMultiWide$ControlDefaultDeviceLangSystemlstrcpy
            • String ID:
            • API String ID: 3058672631-0
            • Opcode ID: d44846b71ec048a98a3cb0e9568e6036a274ee5c34c58920ad56b60fc8d534b8
            • Instruction ID: 8e4f5f0bfaeb8d92cd690b9bc4fa19f672226de3664e08419555226f0f916ad8
            • Opcode Fuzzy Hash: d44846b71ec048a98a3cb0e9568e6036a274ee5c34c58920ad56b60fc8d534b8
            • Instruction Fuzzy Hash: B831A732A0C68295EB20DB51E4443BEB3A5EB89790F644135EF9E8778ADF3DD405C740
            APIs
              • Part of subcall function 00007FF600AC61E0: InitializeCriticalSectionEx.KERNEL32 ref: 00007FF600AC6231
              • Part of subcall function 00007FF600AC61E0: GetLastError.KERNEL32 ref: 00007FF600AC623B
            • EnterCriticalSection.KERNEL32(?,?,?,?,?,?,?,?,00000000,00007FF600ACC7D4), ref: 00007FF600ACC9DA
            • GdiplusStartup.GDIPLUS ref: 00007FF600ACCA0F
            • LeaveCriticalSection.KERNEL32(?,?,?,?,?,?,?,?,00000000,00007FF600ACC7D4), ref: 00007FF600ACCA27
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: CriticalSection$EnterErrorGdiplusInitializeLastLeaveStartup
            • String ID:
            • API String ID: 2723390537-0
            • Opcode ID: c1fce392dff7f0e0a1fd8d320c51b28cecfe9cf3d04554c50c1a4421144027e9
            • Instruction ID: 14f338c06af95e550a115beed41dc970ccf1f6828e58b4184f3c7b20bc7424d8
            • Opcode Fuzzy Hash: c1fce392dff7f0e0a1fd8d320c51b28cecfe9cf3d04554c50c1a4421144027e9
            • Instruction Fuzzy Hash: 45018C33A08B819AE7009F15E40436AB3E5FB84B81F990035EB8E83759CF3CD095CB40
            APIs
              • Part of subcall function 00007FF600AEEE88: GetLastError.KERNEL32(?,?,00002C1F5E3C02FD,00007FF600AE8DA5,?,?,?,?,00007FF600AF27E6,?,?,00000000,00007FF600AEA69B,?,?,?), ref: 00007FF600AEEE97
              • Part of subcall function 00007FF600AEEE88: SetLastError.KERNEL32(?,?,00002C1F5E3C02FD,00007FF600AE8DA5,?,?,?,?,00007FF600AF27E6,?,?,00000000,00007FF600AEA69B,?,?,?), ref: 00007FF600AEEF37
            • CloseHandle.KERNEL32(?,?,?,00007FF600AE8CC5,?,?,?,?,00007FF600AE8B09), ref: 00007FF600AE8B53
            • FreeLibraryAndExitThread.KERNEL32(?,?,?,00007FF600AE8CC5,?,?,?,?,00007FF600AE8B09), ref: 00007FF600AE8B69
            • ExitThread.KERNEL32 ref: 00007FF600AE8B72
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: ErrorExitLastThread$CloseFreeHandleLibrary
            • String ID:
            • API String ID: 1991824761-0
            • Opcode ID: a30104ba4f4f868018fa850f0c9dce139a3884833968d360b0db499d9868783c
            • Instruction ID: 702a6772c332ae35be194ad5e1c1c6709e6fd9d08b2d40f6d902eee2521b4c5a
            • Opcode Fuzzy Hash: a30104ba4f4f868018fa850f0c9dce139a3884833968d360b0db499d9868783c
            • Instruction Fuzzy Hash: ABF06263A086C261FE549B60944427C2369AF40B79F3C0735C63C863DEEF3DD8458340
            APIs
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: SleepTimetime
            • String ID:
            • API String ID: 346578373-0
            • Opcode ID: a07444b426276808b022deff05d84a514b99e0a0f66664c5b3036afdf0babcf4
            • Instruction ID: a1224700c879f6655f0974f02c26d37778c4de5190714239fcc89a1c11d13b84
            • Opcode Fuzzy Hash: a07444b426276808b022deff05d84a514b99e0a0f66664c5b3036afdf0babcf4
            • Instruction Fuzzy Hash: D3018C23B1864197EB644B64E28877C27A0FB48B84F55AA34C75A877DACF3CD5E5C700
            APIs
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: ErrorExitLastThread
            • String ID:
            • API String ID: 1611280651-0
            • Opcode ID: 41641528019013f9ff929c92362d335c34901b889fac2650327ddb4de509bf94
            • Instruction ID: 07f8d172124500f3a92f0385092eefa545be442997e1a5448278d4ffb4e01203
            • Opcode Fuzzy Hash: 41641528019013f9ff929c92362d335c34901b889fac2650327ddb4de509bf94
            • Instruction Fuzzy Hash: FCF0B423E5A68296EF04BBB1944917D1254AF54B40F340434D90DC739BEF2CE4458310
            APIs
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: Concurrency::cancel_current_task
            • String ID:
            • API String ID: 118556049-0
            • Opcode ID: 8afa6a4327cd587ea362fe0c4f5b4bf1e5e9001c34c8a508c9f4177e13cca725
            • Instruction ID: 8d40c1fa34ac979a5a2907ffffa5ca6091646dd961596b02d3b1c80aa32b625e
            • Opcode Fuzzy Hash: 8afa6a4327cd587ea362fe0c4f5b4bf1e5e9001c34c8a508c9f4177e13cca725
            • Instruction Fuzzy Hash: 16E0BD42E1D10B65F92823AA241A9B820800F4D7B0F381B32EE7FC83CBBD1CA4A58151
            APIs
            • RtlFreeHeap.NTDLL(?,?,?,00007FF600AF6862,?,?,?,00007FF600AF6BDF,?,?,00000000,00007FF600AF7025,?,?,?,00007FF600AF6F57), ref: 00007FF600AEE972
            • GetLastError.KERNEL32(?,?,?,00007FF600AF6862,?,?,?,00007FF600AF6BDF,?,?,00000000,00007FF600AF7025,?,?,?,00007FF600AF6F57), ref: 00007FF600AEE97C
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: ErrorFreeHeapLast
            • String ID:
            • API String ID: 485612231-0
            • Opcode ID: a2b1b4d253dc9b48524949a201526306b0bcc39bf10aa9e0b1341fdbb23a067c
            • Instruction ID: 67afb938143cf4ed2abf297740e2c84c334dd55cc57d9a10b09a488f76bb4790
            • Opcode Fuzzy Hash: a2b1b4d253dc9b48524949a201526306b0bcc39bf10aa9e0b1341fdbb23a067c
            • Instruction Fuzzy Hash: DCE0C212F0924363FF58ABF2A84407916949F84701F705434CD0DC739BFE3CA8408310
            APIs
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: AllocErrorLastVirtual
            • String ID:
            • API String ID: 497505419-0
            • Opcode ID: e8cc5ead388a834f61713ab96b6f627611700b567b2c89878f21a98ade30cb92
            • Instruction ID: b496e5604856f9164fbbc1bedc5cdf5bf8918cb12c26afa1c748af680c4f038d
            • Opcode Fuzzy Hash: e8cc5ead388a834f61713ab96b6f627611700b567b2c89878f21a98ade30cb92
            • Instruction Fuzzy Hash: BF316D73B0498196DB14CB16E844669B7A1FB54B88F148036EF4E87759DE38D481C701
            APIs
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: Virtual$AllocFree
            • String ID:
            • API String ID: 2087232378-0
            • Opcode ID: 17a02dcf2f47f10d7a08db77411b6b44ca6662cc7d290d042544fe107c4b0b33
            • Instruction ID: 38f7d2a0295a977df80ac134d5308fec6ce06e88f4975e782b8711bfaa712dff
            • Opcode Fuzzy Hash: 17a02dcf2f47f10d7a08db77411b6b44ca6662cc7d290d042544fe107c4b0b33
            • Instruction Fuzzy Hash: 2321793271864196D724CB6AF48052AB7B1FB85B84B244535EB9ED3B19DF3CE4818B44
            APIs
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: Virtual$AllocFree
            • String ID:
            • API String ID: 2087232378-0
            • Opcode ID: 4c8156205564e744c18fa944b02d568327434d479cf77dfe2f9176b33a9ea29c
            • Instruction ID: 6acc73834029f8e6376055c7ee34be909fe7cc94e348b00626f9abba52ab13a3
            • Opcode Fuzzy Hash: 4c8156205564e744c18fa944b02d568327434d479cf77dfe2f9176b33a9ea29c
            • Instruction Fuzzy Hash: C8110832B28A4182EB05CF36E440529A3A5FF89BC0B244531EA4ED775DEF3CD891CB40
            APIs
              • Part of subcall function 00007FF600ADDD80: __scrt_dllmain_crt_thread_attach.LIBCMT ref: 00007FF600ADDD94
            • __scrt_release_startup_lock.LIBCMT ref: 00007FF600ADE177
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: __scrt_dllmain_crt_thread_attach__scrt_release_startup_lock
            • String ID:
            • API String ID: 2217363868-0
            • Opcode ID: df8c2cae6130cff53013dc258be4a77fac826802f49534194485c90f58f48bf0
            • Instruction ID: 4b4bee55ba523bd7b70bf273d928fb73ebf507613189c792b7caee0d63e44146
            • Opcode Fuzzy Hash: df8c2cae6130cff53013dc258be4a77fac826802f49534194485c90f58f48bf0
            • Instruction Fuzzy Hash: A6314A23A0914365FA10FB6494513B92395AF95784FA4003AEE4FCB3EFDE6DE4458310
            APIs
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: Startup
            • String ID:
            • API String ID: 724789610-0
            • Opcode ID: 2276b2cfde0ec166953e0ec75e850ce31f8cbc4b3846b0cdc97fb7f8133b5954
            • Instruction ID: 34be0697f95ec8502534e9acb865cadd06da0f1d07f896aa3067a87e8ee9253f
            • Opcode Fuzzy Hash: 2276b2cfde0ec166953e0ec75e850ce31f8cbc4b3846b0cdc97fb7f8133b5954
            • Instruction Fuzzy Hash: 99E04F36B05545EAE611EB64D4450B47365FB58340F504132E98D8379ADF2CE515CB00
            APIs
              • Part of subcall function 00007FF600ADDFB8: Concurrency::cancel_current_task.LIBCPMT ref: 00007FF600ADDFE8
              • Part of subcall function 00007FF600ADDFB8: Concurrency::cancel_current_task.LIBCPMT ref: 00007FF600ADDFEE
              • Part of subcall function 00007FF600AE8A40: _invalid_parameter_noinfo.LIBCMT ref: 00007FF600AE8A66
            • CloseHandle.KERNEL32 ref: 00007FF600ACEF19
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: Concurrency::cancel_current_task$CloseHandle_invalid_parameter_noinfo
            • String ID:
            • API String ID: 1286571413-0
            • Opcode ID: c6d68c6bbe32cbf81c792a0b4ad5dedd764ab29200c0bf5c6bb2578c3c869653
            • Instruction ID: 758d80fc8c7f0696c906199f4b400430e5db4a429d09dffb2d503d3098b95849
            • Opcode Fuzzy Hash: c6d68c6bbe32cbf81c792a0b4ad5dedd764ab29200c0bf5c6bb2578c3c869653
            • Instruction Fuzzy Hash: 7731BCB3A08B91A1E768DF14E4146EE7765FB88B44F62403AEB0E8738ACF38D551C344
            APIs
            • HeapAlloc.KERNEL32(?,?,?,00007FF600AF27CD,?,?,00000000,00007FF600AEA69B,?,?,?,00007FF600AEC873,?,?,?,00007FF600AEC769), ref: 00007FF600AEF0AE
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: AllocHeap
            • String ID:
            • API String ID: 4292702814-0
            • Opcode ID: 016c47a342e12657c725cebeaa7b4028c5a2c41f1cbc7a3001cbfc12b323d78a
            • Instruction ID: 2d739f4b4072fd965805345a739b6c49a62d2dfe189f800bdd12468bff333713
            • Opcode Fuzzy Hash: 016c47a342e12657c725cebeaa7b4028c5a2c41f1cbc7a3001cbfc12b323d78a
            • Instruction Fuzzy Hash: 0BF03053F4D6836AFE646BA2584167612849F857A0F380730DD2EC63CFFE2CE4818215
            APIs
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: CloseHandle_invalid_parameter_noinfo
            • String ID:
            • API String ID: 1071934762-0
            • Opcode ID: 6a7d53c689feae9ae0328117cfd99eda37d466c79035ccfc82de7d7785a1b7c7
            • Instruction ID: d3c71b3a7d46db9eca8349cdc7dd05ae8b2cc0019612698d4df789010ff5ecfa
            • Opcode Fuzzy Hash: 6a7d53c689feae9ae0328117cfd99eda37d466c79035ccfc82de7d7785a1b7c7
            • Instruction Fuzzy Hash: C1F0E223E0C54151F7249B55A4003BE6251BFC4B94F14043AEE0EA77CBDD3CE0538740
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: Process$Virtual$AddressLibraryLoadProcProtect$AllocCreateCurrentMemoryOpenThreadTokenWrite$AdjustDirectoryFileLookupModuleNamePrivilegePrivilegesRemoteResumeSleepSystemValue
            • String ID: %s%s$@$ExitProcess$Kernel32.dll$OpenProcess$SeDebugPrivilege$WaitForSingleObject$WinExec$Windows\System32\svchost.exe$h
            • API String ID: 3040193174-4212407401
            • Opcode ID: 6fd3f4fde48d0361eb2d5c202ab323ad8a247f6fe0c7ba3ad29a459755052d7c
            • Instruction ID: e1ac2017ca29a8b51c8ba424f06270ae27095a65d0c04194408532ef5e933021
            • Opcode Fuzzy Hash: 6fd3f4fde48d0361eb2d5c202ab323ad8a247f6fe0c7ba3ad29a459755052d7c
            • Instruction Fuzzy Hash: AEA16172B08B8299E7218F61E8147FA23A8FF89788F504135DA4E97B69DF3CD245C744
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: lstrlen$wsprintf$ClipboardFileGlobal$CloseCountTickWindow$CreateDataForegroundHandleLocalLockMutexObjectOpenPointerReleaseSingleSizeSleepStateTextTimeUnlockWaitWrite
            • String ID: [$[$%s%s$%s%s$%s%s$[esc]
            • API String ID: 3669393114-972647286
            • Opcode ID: 0ba4a650500777e326fb2fa0ba1ce122045bb19d315cab67db3075d848846471
            • Instruction ID: f9633507daaeafdf70e29b1af14e22aa30d0bc12e743c0e0e2778f5d6e49d8ad
            • Opcode Fuzzy Hash: 0ba4a650500777e326fb2fa0ba1ce122045bb19d315cab67db3075d848846471
            • Instruction Fuzzy Hash: B1D1DE22A0C642A6FB209B65E8046FA73A4FF85784F604532D95EC37AEDF3DE548C710
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: lstrlen$CreateEventLocalTimewsprintf
            • String ID: %4d.%2d.%2d-%2d:%2d:%2d$o1:$p1:$t1:
            • API String ID: 2157945651-1225219777
            • Opcode ID: 8e5e4238cfe7c353d5852bfc473442a04ad693366b72332548162b2e4d4925fd
            • Instruction ID: 563a2f7e859bbd341f782b9009563034e683d61a61d6c4cf0f49cdcfaebc634f
            • Opcode Fuzzy Hash: 8e5e4238cfe7c353d5852bfc473442a04ad693366b72332548162b2e4d4925fd
            • Instruction Fuzzy Hash: 67F1F463B18692A6EB209F65D8407BD23A1FB44B88F214635DA4E97B9EDF3CE541C700
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: AddressProc$Library$FileFree$CloseCreateHandleLoadSleepWrite
            • String ID: InternetCloseHandle$InternetOpenUrlW$InternetOpenW$InternetReadFile$MSIE 6.0$wininet.dll
            • API String ID: 2977986460-1099148085
            • Opcode ID: 067ce2f794736821cf202725aa30ed0aa3c92a2ab4f8812fc9fc05c1c4d827d7
            • Instruction ID: 0d99021946635283c3f9f8aa471156a1d0794dc378adf9d2cd4f7b48d46aefc4
            • Opcode Fuzzy Hash: 067ce2f794736821cf202725aa30ed0aa3c92a2ab4f8812fc9fc05c1c4d827d7
            • Instruction Fuzzy Hash: 6B410627A08642A6EB20DB51B904BBA77A0FF89BD4F644130CE5E47799DF3CD005CB00
            APIs
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: Lockitstd::_$Clipboard$GlobalLockit::_$Lockit::~_$Close_invalid_parameter_noinfo_noreturn$DataLockOpenUnlock$AllocEmptySetgloballocaleSleeplstrlenstd::locale::_
            • String ID:
            • API String ID: 1851032462-0
            • Opcode ID: 3dc2591f054965ba17c19e7eb8a1a5c0391eaf4d51c1fc91c888d0fc922051e0
            • Instruction ID: 0981ec946159db07081914a86b7144dc5bfe4c264f7b7ff31d311e667455c6bf
            • Opcode Fuzzy Hash: 3dc2591f054965ba17c19e7eb8a1a5c0391eaf4d51c1fc91c888d0fc922051e0
            • Instruction Fuzzy Hash: 66D17063B09A86A6EA109B65E4442BD7361FF84B94F244636EE5E8779EDF3CE440C700
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: _invalid_parameter_noinfo$memcpy_s$fegetenv
            • String ID: 1#IND$1#INF$1#QNAN$1#SNAN
            • API String ID: 808467561-2761157908
            • Opcode ID: 8a8cdf450ad9da4e3e91848c83b2fc9670f44cdb81e1e9276785e569651f6bed
            • Instruction ID: 417783b34237f83eb57a677cbfff3503d0a4da7e423e90aad03f76d73501b832
            • Opcode Fuzzy Hash: 8a8cdf450ad9da4e3e91848c83b2fc9670f44cdb81e1e9276785e569651f6bed
            • Instruction Fuzzy Hash: EDB2E173A582829BE7658EA4D4407FD77A9FB54388F605135DA0D97B8EDF3CAA00CB40
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: Close$OpenQueryValuelstrcpy
            • String ID: %08X
            • API String ID: 2032971926-3773563069
            • Opcode ID: 32c954eb57fda164b81f0150aeb248f5c32c45763a12c98c87c6a1606aaef6c8
            • Instruction ID: e44c0c8d4cd24666d0d1e8e504a1a4ebe4662db91acf4f53ae7a0c70c8353f85
            • Opcode Fuzzy Hash: 32c954eb57fda164b81f0150aeb248f5c32c45763a12c98c87c6a1606aaef6c8
            • Instruction Fuzzy Hash: 5B516E62648AC1A5E770CB25E4447ABB360FB85794FA04136DB8D83BAEDF3CD544CB08
            APIs
              • Part of subcall function 00007FF600AEED10: GetLastError.KERNEL32(?,?,?,00007FF600AF7113,?,?,?,00007FF600AEF444,?,?,?,00007FF600AE843F,?,?,?,00007FF600AE66E3), ref: 00007FF600AEED1F
              • Part of subcall function 00007FF600AEED10: FlsGetValue.KERNEL32(?,?,?,00007FF600AF7113,?,?,?,00007FF600AEF444,?,?,?,00007FF600AE843F,?,?,?,00007FF600AE66E3), ref: 00007FF600AEED34
              • Part of subcall function 00007FF600AEED10: SetLastError.KERNEL32(?,?,?,00007FF600AF7113,?,?,?,00007FF600AEF444,?,?,?,00007FF600AE843F,?,?,?,00007FF600AE66E3), ref: 00007FF600AEEDBF
            • TranslateName.LIBCMT ref: 00007FF600AF79E6
            • TranslateName.LIBCMT ref: 00007FF600AF7A21
            • GetACP.KERNEL32(?,?,?,00000000,00000092,00007FF600AED778), ref: 00007FF600AF7A68
            • IsValidCodePage.KERNEL32(?,?,?,00000000,00000092,00007FF600AED778), ref: 00007FF600AF7AA0
            • GetLocaleInfoW.KERNEL32 ref: 00007FF600AF7C5D
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: ErrorLastNameTranslate$CodeInfoLocalePageValidValue
            • String ID: utf8
            • API String ID: 3069159798-905460609
            • Opcode ID: ed249922890c5a667d77dbf9e0f0f5ff4edc5bc12cc14daec0a02a097362d650
            • Instruction ID: 337a1c48eb1f153cc9621260e780ba20ad2f265b1f50c847d470d4d4b21cdba8
            • Opcode Fuzzy Hash: ed249922890c5a667d77dbf9e0f0f5ff4edc5bc12cc14daec0a02a097362d650
            • Instruction Fuzzy Hash: 47918933A4C782A5EB24AFA1D8412BD22A8EB45B80F644131DE4D8778AEF3DE552C740
            APIs
              • Part of subcall function 00007FF600AEED10: GetLastError.KERNEL32(?,?,?,00007FF600AF7113,?,?,?,00007FF600AEF444,?,?,?,00007FF600AE843F,?,?,?,00007FF600AE66E3), ref: 00007FF600AEED1F
              • Part of subcall function 00007FF600AEED10: FlsGetValue.KERNEL32(?,?,?,00007FF600AF7113,?,?,?,00007FF600AEF444,?,?,?,00007FF600AE843F,?,?,?,00007FF600AE66E3), ref: 00007FF600AEED34
              • Part of subcall function 00007FF600AEED10: SetLastError.KERNEL32(?,?,?,00007FF600AF7113,?,?,?,00007FF600AEF444,?,?,?,00007FF600AE843F,?,?,?,00007FF600AE66E3), ref: 00007FF600AEEDBF
              • Part of subcall function 00007FF600AEED10: FlsSetValue.KERNEL32(?,?,?,00007FF600AF7113,?,?,?,00007FF600AEF444,?,?,?,00007FF600AE843F,?,?,?,00007FF600AE66E3), ref: 00007FF600AEED55
            • GetUserDefaultLCID.KERNEL32(00000000,00000092,?,?), ref: 00007FF600AF8534
              • Part of subcall function 00007FF600AEED10: FlsSetValue.KERNEL32(?,?,?,00007FF600AF7113,?,?,?,00007FF600AEF444,?,?,?,00007FF600AE843F,?,?,?,00007FF600AE66E3), ref: 00007FF600AEED82
              • Part of subcall function 00007FF600AEED10: FlsSetValue.KERNEL32(?,?,?,00007FF600AF7113,?,?,?,00007FF600AEF444,?,?,?,00007FF600AE843F,?,?,?,00007FF600AE66E3), ref: 00007FF600AEED93
              • Part of subcall function 00007FF600AEED10: FlsSetValue.KERNEL32(?,?,?,00007FF600AF7113,?,?,?,00007FF600AEF444,?,?,?,00007FF600AE843F,?,?,?,00007FF600AE66E3), ref: 00007FF600AEEDA4
            • EnumSystemLocalesW.KERNEL32(00000000,00000092,?,?,00000000,?,?,00007FF600AED771), ref: 00007FF600AF851B
            • ProcessCodePage.LIBCMT ref: 00007FF600AF855E
            • IsValidCodePage.KERNEL32 ref: 00007FF600AF8570
            • IsValidLocale.KERNEL32 ref: 00007FF600AF8586
            • GetLocaleInfoW.KERNEL32 ref: 00007FF600AF85E2
            • GetLocaleInfoW.KERNEL32 ref: 00007FF600AF85FE
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: Value$Locale$CodeErrorInfoLastPageValid$DefaultEnumLocalesProcessSystemUser
            • String ID:
            • API String ID: 2591520935-0
            • Opcode ID: 22d8bcddac7133f8b6f7a06d5e5334a0f8ea8210c2b9d064d69f21135d6cdb9b
            • Instruction ID: a88ef4668d114637495405cd269997642c46e5108cd33c680e11089e12509b04
            • Opcode Fuzzy Hash: 22d8bcddac7133f8b6f7a06d5e5334a0f8ea8210c2b9d064d69f21135d6cdb9b
            • Instruction Fuzzy Hash: CA716923B48602AAFB609FA0D8506BD23A8BF48B44F644135CA1D9779AEF3CE445C350
            APIs
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: ExceptionFilterPresentUnhandled$CaptureContextDebuggerEntryFeatureFunctionLookupProcessorUnwindVirtual
            • String ID:
            • API String ID: 3140674995-0
            • Opcode ID: 045e81cc47e066d153aaaf5b50bd9fe289779446efb159575806e036ae1ed661
            • Instruction ID: 3a07e6042e6960d907289daac910c9ef5df40abfddd1dea34e9d75a690d9fc82
            • Opcode Fuzzy Hash: 045e81cc47e066d153aaaf5b50bd9fe289779446efb159575806e036ae1ed661
            • Instruction Fuzzy Hash: 75310A73609B819AEB609FA0E8407FD7364FB84744F54443ADA4E87B9AEF38D648C714
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: Event$ClearCloseOpen
            • String ID: Application$Security$System
            • API String ID: 1391105993-2169399579
            • Opcode ID: 1bb91c5c2b3888595093d95bda04c9b415b5dc93057c8244563c58f3f028a90d
            • Instruction ID: 4839f70704e79755e5f28ba35552b839f9067cf4365811a4ebcd642059098270
            • Opcode Fuzzy Hash: 1bb91c5c2b3888595093d95bda04c9b415b5dc93057c8244563c58f3f028a90d
            • Instruction Fuzzy Hash: 94F0F437A0DF4195EA15CB15F840675A3A4FF89764F240435CD4E83769EF3DD1968704
            APIs
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: ExceptionFilterUnhandled$CaptureContextDebuggerEntryFunctionLookupPresentUnwindVirtual
            • String ID:
            • API String ID: 1239891234-0
            • Opcode ID: fa8f028e9fcd13a2b73484911b7de9c78ca1ddcb2e97266c57a75bc76a24fdd2
            • Instruction ID: f0802e4d3a69a77f8d3c7f9e795bf066429c7251e1517ffe972d55107c3606c2
            • Opcode Fuzzy Hash: fa8f028e9fcd13a2b73484911b7de9c78ca1ddcb2e97266c57a75bc76a24fdd2
            • Instruction Fuzzy Hash: 6A318133608B81A9DB60CF65E8442BE73A4FB88754F640136EA9D87B99EF3CD545CB00
            APIs
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: FileFindFirst_invalid_parameter_noinfo
            • String ID:
            • API String ID: 2227656907-0
            • Opcode ID: 68b5c0f69695cefe4d2b1cac7d4572eefde3aab897b1af24f4d9a3b1cd0a2181
            • Instruction ID: 34985d2652c28801194a078a52200528839f5f7a3713f398d8b285d1a00eae4c
            • Opcode Fuzzy Hash: 68b5c0f69695cefe4d2b1cac7d4572eefde3aab897b1af24f4d9a3b1cd0a2181
            • Instruction Fuzzy Hash: B1B1D823B5869251EA60DBA5E4002BA6395FF48BD4F644231EE5D9BBCFEF3CE4418300
            APIs
            Strings
            • ERROR : Unable to initialize critical section in CAtlBaseModule, xrefs: 00007FF600ADC8AF
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: DebugDebuggerErrorLastOutputPresentString
            • String ID: ERROR : Unable to initialize critical section in CAtlBaseModule
            • API String ID: 389471666-631824599
            • Opcode ID: 6ee909605b01ed677f0d258b83eb54f87cb27d04152a024ec70f484db7e8edcc
            • Instruction ID: 74ac651e01b1d61ff9adeb9b66627f24b8a2a3fdafe54fc982272c6ef43ce277
            • Opcode Fuzzy Hash: 6ee909605b01ed677f0d258b83eb54f87cb27d04152a024ec70f484db7e8edcc
            • Instruction Fuzzy Hash: AB112833A14B42AAF7449B62D6547B932A4FF44355F644135CA4E83B9AEF7CE074C710
            APIs
            Memory Dump Source
            • Source File: 00000000.00000003.2179097870.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
            • Associated: 00000000.00000003.2091618542.00000001800A4000.00000004.00001000.00020000.00000000.sdmpDownload File
            • Associated: 00000000.00000003.2179082431.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
            • Associated: 00000000.00000003.2179132878.000000018006A000.00000002.00001000.00020000.00000000.sdmpDownload File
            • Associated: 00000000.00000003.2179132878.0000000180077000.00000002.00001000.00020000.00000000.sdmpDownload File
            • Associated: 00000000.00000003.2179183910.000000018009C000.00000004.00001000.00020000.00000000.sdmpDownload File
            • Associated: 00000000.00000003.2179196781.000000018009F000.00000002.00001000.00020000.00000000.sdmpDownload File
            • Associated: 00000000.00000003.3868202191.0000000180088000.00000002.00001000.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_3_180000000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: CurrentTime$CounterFilePerformanceProcessQuerySystemThread
            • String ID:
            • API String ID: 2933794660-0
            • Opcode ID: f43c5c384dd62e127aff23c3300620b55bf120581340eb66dff6dc6593971a8f
            • Instruction ID: 335ea6a06d10f4d8781396ceb673bb2c692713a1181adefcbf3dbf2c25eb2b35
            • Opcode Fuzzy Hash: f43c5c384dd62e127aff23c3300620b55bf120581340eb66dff6dc6593971a8f
            • Instruction Fuzzy Hash: A6111832714F088AFB409B60E8543A933A4F75D798F444E21FA6D867A4EF78C2A88340
            APIs
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: memcpy_s
            • String ID:
            • API String ID: 1502251526-0
            • Opcode ID: a3a34dc7f104a5757306e0e4006adbba08ef9a00a3e13a0073f806107d450ba3
            • Instruction ID: 7c5b9e8f46d8d3b80e5eccaa9c55165236a297c2fde447fe034caf53b56c7865
            • Opcode Fuzzy Hash: a3a34dc7f104a5757306e0e4006adbba08ef9a00a3e13a0073f806107d450ba3
            • Instruction Fuzzy Hash: D9C1E673B296C697EB24CF19A04866AB791F784B84F548134DB4A83B49EF3CE801CB40
            APIs
              • Part of subcall function 00007FF600AEED10: GetLastError.KERNEL32(?,?,?,00007FF600AF7113,?,?,?,00007FF600AEF444,?,?,?,00007FF600AE843F,?,?,?,00007FF600AE66E3), ref: 00007FF600AEED1F
              • Part of subcall function 00007FF600AEED10: FlsGetValue.KERNEL32(?,?,?,00007FF600AF7113,?,?,?,00007FF600AEF444,?,?,?,00007FF600AE843F,?,?,?,00007FF600AE66E3), ref: 00007FF600AEED34
              • Part of subcall function 00007FF600AEED10: SetLastError.KERNEL32(?,?,?,00007FF600AF7113,?,?,?,00007FF600AEF444,?,?,?,00007FF600AE843F,?,?,?,00007FF600AE66E3), ref: 00007FF600AEEDBF
              • Part of subcall function 00007FF600AEED10: FlsSetValue.KERNEL32(?,?,?,00007FF600AF7113,?,?,?,00007FF600AEF444,?,?,?,00007FF600AE843F,?,?,?,00007FF600AE66E3), ref: 00007FF600AEED55
            • GetLocaleInfoW.KERNEL32 ref: 00007FF600AF7EAC
              • Part of subcall function 00007FF600AF3FCC: _invalid_parameter_noinfo.LIBCMT ref: 00007FF600AF3FE9
            • GetLocaleInfoW.KERNEL32 ref: 00007FF600AF7EF5
              • Part of subcall function 00007FF600AF3FCC: _invalid_parameter_noinfo.LIBCMT ref: 00007FF600AF4042
            • GetLocaleInfoW.KERNEL32 ref: 00007FF600AF7FBD
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: InfoLocale$ErrorLastValue_invalid_parameter_noinfo
            • String ID:
            • API String ID: 1791019856-0
            • Opcode ID: 47a608bb907d4de4290f427b339ca80dcd83f241fa12a378f23bb4634d50531a
            • Instruction ID: eb66dd609985536e76dd692a927b8f364e9b90ca50467adbc69f3fd253778ad8
            • Opcode Fuzzy Hash: 47a608bb907d4de4290f427b339ca80dcd83f241fa12a378f23bb4634d50531a
            • Instruction Fuzzy Hash: 5D619A33A48642AAEB348F61E4402BD73A9EB84B40F608135DB9EC779ADF3CE555C700
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: InfoLocale
            • String ID: GetLocaleInfoEx
            • API String ID: 2299586839-2904428671
            • Opcode ID: 3b61ae466ef5758e0e9e9450f631c2e40b05ac649b5573246797acb4bca5b173
            • Instruction ID: 3a7b6df51792e41a7053ffe8af4b2fe38030909e85774577d0e78fa418e34d07
            • Opcode Fuzzy Hash: 3b61ae466ef5758e0e9e9450f631c2e40b05ac649b5573246797acb4bca5b173
            • Instruction Fuzzy Hash: 3E01A222B08A81E5E7009B96B4401B6B764AF85BD0F684035DF4D83B5ECF3DD9418340
            APIs
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: ExceptionRaise_clrfp
            • String ID:
            • API String ID: 15204871-0
            • Opcode ID: 122b1925bd55db41e804c5b079ebde0f01de1123b2666aa23313b6dae26d6c44
            • Instruction ID: c09a788b1ad0cc8be4651bf46b07ff56d4be0f535c4626a99dd8972d66841538
            • Opcode Fuzzy Hash: 122b1925bd55db41e804c5b079ebde0f01de1123b2666aa23313b6dae26d6c44
            • Instruction Fuzzy Hash: 87B15B73604B898BEB15CF29C84636C7BA4F784B88F258931DA5D877A9CF39D552C700
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID:
            • String ID: $
            • API String ID: 0-227171996
            • Opcode ID: 551e646fd59d23c1ee018d61c48a67f2a52f50f5278fc9195615cae8faf456cd
            • Instruction ID: 9b51804ecfe7763f9c5d7b73b74a69d397364aab498f9e0aba6dc0fe59263e88
            • Opcode Fuzzy Hash: 551e646fd59d23c1ee018d61c48a67f2a52f50f5278fc9195615cae8faf456cd
            • Instruction Fuzzy Hash: 2BE1A277A0C6C292EB688E29805057D33A0FF55B88F345235DA5E8779AFF2DE851C740
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID:
            • String ID: e+000$gfff
            • API String ID: 0-3030954782
            • Opcode ID: a347cb712251c494c0ac76841d0ca458a250c6be9a7c463d0ead6691c264c289
            • Instruction ID: 00bf89e1f7bd4e7dd7885253954ca08ebf7bf62aa25ed4c1d9ada2ebad8a73f1
            • Opcode Fuzzy Hash: a347cb712251c494c0ac76841d0ca458a250c6be9a7c463d0ead6691c264c289
            • Instruction Fuzzy Hash: 04515963B182C69AE7258E35E8107697B91E745B94F68C231CB9C8BBCBEF7DD4448700
            APIs
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: Info
            • String ID:
            • API String ID: 1807457897-0
            • Opcode ID: 773e53d09e5455f04dc57cd524f4ca394a315c5928bf5f5768ba6214c405212f
            • Instruction ID: 9e740e8b8b24e01937e74c8ad32dcd117f54d7d7dec1a5555c2cf7f63e7b0a33
            • Opcode Fuzzy Hash: 773e53d09e5455f04dc57cd524f4ca394a315c5928bf5f5768ba6214c405212f
            • Instruction Fuzzy Hash: CA127A23A08BC196E751CF2895543F973A4FB69748F259235EA9D87797EF38E184C300
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID:
            • String ID:
            • API String ID:
            • Opcode ID: e22158b38decd8d90c74f2f99d25a665006446744f2e1b5a41cef00b0dd0ad41
            • Instruction ID: 5c07785a6599f1130f4c1a50e5bb61ea483c4ddc3a018828b45c76d1cfe5f045
            • Opcode Fuzzy Hash: e22158b38decd8d90c74f2f99d25a665006446744f2e1b5a41cef00b0dd0ad41
            • Instruction Fuzzy Hash: 0CE13D33A04B8196E720DBA1E4416FE67A4FB94788F504636DF9D93B9AEF78D245C300
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID:
            • String ID: [RO] %ld bytes
            • API String ID: 0-772938740
            • Opcode ID: 4874844c38418d14ede67d35d8ec1f57646d452b183219fb2a06a3d7a21df842
            • Instruction ID: fbbcdd6a7c9dcc37e7c72026b65451132410bebde90855fe5e5658d7d56503f5
            • Opcode Fuzzy Hash: 4874844c38418d14ede67d35d8ec1f57646d452b183219fb2a06a3d7a21df842
            • Instruction Fuzzy Hash: 0542AC336093C59FC328CF28E4406AE7BA0F755B48F148539DB8A87B4ADB38E955CB51
            APIs
              • Part of subcall function 00007FF600AEED10: GetLastError.KERNEL32(?,?,?,00007FF600AF7113,?,?,?,00007FF600AEF444,?,?,?,00007FF600AE843F,?,?,?,00007FF600AE66E3), ref: 00007FF600AEED1F
              • Part of subcall function 00007FF600AEED10: FlsGetValue.KERNEL32(?,?,?,00007FF600AF7113,?,?,?,00007FF600AEF444,?,?,?,00007FF600AE843F,?,?,?,00007FF600AE66E3), ref: 00007FF600AEED34
              • Part of subcall function 00007FF600AEED10: SetLastError.KERNEL32(?,?,?,00007FF600AF7113,?,?,?,00007FF600AEF444,?,?,?,00007FF600AE843F,?,?,?,00007FF600AE66E3), ref: 00007FF600AEEDBF
              • Part of subcall function 00007FF600AEED10: FlsSetValue.KERNEL32(?,?,?,00007FF600AF7113,?,?,?,00007FF600AEF444,?,?,?,00007FF600AE843F,?,?,?,00007FF600AE66E3), ref: 00007FF600AEED55
            • GetLocaleInfoW.KERNEL32 ref: 00007FF600AF80F0
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: ErrorLastValue$InfoLocale
            • String ID:
            • API String ID: 673564084-0
            • Opcode ID: fd4313f3ed39529f0e214070d5eb9b22141959494d17c08f529f82dcba2f0cc7
            • Instruction ID: e0aa62d035172697d3d496896697b372ffeb036f4c2e8087fbb9bb8325d5af31
            • Opcode Fuzzy Hash: fd4313f3ed39529f0e214070d5eb9b22141959494d17c08f529f82dcba2f0cc7
            • Instruction Fuzzy Hash: C5318033B4868296EB24DB61D4413BA73A4FB88780F648635DB8DC738ADF3CE5028700
            APIs
              • Part of subcall function 00007FF600AEED10: GetLastError.KERNEL32(?,?,?,00007FF600AF7113,?,?,?,00007FF600AEF444,?,?,?,00007FF600AE843F,?,?,?,00007FF600AE66E3), ref: 00007FF600AEED1F
              • Part of subcall function 00007FF600AEED10: FlsGetValue.KERNEL32(?,?,?,00007FF600AF7113,?,?,?,00007FF600AEF444,?,?,?,00007FF600AE843F,?,?,?,00007FF600AE66E3), ref: 00007FF600AEED34
              • Part of subcall function 00007FF600AEED10: SetLastError.KERNEL32(?,?,?,00007FF600AF7113,?,?,?,00007FF600AEF444,?,?,?,00007FF600AE843F,?,?,?,00007FF600AE66E3), ref: 00007FF600AEEDBF
            • EnumSystemLocalesW.KERNEL32(?,?,?,00007FF600AF84C7,00000000,00000092,?,?,00000000,?,?,00007FF600AED771), ref: 00007FF600AF7D76
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: ErrorLast$EnumLocalesSystemValue
            • String ID:
            • API String ID: 3029459697-0
            • Opcode ID: 15ac7d5427dd9fc22c9c1f247fbd5354b0666d540418ec543f069a2b87512e20
            • Instruction ID: 4b79002df2861675a470c8b63bcff065dad7673cb2b481f2e7e2eff0289ea12c
            • Opcode Fuzzy Hash: 15ac7d5427dd9fc22c9c1f247fbd5354b0666d540418ec543f069a2b87512e20
            • Instruction Fuzzy Hash: 1F112463A0C6459AEB248F55D0806BC77A5FB80FA0FA48135C629833CADE38D6D1CB40
            APIs
              • Part of subcall function 00007FF600AEED10: GetLastError.KERNEL32(?,?,?,00007FF600AF7113,?,?,?,00007FF600AEF444,?,?,?,00007FF600AE843F,?,?,?,00007FF600AE66E3), ref: 00007FF600AEED1F
              • Part of subcall function 00007FF600AEED10: FlsGetValue.KERNEL32(?,?,?,00007FF600AF7113,?,?,?,00007FF600AEF444,?,?,?,00007FF600AE843F,?,?,?,00007FF600AE66E3), ref: 00007FF600AEED34
              • Part of subcall function 00007FF600AEED10: SetLastError.KERNEL32(?,?,?,00007FF600AF7113,?,?,?,00007FF600AEF444,?,?,?,00007FF600AE843F,?,?,?,00007FF600AE66E3), ref: 00007FF600AEEDBF
            • GetLocaleInfoW.KERNEL32(?,?,?,00007FF600AF803A), ref: 00007FF600AF82C7
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: ErrorLast$InfoLocaleValue
            • String ID:
            • API String ID: 3796814847-0
            • Opcode ID: 02c8055d8d650acd3e8a74c68ff88f338c75fb4c0e3c19cf7d436b4e0503b1ee
            • Instruction ID: 1d0af5610975a245954734123006acd69f4b6358a31ccc4814063d38ffc8fec5
            • Opcode Fuzzy Hash: 02c8055d8d650acd3e8a74c68ff88f338c75fb4c0e3c19cf7d436b4e0503b1ee
            • Instruction Fuzzy Hash: 13115C33F5855293E7748765F04067E6264EB40BA4F748331D66D8B7DAEF2DD8818300
            APIs
              • Part of subcall function 00007FF600AEED10: GetLastError.KERNEL32(?,?,?,00007FF600AF7113,?,?,?,00007FF600AEF444,?,?,?,00007FF600AE843F,?,?,?,00007FF600AE66E3), ref: 00007FF600AEED1F
              • Part of subcall function 00007FF600AEED10: FlsGetValue.KERNEL32(?,?,?,00007FF600AF7113,?,?,?,00007FF600AEF444,?,?,?,00007FF600AE843F,?,?,?,00007FF600AE66E3), ref: 00007FF600AEED34
              • Part of subcall function 00007FF600AEED10: SetLastError.KERNEL32(?,?,?,00007FF600AF7113,?,?,?,00007FF600AEF444,?,?,?,00007FF600AE843F,?,?,?,00007FF600AE66E3), ref: 00007FF600AEEDBF
            • EnumSystemLocalesW.KERNEL32(?,?,?,00007FF600AF8483,00000000,00000092,?,?,00000000,?,?,00007FF600AED771), ref: 00007FF600AF7E26
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: ErrorLast$EnumLocalesSystemValue
            • String ID:
            • API String ID: 3029459697-0
            • Opcode ID: 5727eb7e919169bab7f3b731904feba02bf0749f82d0e8f83876c19ff70cc26c
            • Instruction ID: 9c8f974e1de1b64bb0c00300534a8bc1ec03b0f11d0509c3b9a86da40d1ababd
            • Opcode Fuzzy Hash: 5727eb7e919169bab7f3b731904feba02bf0749f82d0e8f83876c19ff70cc26c
            • Instruction Fuzzy Hash: 2901F573F0C2815AE7204B95E4407BD76A5EF407A0FA48232D228873CEDFBC98858700
            APIs
            • EnumSystemLocalesW.KERNEL32(?,?,00000000,00007FF600AF0F7F,?,?,?,?,?,?,?,?,00000000,00007FF600AF7328), ref: 00007FF600AF0B27
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: EnumLocalesSystem
            • String ID:
            • API String ID: 2099609381-0
            • Opcode ID: 0f058bcf8847595df1816a53f4d47a97cac47f7a866e7bb19b671d0c18a11263
            • Instruction ID: 1cd469a2b5ca652b6befd6234cf4f0cc2c5dc4e0a38dadb3f0b7f09d86206ab4
            • Opcode Fuzzy Hash: 0f058bcf8847595df1816a53f4d47a97cac47f7a866e7bb19b671d0c18a11263
            • Instruction Fuzzy Hash: 8DF03C72B08B41A3E704DB55E8905A96366FB997C0FA48035EA5ED736ADF3CE460C340
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID:
            • String ID: gfffffff
            • API String ID: 0-1523873471
            • Opcode ID: 91511e75055787009b36da5e0b5904dd2b35cdbec92fe664924b5d59d9c2ed42
            • Instruction ID: 54ae7dabb6a1ccdf0bcb246c28db0c28a6a84e82e2f671fa400318392c3709d2
            • Opcode Fuzzy Hash: 91511e75055787009b36da5e0b5904dd2b35cdbec92fe664924b5d59d9c2ed42
            • Instruction Fuzzy Hash: 97A15863B097C69BEB21CF29A4107A97B91EB50B84F258132DE4D8779AFE3DD502C701
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID:
            • String ID:
            • API String ID: 0-3916222277
            • Opcode ID: 5fb6afdc90124b9ccfbc1fc7428f51e6266c183c57cc2358b46b47bb293d3794
            • Instruction ID: 14b278ff459b05d1ed8b697310997947ab9d65f51e9bd38451c713f41b327b78
            • Opcode Fuzzy Hash: 5fb6afdc90124b9ccfbc1fc7428f51e6266c183c57cc2358b46b47bb293d3794
            • Instruction Fuzzy Hash: 73B16C73A0878595EB648F29C05427C3BB0F769B88F385536CA4E8739AEF39D841D705
            APIs
            • GetLastError.KERNEL32 ref: 00007FF600AF2A89
              • Part of subcall function 00007FF600AF0A28: HeapAlloc.KERNEL32(?,?,00000000,00007FF600AEEEEA,?,?,00002C1F5E3C02FD,00007FF600AE8DA5,?,?,?,?,00007FF600AF27E6,?,?,00000000), ref: 00007FF600AF0A7D
              • Part of subcall function 00007FF600AEE95C: RtlFreeHeap.NTDLL(?,?,?,00007FF600AF6862,?,?,?,00007FF600AF6BDF,?,?,00000000,00007FF600AF7025,?,?,?,00007FF600AF6F57), ref: 00007FF600AEE972
              • Part of subcall function 00007FF600AEE95C: GetLastError.KERNEL32(?,?,?,00007FF600AF6862,?,?,?,00007FF600AF6BDF,?,?,00000000,00007FF600AF7025,?,?,?,00007FF600AF6F57), ref: 00007FF600AEE97C
              • Part of subcall function 00007FF600AFA24C: _invalid_parameter_noinfo.LIBCMT ref: 00007FF600AFA27F
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: ErrorHeapLast$AllocFree_invalid_parameter_noinfo
            • String ID:
            • API String ID: 916656526-0
            • Opcode ID: 211458dcc4182629a49dfa16bd233c2fd01fa5b79e8a7313d1c8d1c4e015e553
            • Instruction ID: 0c07d5449f7fa827eb89f3bcf2ea84a99925c151895e55bec758b63c4fe2db61
            • Opcode Fuzzy Hash: 211458dcc4182629a49dfa16bd233c2fd01fa5b79e8a7313d1c8d1c4e015e553
            • Instruction Fuzzy Hash: F441B823B4964361F670AE9668517BAA788BF957C0F644535EE8DC778FEE3CE4008700
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID:
            • String ID:
            • API String ID:
            • Opcode ID: f9d3e26cd520c0d7484bca21c75386a0081201fe8f2cf936fcf25e5b7a4aa551
            • Instruction ID: a7a30075035b44d613dd04ddede2e682b0dd088178aaa4cd19c1d5e17e16c0bf
            • Opcode Fuzzy Hash: f9d3e26cd520c0d7484bca21c75386a0081201fe8f2cf936fcf25e5b7a4aa551
            • Instruction Fuzzy Hash: 6722CEB7B3805047D36DCB1DEC52FA97692B7A5348748A02CFA07C3F45EA3DEA458A44
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID:
            • String ID:
            • API String ID:
            • Opcode ID: 2dbab6f601d912f7832fe87e6cb8010b159b99cec89eaaed4f22644e13967388
            • Instruction ID: 61ec0c2ab39dc35306d2240668fe5313624ac844d8edcde5832e7c5fda5ab42a
            • Opcode Fuzzy Hash: 2dbab6f601d912f7832fe87e6cb8010b159b99cec89eaaed4f22644e13967388
            • Instruction Fuzzy Hash: 6CC1ED73B186919BDB09CF26E95056DB792BBC4BD0B65C135DE4A47B89EE3CD801CB00
            Memory Dump Source
            • Source File: 00000000.00000003.2179097870.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
            • Associated: 00000000.00000003.2091618542.00000001800A4000.00000004.00001000.00020000.00000000.sdmpDownload File
            • Associated: 00000000.00000003.2179082431.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
            • Associated: 00000000.00000003.2179132878.000000018006A000.00000002.00001000.00020000.00000000.sdmpDownload File
            • Associated: 00000000.00000003.2179132878.0000000180077000.00000002.00001000.00020000.00000000.sdmpDownload File
            • Associated: 00000000.00000003.2179183910.000000018009C000.00000004.00001000.00020000.00000000.sdmpDownload File
            • Associated: 00000000.00000003.2179196781.000000018009F000.00000002.00001000.00020000.00000000.sdmpDownload File
            • Associated: 00000000.00000003.3868202191.0000000180088000.00000002.00001000.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_3_180000000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID:
            • String ID:
            • API String ID:
            • Opcode ID: 872fd2783583b3cd762f827bdf0a68bc7e37a8f8e8274d1aa2e2fae5feacd2de
            • Instruction ID: 1cf1c2553b0555ee6ea91e657742496aa9e8a1338f503d70c1e054abea576052
            • Opcode Fuzzy Hash: 872fd2783583b3cd762f827bdf0a68bc7e37a8f8e8274d1aa2e2fae5feacd2de
            • Instruction Fuzzy Hash: 11E11E23A2ABD085E7239F3D44097982B919FE37B4F5EC309FA75267E2E7258149C311
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID:
            • String ID:
            • API String ID:
            • Opcode ID: 3e5dc7f97a53f24eb071f4a4c5281cd4cfcae3ea760a8a1df74637965631acf6
            • Instruction ID: f56ffc6484b203fa1afb2221d9f94248afa52c73bcd378e83e666e686666e70a
            • Opcode Fuzzy Hash: 3e5dc7f97a53f24eb071f4a4c5281cd4cfcae3ea760a8a1df74637965631acf6
            • Instruction Fuzzy Hash: BAD1C123A0C683A6EBA9CE29945027D27A0EB45B48F345235DE4D877DAFF3DE841D740
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: ErrorLastNameTranslate$CodePageValidValue_invalid_parameter_noinfo
            • String ID:
            • API String ID: 4023145424-0
            • Opcode ID: 21e64ea7c375e93a6d3691ec49e9bdd76ef4fc5f4d0d1dcdba5dc2295bd766ac
            • Instruction ID: 2441e02af497bd6e0e547dd0067f7b30d741c825ec54d30773a8b932eef76ec5
            • Opcode Fuzzy Hash: 21e64ea7c375e93a6d3691ec49e9bdd76ef4fc5f4d0d1dcdba5dc2295bd766ac
            • Instruction Fuzzy Hash: E0C1C467A086C6A5EB609B6298107BA67A4FB94788F604035DE8DC7BCEFF3CD545C700
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: ErrorLast$Value_invalid_parameter_noinfo
            • String ID:
            • API String ID: 1500699246-0
            • Opcode ID: d774b1686d68766547d9d0affe500116b26f703ac014ee2f743871d76f2ddb8c
            • Instruction ID: 7c41158baa6a6c03a7491303c94e71bc0671e429f89aa155313221b46756df60
            • Opcode Fuzzy Hash: d774b1686d68766547d9d0affe500116b26f703ac014ee2f743871d76f2ddb8c
            • Instruction Fuzzy Hash: 73B1E223A4C646A2EB64DFA5D411ABD33A5EB84B88F604231DA49C77CEDF3CE541C740
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID:
            • String ID:
            • API String ID:
            • Opcode ID: 9cf611d711d996cef35472e7504a5935af8ed11963d98eb5a37693ba2286e55b
            • Instruction ID: 477f3fb14dac67de2e68da22f1d2084bd206724aafa261768b462f1b57cabb80
            • Opcode Fuzzy Hash: 9cf611d711d996cef35472e7504a5935af8ed11963d98eb5a37693ba2286e55b
            • Instruction Fuzzy Hash: 3DB190739187859AEB648F29C05027C3BA0E769B88F391935CB4D8739EEF39E841C705
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: _invalid_parameter_noinfo
            • String ID:
            • API String ID: 3215553584-0
            • Opcode ID: c771e48c11f0d915594974b4bba5b1cef921b70c42e7a63ac30c42f7e56c6b99
            • Instruction ID: 8b5bb2feb1fadbd890fe013575d0c871ca0e632d53decdb7122baab9adbdd6d4
            • Opcode Fuzzy Hash: c771e48c11f0d915594974b4bba5b1cef921b70c42e7a63ac30c42f7e56c6b99
            • Instruction Fuzzy Hash: 8881C373A14A9196EB60DF65D4953BD23A0FB84BA8F204636EE1DC779AEF38D0418300
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID:
            • String ID:
            • API String ID:
            • Opcode ID: c06df77d5c41abf0c9103d11d2ff5cfa312f76e721c7628385afe64dabe37a34
            • Instruction ID: 634a90144edc17c0c11e0b4edf5538346de0850ffc07b13bed2a83c541accdcf
            • Opcode Fuzzy Hash: c06df77d5c41abf0c9103d11d2ff5cfa312f76e721c7628385afe64dabe37a34
            • Instruction Fuzzy Hash: 4481F173A4878196EBB4CF59A44077AAA95FB85794F204235DB8D83B8FDF3DD5408B00
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID:
            • String ID:
            • API String ID:
            • Opcode ID: f6f6a1a1a1cf9baf0de81f1e4df80e775a01d7d2970379cd065fadcfc056c7f6
            • Instruction ID: 63f8fdb2f6266ed99275b4f3344e951384713ad0ddfbaabca5d622bf0b0e6bbf
            • Opcode Fuzzy Hash: f6f6a1a1a1cf9baf0de81f1e4df80e775a01d7d2970379cd065fadcfc056c7f6
            • Instruction Fuzzy Hash: 6661F863B18B8952DE208B19E4416B97360F759780F645332EF9E87B59EF3DE280C340
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID:
            • String ID:
            • API String ID:
            • Opcode ID: 8e69dfdcc94a0aa650623f7423aa354004c1f2fa01d5c1268249020d4c21f447
            • Instruction ID: 78c3f58421dc1656ec569486a473e2fb323770637bcced58c5ee3455d9e0d61b
            • Opcode Fuzzy Hash: 8e69dfdcc94a0aa650623f7423aa354004c1f2fa01d5c1268249020d4c21f447
            • Instruction Fuzzy Hash: 8B514777E14A9196E7648F39E05423837A0EB44B5CF344231DA4D9779AEF3AE853C740
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID:
            • String ID:
            • API String ID:
            • Opcode ID: 68a3f5aab59b2fac328bd6ba34d5b1cd1fa94c6914f84dc4a79da3b9d8ff9a98
            • Instruction ID: 139aca4dc8ac8c7d9212f6c2a75fa83a1d32a83a3a4ffdde6eda2b45ecd27eff
            • Opcode Fuzzy Hash: 68a3f5aab59b2fac328bd6ba34d5b1cd1fa94c6914f84dc4a79da3b9d8ff9a98
            • Instruction Fuzzy Hash: 04519777E18E9192E7648B39D05026837A0EB45BACF344131DE4D9779AEF3AE843C740
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID:
            • String ID:
            • API String ID:
            • Opcode ID: 27099d1c67046ba5536a5c52bb1b19252402c8bb4a5167aa336477e7b6d5f807
            • Instruction ID: adc29118fe33157fc0fbd7e41fa55593235a301b5e44df58c40b8c71615c22c3
            • Opcode Fuzzy Hash: 27099d1c67046ba5536a5c52bb1b19252402c8bb4a5167aa336477e7b6d5f807
            • Instruction Fuzzy Hash: B5516137E18E9196E7248B39E05422837A0EB44B6CF794131CE4D9779AEF3AE853C740
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID:
            • String ID:
            • API String ID:
            • Opcode ID: f6a3dccb135ddd09f63c505db29ff29986bf9dd63497299e7c799fac6b959aa4
            • Instruction ID: 0b97edaa6040f2ba3bd9461783150a9ff29867b05e77967d2ef8764fe4bfbd4b
            • Opcode Fuzzy Hash: f6a3dccb135ddd09f63c505db29ff29986bf9dd63497299e7c799fac6b959aa4
            • Instruction Fuzzy Hash: DF517477E18A9196E7648B39E04423827A1EB54B5CF344131CE4D977DAEF3AE882C740
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID:
            • String ID:
            • API String ID:
            • Opcode ID: e46230d8c0bb23a9b26f12389beaf27d8e9063d4bba2e4d98de2a57eaa924be5
            • Instruction ID: 6b42d5bf8fa15991c59ce803bdf1b0d14ec2e927709fac298d38b5246b0e13a5
            • Opcode Fuzzy Hash: e46230d8c0bb23a9b26f12389beaf27d8e9063d4bba2e4d98de2a57eaa924be5
            • Instruction Fuzzy Hash: D2516037E18A9196E7648B39E04437837A0EB48B6CF344131DE4D9779AEF3AE842D740
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID:
            • String ID:
            • API String ID:
            • Opcode ID: db363646d287334b7a31293e9082935613ba5dde14aee32d187fc7345eaa1eeb
            • Instruction ID: 1cce5ae2ad1f5dc4b3db639247ce1465ee739c6bf8fae7a4062ccf3e73106190
            • Opcode Fuzzy Hash: db363646d287334b7a31293e9082935613ba5dde14aee32d187fc7345eaa1eeb
            • Instruction Fuzzy Hash: 3E516437E18A9196E7249B39E04472827A0EB45B5DF344131DE4D9779AEF3AEC42C780
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: ErrorFreeHeapLast
            • String ID:
            • API String ID: 485612231-0
            • Opcode ID: 992bdeb28752ac81bb160f4e9466717d9b532df2d17ea574ae2dd87a94b6b211
            • Instruction ID: d77b529ce38a5bec26fe0741e16164340a6f3d32cab516bc6eb9a425b4fac95b
            • Opcode Fuzzy Hash: 992bdeb28752ac81bb160f4e9466717d9b532df2d17ea574ae2dd87a94b6b211
            • Instruction Fuzzy Hash: 8141E573714A9591EF08CF6AD9241A973A1BB88FD0B599032EE0DD7B59EF3DD4428340
            Memory Dump Source
            • Source File: 00000000.00000003.2179097870.0000000180001000.00000020.00001000.00020000.00000000.sdmp, Offset: 0000000180000000, based on PE: true
            • Associated: 00000000.00000003.2091618542.00000001800A4000.00000004.00001000.00020000.00000000.sdmpDownload File
            • Associated: 00000000.00000003.2179082431.0000000180000000.00000004.00001000.00020000.00000000.sdmpDownload File
            • Associated: 00000000.00000003.2179132878.000000018006A000.00000002.00001000.00020000.00000000.sdmpDownload File
            • Associated: 00000000.00000003.2179132878.0000000180077000.00000002.00001000.00020000.00000000.sdmpDownload File
            • Associated: 00000000.00000003.2179183910.000000018009C000.00000004.00001000.00020000.00000000.sdmpDownload File
            • Associated: 00000000.00000003.2179196781.000000018009F000.00000002.00001000.00020000.00000000.sdmpDownload File
            • Associated: 00000000.00000003.3868202191.0000000180088000.00000002.00001000.00020000.00000000.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_3_180000000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID:
            • String ID:
            • API String ID:
            • Opcode ID: a7410739455344d3f1b4380a3079d3f807bb5113f299baa345570bc9df7def40
            • Instruction ID: af2ea3f49d7b04ca094969413a2835b0cf2eec1197b490f61ded8962570c81e9
            • Opcode Fuzzy Hash: a7410739455344d3f1b4380a3079d3f807bb5113f299baa345570bc9df7def40
            • Instruction Fuzzy Hash: B2F0E5617057099DFEEBC059DE293E22141870C7E7F0CA134ED4E462D5E85E99A88250
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID:
            • String ID:
            • API String ID:
            • Opcode ID: 9500c7797480eaac07bce270d35ebf5893055aa53205c196292c9b063e5a007a
            • Instruction ID: 3daab7460f454fd132681f402dc7a8385b6cfc7d19a9612cc5fc430018b52409
            • Opcode Fuzzy Hash: 9500c7797480eaac07bce270d35ebf5893055aa53205c196292c9b063e5a007a
            • Instruction Fuzzy Hash: 6AA0022394CD43F4E604DB40E95413433B4FFA5700B6D0132C41ECA26A9F3DB540D355
            APIs
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: Event$Message$Reset$CloseCriticalErrorLastPeekSectionThread$CurrentDispatchEnterHandleLeaveMultipleObjectsSwitchTranslateWaitclosesocketsendshutdown
            • String ID:
            • API String ID: 4058177064-0
            • Opcode ID: d4a00dac0fba48dd619eb6ba1b780ae101c1c81bf132304460c16c28b79e9ffb
            • Instruction ID: 78fec828df55a837036574ad6b8532c6c904982d5caea430fa4d248fc62476d3
            • Opcode Fuzzy Hash: d4a00dac0fba48dd619eb6ba1b780ae101c1c81bf132304460c16c28b79e9ffb
            • Instruction Fuzzy Hash: 05917E33B08A82A7E7589B25D5546B973A4FF48B40F214935CB6EC379ACF38E4A4C700
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: lstrcatlstrlen$CreateEnvironmentExpandProcessStringslstrcpywsprintf
            • String ID: "%1$%s\shell\open\command$WinSta0\Default$h
            • API String ID: 1783372451-551013563
            • Opcode ID: eac3ac33eed5e84588de99090fdd2237e456d1a0e0148cdd7090aa018ec508cf
            • Instruction ID: 977adc18b242adf8db76e283dfd7ccdf08addf353f2c6a5218a39b7acb7cfc02
            • Opcode Fuzzy Hash: eac3ac33eed5e84588de99090fdd2237e456d1a0e0148cdd7090aa018ec508cf
            • Instruction Fuzzy Hash: EB615F33A18B82A5EB20DB61D8406FE3365FB88748F644136DA4E96B9EEF7CD544C740
            APIs
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: ByteCharEventMultiWidelstrlensetsockopt$CreateErrorIoctlLastSelectconnectgethostbynamehtonssocket
            • String ID:
            • API String ID: 1455939504-0
            • Opcode ID: 8e08f9f7998c143048245e45366c2262b6845e92db1a87c8a4e60d79f477c7ad
            • Instruction ID: 9e2bcc1a3d6dbb6f7becb810b1acd656594eab478222064f80455844a06272bc
            • Opcode Fuzzy Hash: 8e08f9f7998c143048245e45366c2262b6845e92db1a87c8a4e60d79f477c7ad
            • Instruction Fuzzy Hash: 39516633608B9196D724DF61E84066AB7A5FF88BA4F200235EE9E83B99CF3CD545C704
            APIs
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: std::_$Lockit$Lockit::_Lockit::~_$Concurrency::cancel_current_taskFacet_Register
            • String ID:
            • API String ID: 2081738530-0
            • Opcode ID: abf8e540b54f698cc9b45021eb612f4fee3d5b077170ba2ec9f9a82e9aa791c4
            • Instruction ID: dea25dd96e8f898f121e52ea9f73e9cc6829cdb58064e32285d98c207dacf599
            • Opcode Fuzzy Hash: abf8e540b54f698cc9b45021eb612f4fee3d5b077170ba2ec9f9a82e9aa791c4
            • Instruction Fuzzy Hash: 71516037A48A42B1EA119B15E4441B937A0FB55B90F680233DE5F837AEDF3DE442C740
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: ErrorLast$EventTimetime$EnumEventsNetworkResetSelectsend
            • String ID:
            • API String ID: 957247320-3916222277
            • Opcode ID: 2310baa555e0df77a8bcfccd4f7fd94b27c56680d13eb448f7d2580fe2531f2f
            • Instruction ID: 811d00a1de5ea7eb41843dfc039490843d1c306ac68d108197d51c6d58a88a6e
            • Opcode Fuzzy Hash: 2310baa555e0df77a8bcfccd4f7fd94b27c56680d13eb448f7d2580fe2531f2f
            • Instruction Fuzzy Hash: 99716B73A08682ABE3608F69D49476977E0FB48B48F254434CB4DC379ACF7DE4858B44
            APIs
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: CriticalSection$EnterErrorLastLeave
            • String ID:
            • API String ID: 4082018349-0
            • Opcode ID: cb0b3ee4ce24505bbac61aa70540e6acda4bbb341cea077ae408a959c4223429
            • Instruction ID: 71cb31ba803debcf697a89a17712bc47bf019dd718aeca8b0e149ff28ab5933a
            • Opcode Fuzzy Hash: cb0b3ee4ce24505bbac61aa70540e6acda4bbb341cea077ae408a959c4223429
            • Instruction Fuzzy Hash: 3961B133B08A42A6E7589B26D444A7E6365FF84B81FA24431DA1EC779ADF3CF495C700
            APIs
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: CriticalSection$EnterErrorLastLeave
            • String ID:
            • API String ID: 4082018349-0
            • Opcode ID: 31685a7c47cc355b0b84d769594d8f48275261b6e3cd822618b6b5c873848fb6
            • Instruction ID: 96012c249d5ed9d08f9bf78df26ba8e9d116494389ad54abefecdfadd94d9def
            • Opcode Fuzzy Hash: 31685a7c47cc355b0b84d769594d8f48275261b6e3cd822618b6b5c873848fb6
            • Instruction Fuzzy Hash: B131B622B0CA43A6E758AB65988C67A2355FF45B85F390530EA0EC779ACF2CF485C700
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: CloseValue$CreateDeleteOpenlstrlen
            • String ID: Software$VenNetwork
            • API String ID: 3197061591-1820303132
            • Opcode ID: b270a5905e67aa2bd04960c5a5af98d5e64a07028cd1629e036b508084a2e799
            • Instruction ID: b4e0e06779a1d08e8b17281885f5e0c108b0fc08ef4683034b8843a21ed9dff2
            • Opcode Fuzzy Hash: b270a5905e67aa2bd04960c5a5af98d5e64a07028cd1629e036b508084a2e799
            • Instruction Fuzzy Hash: 4B216F36608A4096E7108B62E84466AB765FB84BE5F544131DE4D83B69DF7CD149CB04
            APIs
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: CriticalErrorLastSection$EnterLeave
            • String ID:
            • API String ID: 2124651672-0
            • Opcode ID: daa85d6e6a81f6d236355c9ea9004f697aded8e3aa47a9236808cebcd2b51b32
            • Instruction ID: dce89721d6f9fa625eeceadb1c8cec4f1d2035188c8e7360a1c6080675151fb8
            • Opcode Fuzzy Hash: daa85d6e6a81f6d236355c9ea9004f697aded8e3aa47a9236808cebcd2b51b32
            • Instruction Fuzzy Hash: 2451BC33A086429BE764DB15E440A7D77A9FF48B81F268539DE4E8735ACF38E845C740
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: _invalid_parameter_noinfo
            • String ID: f$f$p$p$f
            • API String ID: 3215553584-1325933183
            • Opcode ID: 338c2a64cdc3021812c5b6ddca5db7159329e9a17ba8d876efc02d9e71b2fbd5
            • Instruction ID: bee14b354e3d265aa551910236cec708a876acf328cb44af7d69ca9f40bb1455
            • Opcode Fuzzy Hash: 338c2a64cdc3021812c5b6ddca5db7159329e9a17ba8d876efc02d9e71b2fbd5
            • Instruction Fuzzy Hash: 84126333A0D1C3A5FB605E14E0546B97669FB88B54FA84135E789877CEEF3CE9808B14
            APIs
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: ErrorLast$setsockopt$CreateEventResetTimerWaitable
            • String ID:
            • API String ID: 2911610646-0
            • Opcode ID: 34ebcb83ecca3e20ff49f256afc65ca9a808d404bf61d5c783bec37bfef76818
            • Instruction ID: 29666b3132a948bd5614a6912aa8d2cf35e06c965d736f9b22dd2687fa58a43a
            • Opcode Fuzzy Hash: 34ebcb83ecca3e20ff49f256afc65ca9a808d404bf61d5c783bec37bfef76818
            • Instruction Fuzzy Hash: 91519B73A05A82ABE7148F65E9147AAB3A0FB48345F200534DB4D87BA5DF7DE465CB00
            APIs
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: CriticalSection$Leave$ErrorLastTimetime$EnterEvent
            • String ID:
            • API String ID: 3019579578-0
            • Opcode ID: 4019db875c6352495a6e2a967cb07e89537093c69e3cddfa206385f108ce449b
            • Instruction ID: fd51d2384b618d7fd7801275d7396b9e1f9162597b41d11ec7052fc0cb724b2d
            • Opcode Fuzzy Hash: 4019db875c6352495a6e2a967cb07e89537093c69e3cddfa206385f108ce449b
            • Instruction Fuzzy Hash: 9A413933E08A429BE7619B65E44463EB3A5FB84754F250535EA4E83B9ADF3CF9C18700
            APIs
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: CriticalSection$EnterErrorLastLeave
            • String ID:
            • API String ID: 4082018349-0
            • Opcode ID: bf041e3c240114bd2df664f35279ad8215a3420238d0dd4b213a5f2d55893e77
            • Instruction ID: 0ffc3bf38874b83124371a21c68657eda573041f144478f1138bbe55230550a3
            • Opcode Fuzzy Hash: bf041e3c240114bd2df664f35279ad8215a3420238d0dd4b213a5f2d55893e77
            • Instruction Fuzzy Hash: 0D313B33A18942AAE7948F74D84467D33A8FF44B49F640439EA0EC679ADF3CE499C741
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: BlockFrameHandler3::Unwind$CatchExecutionHandlerIs_bad_exception_allowedSearchStatestd::bad_alloc::bad_alloc
            • String ID: csm$csm$csm
            • API String ID: 849930591-393685449
            • Opcode ID: cb5b3d42660800b6706ee9e5169d6ae77bc1ec10b54460efee445a81ffa0bcf3
            • Instruction ID: 5e7ad3bec540d092a82ea8714684db5a30afe94e0658a7a981f2164621c8e8e4
            • Opcode Fuzzy Hash: cb5b3d42660800b6706ee9e5169d6ae77bc1ec10b54460efee445a81ffa0bcf3
            • Instruction Fuzzy Hash: C5D16033A087929AEB20DB6594407AD77A0FB55798F204135EF8D97B9BEF38E191C700
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: AddressFreeLibraryProc
            • String ID: api-ms-$ext-ms-
            • API String ID: 3013587201-537541572
            • Opcode ID: c5e8058506f29389ada01458bdd8bed04f407a28a220f5367f3ecbd3c22801fb
            • Instruction ID: 9c1bbe404d08794d907a5066668ce21d2cf7747e4ca4b0f05277de2e6936f690
            • Opcode Fuzzy Hash: c5e8058506f29389ada01458bdd8bed04f407a28a220f5367f3ecbd3c22801fb
            • Instruction Fuzzy Hash: 59411663B59A02A5FA25CB56A800A762398FF45BD0F654635DD4ECB78FEF3CE4468300
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: Filelstrcatlstrlenwsprintf$CloseCreateEnvironmentExpandHandleStringsWritelstrcpy
            • String ID: %s %s
            • API String ID: 958574092-2939940506
            • Opcode ID: 9d4b93ecebe44ad3dcfc41bef5c72ffa3e96dd61b2b13565d963145b1ed2cd72
            • Instruction ID: cad3e4f0fdf290766f1c217d1826aeaa042fa7c780c619c340198664e9048886
            • Opcode Fuzzy Hash: 9d4b93ecebe44ad3dcfc41bef5c72ffa3e96dd61b2b13565d963145b1ed2cd72
            • Instruction Fuzzy Hash: 24414B23A18BC692E721CF28D9042FD2360FBA4B48F25A335DB4D56656EF39E2D5C300
            APIs
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: CriticalSection$EnterLeave$ErrorLastsend
            • String ID:
            • API String ID: 3480985631-0
            • Opcode ID: 223d6e403172c637e9da5f06492e840e62a0238e832c6a19f43c9c4cbc36de86
            • Instruction ID: f0bc6bf30c6c8f8ddce94a671ff00d31b33bba8b737aa1891301300fc185b147
            • Opcode Fuzzy Hash: 223d6e403172c637e9da5f06492e840e62a0238e832c6a19f43c9c4cbc36de86
            • Instruction Fuzzy Hash: CA416A33608B82A6E7548F26E5506AC73A4FB08F98F250535CE1E87B5ECF38E595C704
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: _invalid_parameter_noinfo
            • String ID: f$p$p
            • API String ID: 3215553584-1995029353
            • Opcode ID: 42fb3e65d0f17d18353857ebdda260012259b146ac6ef5ada1715a4ca3ec7708
            • Instruction ID: 6f97070ebb50a65e5ae411c7476f07d4fb31d3b4bc689c019875fd7a3297b0c6
            • Opcode Fuzzy Hash: 42fb3e65d0f17d18353857ebdda260012259b146ac6ef5ada1715a4ca3ec7708
            • Instruction Fuzzy Hash: 80126163A0C3D3A6FB249A15E4542BB7656FB40754FA44135E69987BCEFF3CE5808B00
            APIs
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: CriticalSection$ErrorLast$EnterLeave$CurrentThread$EventsMultipleTimerWaitWaitablesend
            • String ID:
            • API String ID: 2807917265-0
            • Opcode ID: b86a4d89a2a610e9370193a82eb041067802b0227bafa79ad6b9f02f0420e125
            • Instruction ID: a705cb47a7e345ff913f5e8fad20dc6d37cd8dd7d449397cc02d7ce1d7b88018
            • Opcode Fuzzy Hash: b86a4d89a2a610e9370193a82eb041067802b0227bafa79ad6b9f02f0420e125
            • Instruction Fuzzy Hash: 22517133A0864296EB608F259860A7933A4FF09B58F251A35DE2DC77DEDF38E8408704
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: std::_$Lockit$GetctypeGetwctypeLocinfo::_Locinfo_ctorLockit::_Lockit::~_
            • String ID: bad locale name
            • API String ID: 1386471777-1405518554
            • Opcode ID: 69cc4a8b7b19662485723bada806c81d00e2c443d81482d7207a293efd463004
            • Instruction ID: 9ca53561bb9b98608f17477122a2865f465dc1a6153891d104048c6cef457075
            • Opcode Fuzzy Hash: 69cc4a8b7b19662485723bada806c81d00e2c443d81482d7207a293efd463004
            • Instruction Fuzzy Hash: 13518823B19B81AAFB14DBB0D4512BC3370EF84748F544535DE8EA6B9ADF38E9568310
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: std::_$Lockit$GetcollLocinfo::_Locinfo_ctorLockit::_Lockit::~__invalid_parameter_noinfo_noreturn
            • String ID: bad locale name
            • API String ID: 3908275632-1405518554
            • Opcode ID: 003808105e7b261864adc6970d8c37b00b83fd0dc8e90f8d604ba696fd0a2e67
            • Instruction ID: ace6e69d0dfc6c710c5b5cd229eb5c081a06b9796db948d4730702fbfe6aec3b
            • Opcode Fuzzy Hash: 003808105e7b261864adc6970d8c37b00b83fd0dc8e90f8d604ba696fd0a2e67
            • Instruction Fuzzy Hash: 90512823B09A81A9FB10DBB0D4503BC33A5AF89748F644136DE4EA7B9EDF38D5569340
            APIs
            • LoadLibraryExW.KERNEL32(?,?,?,00007FF600AE3A7E,?,?,?,00007FF600AE3770,?,?,?,00007FF600AE03A9), ref: 00007FF600AE3851
            • GetLastError.KERNEL32(?,?,?,00007FF600AE3A7E,?,?,?,00007FF600AE3770,?,?,?,00007FF600AE03A9), ref: 00007FF600AE385F
            • LoadLibraryExW.KERNEL32(?,?,?,00007FF600AE3A7E,?,?,?,00007FF600AE3770,?,?,?,00007FF600AE03A9), ref: 00007FF600AE3889
            • FreeLibrary.KERNEL32(?,?,?,00007FF600AE3A7E,?,?,?,00007FF600AE3770,?,?,?,00007FF600AE03A9), ref: 00007FF600AE38F7
            • GetProcAddress.KERNEL32(?,?,?,00007FF600AE3A7E,?,?,?,00007FF600AE3770,?,?,?,00007FF600AE03A9), ref: 00007FF600AE3903
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: Library$Load$AddressErrorFreeLastProc
            • String ID: api-ms-
            • API String ID: 2559590344-2084034818
            • Opcode ID: bdcdafd802d049a58c0b09305f9ac5b25268f61174ed16779f6a01e1bd42f6da
            • Instruction ID: e5e61f124ed02f4ce437f6d314e194575d3725c8557fca3cf1f9f1b4f933fed9
            • Opcode Fuzzy Hash: bdcdafd802d049a58c0b09305f9ac5b25268f61174ed16779f6a01e1bd42f6da
            • Instruction Fuzzy Hash: C531B823B1AB82B5EE65DB42A40457523D4BF44BA0F690535ED1D8B39AFF3CE545C300
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: AttributesCreateErrorFileLastProcesslstrlen
            • String ID: WinSta0\Default$h
            • API String ID: 591566999-1620045033
            • Opcode ID: 870f49fa05843601a7de3c6d96955c487a9850f25a13aeef8c58cbc4c90edb6f
            • Instruction ID: 8acd34f1e2c7090886b1311ff6f5d9e3b3c44ec8462ae5cac314622f5e31dea7
            • Opcode Fuzzy Hash: 870f49fa05843601a7de3c6d96955c487a9850f25a13aeef8c58cbc4c90edb6f
            • Instruction Fuzzy Hash: 67315522A087C255D6708B55B5043BA7395FB99790F505335EA9D87B9AEF3CD0948700
            APIs
            • GetLastError.KERNEL32(?,?,?,00007FF600AF7113,?,?,?,00007FF600AEF444,?,?,?,00007FF600AE843F,?,?,?,00007FF600AE66E3), ref: 00007FF600AEED1F
            • FlsGetValue.KERNEL32(?,?,?,00007FF600AF7113,?,?,?,00007FF600AEF444,?,?,?,00007FF600AE843F,?,?,?,00007FF600AE66E3), ref: 00007FF600AEED34
            • FlsSetValue.KERNEL32(?,?,?,00007FF600AF7113,?,?,?,00007FF600AEF444,?,?,?,00007FF600AE843F,?,?,?,00007FF600AE66E3), ref: 00007FF600AEED55
            • FlsSetValue.KERNEL32(?,?,?,00007FF600AF7113,?,?,?,00007FF600AEF444,?,?,?,00007FF600AE843F,?,?,?,00007FF600AE66E3), ref: 00007FF600AEED82
            • FlsSetValue.KERNEL32(?,?,?,00007FF600AF7113,?,?,?,00007FF600AEF444,?,?,?,00007FF600AE843F,?,?,?,00007FF600AE66E3), ref: 00007FF600AEED93
            • FlsSetValue.KERNEL32(?,?,?,00007FF600AF7113,?,?,?,00007FF600AEF444,?,?,?,00007FF600AE843F,?,?,?,00007FF600AE66E3), ref: 00007FF600AEEDA4
            • SetLastError.KERNEL32(?,?,?,00007FF600AF7113,?,?,?,00007FF600AEF444,?,?,?,00007FF600AE843F,?,?,?,00007FF600AE66E3), ref: 00007FF600AEEDBF
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: Value$ErrorLast
            • String ID:
            • API String ID: 2506987500-0
            • Opcode ID: f2de6421f07b29a90cfdc6310c4a09f0568ac7a9393794dea83b72160e9ddcb3
            • Instruction ID: ca5835fafb11f5ce55491cfb22e3fd16e0f0addec2200a98a5fe8f173ee3ec91
            • Opcode Fuzzy Hash: f2de6421f07b29a90cfdc6310c4a09f0568ac7a9393794dea83b72160e9ddcb3
            • Instruction Fuzzy Hash: E5216D22A0D28362FAA8A361598517953869F887F0F740738E83EC77DFEE2CB4018300
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: ConsoleWrite$CloseCreateErrorFileHandleLast
            • String ID: CONOUT$
            • API String ID: 3230265001-3130406586
            • Opcode ID: 459cac5f161fe15dedf5efeb1a5c45af724dbddd491f92cbd2d9a7ab51bbc5e3
            • Instruction ID: 483544bb4afc4fa7d7418d2852bd4f65de50d6954e48833a773bf8dcd1ab46ff
            • Opcode Fuzzy Hash: 459cac5f161fe15dedf5efeb1a5c45af724dbddd491f92cbd2d9a7ab51bbc5e3
            • Instruction Fuzzy Hash: 48119032B58B4196E3508B92E854339B6A4FF89BE4F600234EA6EC77A9CF3CD5148744
            APIs
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: File$CloseCreateHandleMutexObjectPointerReleaseSingleWaitWritelstrlen
            • String ID:
            • API String ID: 4202892810-0
            • Opcode ID: 1770146ed1a2281a067c6a80d48e2834b530e15e6b9c6a9fb3f6106c2579b985
            • Instruction ID: 8ff4423e6bcbac6e67647aeee76df4977f6ce963e4a2dbe8461e3a21822fa864
            • Opcode Fuzzy Hash: 1770146ed1a2281a067c6a80d48e2834b530e15e6b9c6a9fb3f6106c2579b985
            • Instruction Fuzzy Hash: C511517670864296F7109B55F808776B364FF84BA4F644230EA6E437E9CF7CD4498704
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: Value$CloseDeleteOpen
            • String ID: Console$IpDatespecial
            • API String ID: 3183427449-1840232981
            • Opcode ID: 227ad8f4b06cdb6b08930102bada313d7f8b98b7889bc09013c0be248a67a942
            • Instruction ID: 403d818af4fca29162ad105b7702ba9b9ea3700375e3569a228967fbdac86dfb
            • Opcode Fuzzy Hash: 227ad8f4b06cdb6b08930102bada313d7f8b98b7889bc09013c0be248a67a942
            • Instruction Fuzzy Hash: 28015B37608E819AE7218F24EC10BA93760EB85BA5F144132CA4E83B5ADF3DD199CB04
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: Process$CommandCreateExitFileInfoLineModuleNameStartup
            • String ID:
            • API String ID: 3421218197-3916222277
            • Opcode ID: aa1260efbfd046cd4269c4db6a47a0747b5d48ad13e0b0b72107f694596a2f32
            • Instruction ID: 0f3e7bfad56261c092565f924b7bf87cf9ea9b2bae26f08133ca4a2b66175f0f
            • Opcode Fuzzy Hash: aa1260efbfd046cd4269c4db6a47a0747b5d48ad13e0b0b72107f694596a2f32
            • Instruction Fuzzy Hash: CBF01232658A8196DB608B60F84876AB3A4FB89744F500235D68E87B68DF7CC149CB00
            APIs
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: ErrorLast$recv
            • String ID:
            • API String ID: 316788870-0
            • Opcode ID: 1bfb22ba95e7e7656d2d5e0fb302539e9b3bee6e0c9b932fa958a4b538105933
            • Instruction ID: 249940902f810d9187f3e996515c7fa957d3295374d368ca501c34d9910fc615
            • Opcode Fuzzy Hash: 1bfb22ba95e7e7656d2d5e0fb302539e9b3bee6e0c9b932fa958a4b538105933
            • Instruction Fuzzy Hash: E2317233A0CA4295EB609F29E45477D63A1EF49B88F650935CA0DC739EDF3DD8848709
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: Is_bad_exception_allowedstd::bad_alloc::bad_alloc
            • String ID: csm$csm$csm
            • API String ID: 3523768491-393685449
            • Opcode ID: f0c8ce6e5c114cb55c7e972b5d7e00f12528d3fa075699b5c4d5ef1c378b05c7
            • Instruction ID: 3a2fd29174b13c6b9f23de5d31eb28822029177dbecae525034f1d663b039217
            • Opcode Fuzzy Hash: f0c8ce6e5c114cb55c7e972b5d7e00f12528d3fa075699b5c4d5ef1c378b05c7
            • Instruction Fuzzy Hash: 95E18E73A087929AE7209F74D4807AD37A0FB45B48F254136EE9D9779BEE38E581C700
            APIs
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: EventReset$Thread$CurrentErrorLastObjectSingleSwitchTimeWait_invalid_parameter_noinfotime
            • String ID:
            • API String ID: 2235205178-0
            • Opcode ID: 590f28aa241335ba61f28d79a4cf37bde6970dd5790133cda3c336355218676e
            • Instruction ID: 0415c23c03e35df748eed51320b9efab8bef59b61ffdb296bfeee9ed266c3567
            • Opcode Fuzzy Hash: 590f28aa241335ba61f28d79a4cf37bde6970dd5790133cda3c336355218676e
            • Instruction Fuzzy Hash: D4216B32A08A8196EB508F25E85426A73A4FF88B99F284531EE4DD776ACF38D4818740
            APIs
            • GetLastError.KERNEL32(?,?,00002C1F5E3C02FD,00007FF600AE8DA5,?,?,?,?,00007FF600AF27E6,?,?,00000000,00007FF600AEA69B,?,?,?), ref: 00007FF600AEEE97
            • FlsSetValue.KERNEL32(?,?,00002C1F5E3C02FD,00007FF600AE8DA5,?,?,?,?,00007FF600AF27E6,?,?,00000000,00007FF600AEA69B,?,?,?), ref: 00007FF600AEEECD
            • FlsSetValue.KERNEL32(?,?,00002C1F5E3C02FD,00007FF600AE8DA5,?,?,?,?,00007FF600AF27E6,?,?,00000000,00007FF600AEA69B,?,?,?), ref: 00007FF600AEEEFA
            • FlsSetValue.KERNEL32(?,?,00002C1F5E3C02FD,00007FF600AE8DA5,?,?,?,?,00007FF600AF27E6,?,?,00000000,00007FF600AEA69B,?,?,?), ref: 00007FF600AEEF0B
            • FlsSetValue.KERNEL32(?,?,00002C1F5E3C02FD,00007FF600AE8DA5,?,?,?,?,00007FF600AF27E6,?,?,00000000,00007FF600AEA69B,?,?,?), ref: 00007FF600AEEF1C
            • SetLastError.KERNEL32(?,?,00002C1F5E3C02FD,00007FF600AE8DA5,?,?,?,?,00007FF600AF27E6,?,?,00000000,00007FF600AEA69B,?,?,?), ref: 00007FF600AEEF37
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: Value$ErrorLast
            • String ID:
            • API String ID: 2506987500-0
            • Opcode ID: 3654d854b1b7b54d09208102c236c7adbe92e0b1e90858cb6ea83a43bfdf338d
            • Instruction ID: 23461ea51f3634669604aa84a77155602b03bd4bc0a900f8cda2b2c10d1e2a1c
            • Opcode Fuzzy Hash: 3654d854b1b7b54d09208102c236c7adbe92e0b1e90858cb6ea83a43bfdf338d
            • Instruction Fuzzy Hash: F2116D22B1D68362FA68A771655547962565F887F0F744738E83EC77CFEE6CB4018300
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: AddressFreeHandleLibraryModuleProc
            • String ID: CorExitProcess$mscoree.dll
            • API String ID: 4061214504-1276376045
            • Opcode ID: 69936be9a3c9092073ccdecace5a334f9bb4337f6d94747144cad9e03172cb9f
            • Instruction ID: e74c6fd30bf521267bc80dfc3251c0751b8d060f2eb58b16e13639618f6eb69a
            • Opcode Fuzzy Hash: 69936be9a3c9092073ccdecace5a334f9bb4337f6d94747144cad9e03172cb9f
            • Instruction Fuzzy Hash: 10F0F667B29B02A5EB108B64E84837A6364FF497A0F640235C96EC63F9DF2DD048C710
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: CloseDeleteOpenValue
            • String ID: Console$IpDatespecial
            • API String ID: 849931509-1840232981
            • Opcode ID: 428edfecf080eeaca7e0c1c67ef556d191498152a1b600a56db6dc59e929ff35
            • Instruction ID: 9403e6a9110efdb562a63742bc70f369cbd1e52e39a17d7b34714102025f3e1c
            • Opcode Fuzzy Hash: 428edfecf080eeaca7e0c1c67ef556d191498152a1b600a56db6dc59e929ff35
            • Instruction Fuzzy Hash: 63F0F936608DC195E7208B18EC10BA97364EB8476AF100131C91D97B6DEF39D59A8B04
            APIs
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: AdjustPointer
            • String ID:
            • API String ID: 1740715915-0
            • Opcode ID: 95c273c5d9a602b1e514679a9057b242ded82a174dba946a287035d63dc3020a
            • Instruction ID: dd8957701c26a4f1d86f24f7092fe268f0fc574aa755ad7f6585b82f3c5b88f1
            • Opcode Fuzzy Hash: 95c273c5d9a602b1e514679a9057b242ded82a174dba946a287035d63dc3020a
            • Instruction Fuzzy Hash: 8FB1B423E0ABC6A5FA659F119450A396290EF54B84F258436DE8D8778FEFBCE481C740
            APIs
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: _set_statfp
            • String ID:
            • API String ID: 1156100317-0
            • Opcode ID: 3a9c703ea5aaac55ee3dcba71a43574e980d604707a0521e319b1fc91c9c8b59
            • Instruction ID: 54fcb516a57197737b2284ab6cfcb75a13d5cdb37a7f11bb4aca57ebc60988a1
            • Opcode Fuzzy Hash: 3a9c703ea5aaac55ee3dcba71a43574e980d604707a0521e319b1fc91c9c8b59
            • Instruction Fuzzy Hash: 34117723E9CA0B21F76411AAD79637551596F55370F780A34E6AEC63DFCEAC69404310
            APIs
            • FlsGetValue.KERNEL32(?,?,?,00007FF600AE3C9B,?,?,00000000,00007FF600AE3F36,?,?,?,?,?,00007FF600AE3EC2), ref: 00007FF600AEEF6F
            • FlsSetValue.KERNEL32(?,?,?,00007FF600AE3C9B,?,?,00000000,00007FF600AE3F36,?,?,?,?,?,00007FF600AE3EC2), ref: 00007FF600AEEF8E
            • FlsSetValue.KERNEL32(?,?,?,00007FF600AE3C9B,?,?,00000000,00007FF600AE3F36,?,?,?,?,?,00007FF600AE3EC2), ref: 00007FF600AEEFB6
            • FlsSetValue.KERNEL32(?,?,?,00007FF600AE3C9B,?,?,00000000,00007FF600AE3F36,?,?,?,?,?,00007FF600AE3EC2), ref: 00007FF600AEEFC7
            • FlsSetValue.KERNEL32(?,?,?,00007FF600AE3C9B,?,?,00000000,00007FF600AE3F36,?,?,?,?,?,00007FF600AE3EC2), ref: 00007FF600AEEFD8
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: Value
            • String ID:
            • API String ID: 3702945584-0
            • Opcode ID: 4047813a2c2501da88736eb8979464a470432fe091b6a2381c64cb1679d0dde5
            • Instruction ID: 1dafd10a0d9d5c581b481b278b35f555a46ddd90575ecbf139acf39efa71e40d
            • Opcode Fuzzy Hash: 4047813a2c2501da88736eb8979464a470432fe091b6a2381c64cb1679d0dde5
            • Instruction Fuzzy Hash: F3115E22F0968262FAA8E365A55157962456F843F0F745338E87EC67DFEE3CF4028300
            APIs
            • FlsGetValue.KERNEL32(?,?,?,?,?,?,?,00007FF600AF7113,?,?,?,00007FF600AEF444,?,?,?,00007FF600AE843F), ref: 00007FF600AEEDF5
            • FlsSetValue.KERNEL32(?,?,?,?,?,?,?,00007FF600AF7113,?,?,?,00007FF600AEF444,?,?,?,00007FF600AE843F), ref: 00007FF600AEEE14
            • FlsSetValue.KERNEL32(?,?,?,?,?,?,?,00007FF600AF7113,?,?,?,00007FF600AEF444,?,?,?,00007FF600AE843F), ref: 00007FF600AEEE3C
            • FlsSetValue.KERNEL32(?,?,?,?,?,?,?,00007FF600AF7113,?,?,?,00007FF600AEF444,?,?,?,00007FF600AE843F), ref: 00007FF600AEEE4D
            • FlsSetValue.KERNEL32(?,?,?,?,?,?,?,00007FF600AF7113,?,?,?,00007FF600AEF444,?,?,?,00007FF600AE843F), ref: 00007FF600AEEE5E
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: Value
            • String ID:
            • API String ID: 3702945584-0
            • Opcode ID: f4b63a2d358e16832ea89596edc1dbf90b4b2fd2f1616095919a36d422ba38cd
            • Instruction ID: 7c6008e12001cf80539cd741ed7711c0fbf3f98cc9c73a6dd59415d56e93b575
            • Opcode Fuzzy Hash: f4b63a2d358e16832ea89596edc1dbf90b4b2fd2f1616095919a36d422ba38cd
            • Instruction Fuzzy Hash: 53110C12E4928372FAA8A261585257912865F49370F781B38E93ECA3DFEE3CB4414341
            APIs
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: CriticalSection$EnterLeave
            • String ID:
            • API String ID: 3168844106-0
            • Opcode ID: 7d1c33e0fc199dc1a1b2b98ae86d416f77ce0655480dcc5f384a8a26f1c27f0c
            • Instruction ID: 97441bbd3d4e861781f65229014fcf2690a6b208d1c31e28ec9337ced628f52f
            • Opcode Fuzzy Hash: 7d1c33e0fc199dc1a1b2b98ae86d416f77ce0655480dcc5f384a8a26f1c27f0c
            • Instruction Fuzzy Hash: DE11DA32A2894297EB909B65F4943BA6360FF44759F951431EB8F86B59CF3CE4C6C700
            APIs
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: CriticalSection$Enter$DeleteGdiplusLeaveObjectShutdown
            • String ID:
            • API String ID: 1513102227-0
            • Opcode ID: cb3a45266a7c72afb3eef7b31d32061257325c5ad6beb33f20a6e81f88ef5b24
            • Instruction ID: 5d256b1de6bdd01e7efd196435db05dacac4706ede1665f5b3d14783b2e95049
            • Opcode Fuzzy Hash: cb3a45266a7c72afb3eef7b31d32061257325c5ad6beb33f20a6e81f88ef5b24
            • Instruction Fuzzy Hash: 2D115833505B4295EB008F69E84002973B8FF08FA9B284236D65D833AADF38D892C340
            APIs
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: CloseHandleObjectSingleThreadWait$CurrentErrorLastSleepSwitch
            • String ID:
            • API String ID: 1535946027-0
            • Opcode ID: 311de798c0593289d29e071e9f78a1d734eb52b4581ef33c1cbfd426072e5f36
            • Instruction ID: 235f2f20cbcb86d931c14258c5f041f6c29f8f30a171ea79cf3528e859dd41aa
            • Opcode Fuzzy Hash: 311de798c0593289d29e071e9f78a1d734eb52b4581ef33c1cbfd426072e5f36
            • Instruction Fuzzy Hash: A3F0F937A44A4596EB149F79E8541792324FF89F6AF284230DA2E873E9CF38D885C350
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: CallEncodePointerTranslator
            • String ID: MOC$RCC
            • API String ID: 3544855599-2084237596
            • Opcode ID: 85eb8fbd3e06a99c4afa559b4d80cf249f4e954e0195537aa802c98b0a840f84
            • Instruction ID: 2e7cd9c67bc8fc78f4a260f4d93923353124795c3f4d6e87b2012021cd0e8304
            • Opcode Fuzzy Hash: 85eb8fbd3e06a99c4afa559b4d80cf249f4e954e0195537aa802c98b0a840f84
            • Instruction Fuzzy Hash: 5B91A273A087959AE710DF65D8806ED77A0FB44788F204136EE8D97B5AEF38D195C700
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: CurrentImageNonwritableUnwind__except_validate_context_record
            • String ID: csm
            • API String ID: 2395640692-1018135373
            • Opcode ID: c305225e0e2b3a2203a822812f960376c115b044745f784688940b7b0a399dcc
            • Instruction ID: faedc05094ea298e99e13aebcdf3ae7525bd48ebbc0df0d751951f3f70f7f2d9
            • Opcode Fuzzy Hash: c305225e0e2b3a2203a822812f960376c115b044745f784688940b7b0a399dcc
            • Instruction Fuzzy Hash: 7F518E33A19642AEDB14CB15E444A7A7792EB44B88F248136EE4F8779EDF7DE841C700
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: Frame$EmptyHandler3::StateUnwind__except_validate_context_record
            • String ID: csm$csm
            • API String ID: 3896166516-3733052814
            • Opcode ID: 544592ab7251effa554c0990b2f03f08321f7b0f5e6baf8f1fc1d42750b8d711
            • Instruction ID: d08d17fe3502fea53a9a204c33c7edef949faa4c01e56b42797b2804d877e325
            • Opcode Fuzzy Hash: 544592ab7251effa554c0990b2f03f08321f7b0f5e6baf8f1fc1d42750b8d711
            • Instruction Fuzzy Hash: 73517133A082C2AAEB748F1194443A877A8FB55B94F244235DB9D87BDADF3CE590C701
            APIs
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: FileWrite$ConsoleErrorLastOutput
            • String ID:
            • API String ID: 2718003287-0
            • Opcode ID: b0a5a2f5e03aa4de9bb2610dcdd396f5b9cdbd820afb8483674e8d26cbad73da
            • Instruction ID: d071b3207b1458a2cd6170a0501ee1f9b1f9811bd18744fd7513edbaf988adfa
            • Opcode Fuzzy Hash: b0a5a2f5e03aa4de9bb2610dcdd396f5b9cdbd820afb8483674e8d26cbad73da
            • Instruction Fuzzy Hash: 7BD1CE73B18A819AE711CFA5D4402FC37BAFB54798B248236CE5D97B9ADE38D456C300
            APIs
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: Concurrency::cancel_current_task_invalid_parameter_noinfo_noreturn
            • String ID:
            • API String ID: 73155330-0
            • Opcode ID: 8fee3de5b3b2f0071dc3db66fd2bdfdcb24e79f59a02b604d58c203983c7a5df
            • Instruction ID: d69612731c8dbd17952db8fea987029d55afab17784a3ab096d5c3b28028f6ed
            • Opcode Fuzzy Hash: 8fee3de5b3b2f0071dc3db66fd2bdfdcb24e79f59a02b604d58c203983c7a5df
            • Instruction Fuzzy Hash: 0E919163B05A8265EE14DB66D4482BD7361BB08BE0F648632DF6E87BDADF7CD0518300
            APIs
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: _invalid_parameter_noinfo_noreturn
            • String ID:
            • API String ID: 3668304517-0
            • Opcode ID: 12821617f7a64de7d3cb37ac5f3ef33577a0d69585e7a9a316e27e8c0fa45f34
            • Instruction ID: ea9acbea3fa4aafdaa7aa17250ca1c8db4bb6a8c7168f62d459f11ea52cdf70a
            • Opcode Fuzzy Hash: 12821617f7a64de7d3cb37ac5f3ef33577a0d69585e7a9a316e27e8c0fa45f34
            • Instruction Fuzzy Hash: D7B16F63F18B5595EB048BA4D4447AC3372FB08798F605236DE6D67B9EEF78A481C340
            APIs
            • GetConsoleMode.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,00000000,00000000,00000000,00007FF600AFB36F), ref: 00007FF600AFB4A0
            • GetLastError.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,00000000,00000000,00000000,00007FF600AFB36F), ref: 00007FF600AFB52B
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: ConsoleErrorLastMode
            • String ID:
            • API String ID: 953036326-0
            • Opcode ID: c0b9c452233083e8ba344db7b85cdb6942af15e1945070f1535423c6b6b64ca2
            • Instruction ID: 29fc4b0f6b6a94170c15db499d8afd6ccee29295d2d8e30803e4f2a6ad4817f0
            • Opcode Fuzzy Hash: c0b9c452233083e8ba344db7b85cdb6942af15e1945070f1535423c6b6b64ca2
            • Instruction Fuzzy Hash: 9E91C363A68652A9F750CFA5D4802BD2BB8AB04B88F744139DE0ED7B9ADF3CD445C710
            APIs
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: _invalid_parameter_noinfo_noreturn$Concurrency::cancel_current_task
            • String ID:
            • API String ID: 3936042273-0
            • Opcode ID: 62b4c31c7c5400ea0ae5361b2cdd4f0e0c1c2a04a61e177b842a2efb8ef1d907
            • Instruction ID: f5f0c651f1162ef5976d5ee5c0ecb3842b7a0e1c03122d73724f605919739917
            • Opcode Fuzzy Hash: 62b4c31c7c5400ea0ae5361b2cdd4f0e0c1c2a04a61e177b842a2efb8ef1d907
            • Instruction Fuzzy Hash: 7A719D63B14B85A5EA04DB25940836C7361EB89FE0F658632DEAD47BDADE7CE580C300
            APIs
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: Process32$CreateFirstNextSnapshotToolhelp32_invalid_parameter_noinfo_invalid_parameter_noinfo_noreturn
            • String ID:
            • API String ID: 4260596558-0
            • Opcode ID: 8f25ca90b910a531810e7f5bf128020c3683582cb0693416a2ac57c12dcd4de1
            • Instruction ID: 30c8581761e48c4295c252581a9771fa79ebab2e945d343da906eedaac5821fc
            • Opcode Fuzzy Hash: 8f25ca90b910a531810e7f5bf128020c3683582cb0693416a2ac57c12dcd4de1
            • Instruction Fuzzy Hash: 4E71D463B08682A5EA209B25D4446BD7362FB85BA0F658732DA7E877DEDF3CD540C700
            APIs
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: Virtual$AllocInfoProtectQuerySystem
            • String ID:
            • API String ID: 3562403962-0
            • Opcode ID: de052ff2da3a860ebe00b2b1188a3b3a24b5d5626fd4b16e4c5629aca21b164b
            • Instruction ID: 49f3f093b4cba2bcba4ed1464f60d9d89064e73980a0e69977c7e3f1a65ab476
            • Opcode Fuzzy Hash: de052ff2da3a860ebe00b2b1188a3b3a24b5d5626fd4b16e4c5629aca21b164b
            • Instruction Fuzzy Hash: C6312A32714A85AEDB20CF31D8547E933A5FB48788F944136EA4D8BB59DF38E645C700
            APIs
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: CriticalSection$Leave$EnterEvent
            • String ID:
            • API String ID: 3394196147-0
            • Opcode ID: 401af7361c6d18c862ea4f071fb6758f38da9ad67756e4e78bac1cd16ae14490
            • Instruction ID: d19a26356ae7fb1331a2a46868343c85f0bdd19acb7631453c70d630d57d7213
            • Opcode Fuzzy Hash: 401af7361c6d18c862ea4f071fb6758f38da9ad67756e4e78bac1cd16ae14490
            • Instruction Fuzzy Hash: 01212B32704B8197D748CF2AE5806ADB3A4FB48B94F544535DB6D83766DF38E4A1C740
            APIs
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: CurrentTime$CounterFilePerformanceProcessQuerySystemThread
            • String ID:
            • API String ID: 2933794660-0
            • Opcode ID: e05f7aef3380f0f9b3312b24ce1aa7c1f593c40dbd43f636e11a9c4c637e2614
            • Instruction ID: 21ad170883e6e7fe5a0bbd535a664240723c4271b7056684694b4352f91a2376
            • Opcode Fuzzy Hash: e05f7aef3380f0f9b3312b24ce1aa7c1f593c40dbd43f636e11a9c4c637e2614
            • Instruction Fuzzy Hash: 10115236B55F059AEB00DFA0E8542B833A4FB59758F540E31DE6D867A8DF7CD1548340
            APIs
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: ObjectSingleWait$Sleep
            • String ID:
            • API String ID: 2961732021-0
            • Opcode ID: 83ddd93f6670c03bec4b7f128343a3e6a6daf1263786cfff0f95db90d503808b
            • Instruction ID: 6cc7df2e1a735fe94ee275ef41c31313fa6536202546e6e8cd4764e54cc8730a
            • Opcode Fuzzy Hash: 83ddd93f6670c03bec4b7f128343a3e6a6daf1263786cfff0f95db90d503808b
            • Instruction Fuzzy Hash: F5F0FE72704A449AD7509F79D8542393365EF89B3AF654330CA2D873E9CF38C485C354
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: __except_validate_context_record
            • String ID: csm$csm
            • API String ID: 1467352782-3733052814
            • Opcode ID: f15189d2199330c0f402dae8ecdfa2ca81426a1eff024833c44a8ddbe4b12987
            • Instruction ID: bebdb5f1e8b5052ce902bf395223d7129cdc988a467a7f182c8cf8d70bcb55d6
            • Opcode Fuzzy Hash: f15189d2199330c0f402dae8ecdfa2ca81426a1eff024833c44a8ddbe4b12987
            • Instruction Fuzzy Hash: 4B718D73A086C296DB608F2591507797BA4FB04B85F248136DE8D87B8AEF3CD591CB00
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: EncodePointer
            • String ID: MOC$RCC
            • API String ID: 2118026453-2084237596
            • Opcode ID: ff6c3586205ef54b92cc1381aa76c713ce5aef96bda724e5a14e442f6a8185ef
            • Instruction ID: cedda488fbdd2d426ece623c46078f4337a923b072e7f3274a43a4e8e9e96498
            • Opcode Fuzzy Hash: ff6c3586205ef54b92cc1381aa76c713ce5aef96bda724e5a14e442f6a8185ef
            • Instruction Fuzzy Hash: EC61AF33909BC595E7609B15E4407BAB7A0FB85B94F144235EB9D83B9AEF7CE190CB00
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: _get_daylight$_invalid_parameter_noinfo
            • String ID: ?
            • API String ID: 1286766494-1684325040
            • Opcode ID: 73dd6a1d9a5ad4992f3991f8c36a8220d63358c9d054768064d2836bf5e58140
            • Instruction ID: a650964f225e0a4c5ade280e3420e7c0b97ee8c425e87d027e4a263602654c3c
            • Opcode Fuzzy Hash: 73dd6a1d9a5ad4992f3991f8c36a8220d63358c9d054768064d2836bf5e58140
            • Instruction Fuzzy Hash: 68410A23A48382A5FB6097A5D4013BA6658EB907A4F244235EF5C86BDFDF3CD441C700
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: CreateFrameInfo__except_validate_context_record
            • String ID: csm
            • API String ID: 2558813199-1018135373
            • Opcode ID: f28967bb51a8388d528e36e8d1b9cbe39d4a27893e421944e70fc0d8e7df8c72
            • Instruction ID: 4fc942b3ee9e663d34be5389a5ae5e9e24b2e4d044316299db91f22acf716f9e
            • Opcode Fuzzy Hash: f28967bb51a8388d528e36e8d1b9cbe39d4a27893e421944e70fc0d8e7df8c72
            • Instruction Fuzzy Hash: C3513F776187819AD620AF25E14166E77A4FB88B90F241135EF8D87B5BEF3CE491CB00
            APIs
            • _invalid_parameter_noinfo.LIBCMT ref: 00007FF600AEC256
              • Part of subcall function 00007FF600AEE95C: RtlFreeHeap.NTDLL(?,?,?,00007FF600AF6862,?,?,?,00007FF600AF6BDF,?,?,00000000,00007FF600AF7025,?,?,?,00007FF600AF6F57), ref: 00007FF600AEE972
              • Part of subcall function 00007FF600AEE95C: GetLastError.KERNEL32(?,?,?,00007FF600AF6862,?,?,?,00007FF600AF6BDF,?,?,00000000,00007FF600AF7025,?,?,?,00007FF600AF6F57), ref: 00007FF600AEE97C
            • GetModuleFileNameW.KERNEL32(?,?,?,?,?,00007FF600ADE051), ref: 00007FF600AEC274
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: ErrorFileFreeHeapLastModuleName_invalid_parameter_noinfo
            • String ID: C:\Users\user\Desktop\0DrqlQ4JfZ.exe
            • API String ID: 3580290477-192714766
            • Opcode ID: aee35bfe6285ca872dc023e0e85ec8bac6debb86297f70b490d45f268cf6f652
            • Instruction ID: 66d53f1e342ff3541ffde626bb8e36af9f37376ee54e1b0d1c4dda557ffe4d0d
            • Opcode Fuzzy Hash: aee35bfe6285ca872dc023e0e85ec8bac6debb86297f70b490d45f268cf6f652
            • Instruction Fuzzy Hash: 7B419037A08B92A5EB54EF25A4501FDA7A4FF45790F654035EA4E87B8EEF3DE4428300
            APIs
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: ErrorFileLastWrite
            • String ID: U
            • API String ID: 442123175-4171548499
            • Opcode ID: 82c14a47abd65dfd2f18e3d0d2973b2ccc07122a063a358567b3cbc0c6ba3651
            • Instruction ID: 50a30e2047cd295bbf1b9da6ac9275d9e7eb4a75240dc7cb14f72c98864775cf
            • Opcode Fuzzy Hash: 82c14a47abd65dfd2f18e3d0d2973b2ccc07122a063a358567b3cbc0c6ba3651
            • Instruction Fuzzy Hash: 3E419F23B28A81A5EB208F65E8543BA67A5FB88794F614131EE4EC7799DF3CD401C750
            APIs
            • RtlPcToFileHeader.KERNEL32(?,?,?,?,?,?,?,?,?,00007FF600AC1111), ref: 00007FF600AE0340
            • RaiseException.KERNEL32(?,?,?,?,?,?,?,?,?,00007FF600AC1111), ref: 00007FF600AE0381
            Strings
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: ExceptionFileHeaderRaise
            • String ID: csm
            • API String ID: 2573137834-1018135373
            • Opcode ID: 4e14dd832fb4824443fa8c0aec862097db35212d867c479028c393dfe5930aef
            • Instruction ID: e8740008868c4fafb06522caba04bdeaff846b24c01fd9de4a6b1fd0c416d1a7
            • Opcode Fuzzy Hash: 4e14dd832fb4824443fa8c0aec862097db35212d867c479028c393dfe5930aef
            • Instruction Fuzzy Hash: A1113D33618B8192EB618F25F44426977E5FB88B84F684230EE8C8B769EF7CD551CB00
            APIs
            Memory Dump Source
            • Source File: 00000000.00000002.3974884221.00007FF600AC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF600AC0000, based on PE: true
            • Associated: 00000000.00000002.3974827166.00007FF600AC0000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974924261.00007FF600AFF000.00000002.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974951041.00007FF600B15000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974974715.00007FF600B18000.00000008.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3974997931.00007FF600B1C000.00000004.00000001.01000000.00000003.sdmpDownload File
            • Associated: 00000000.00000002.3975025113.00007FF600B20000.00000002.00000001.01000000.00000003.sdmpDownload File
            Joe Sandbox IDA Plugin
            • Snapshot File: hcaresult_0_2_7ff600ac0000_0DrqlQ4JfZ.jbxd
            Similarity
            • API ID: ErrorLastRead
            • String ID:
            • API String ID: 4100373531-0
            • Opcode ID: 82ac0250d1ecd3177f83757e94cf9be5bc81ee4aab1a059e0fd8dc4cfb57a079
            • Instruction ID: 7255bfd767804ba9ff5431f6c812553155c9dfad9134c53d0adbb4876c8435b7
            • Opcode Fuzzy Hash: 82ac0250d1ecd3177f83757e94cf9be5bc81ee4aab1a059e0fd8dc4cfb57a079
            • Instruction Fuzzy Hash: F0414B63B09B41A6EB108B16E44027973A0FB58B91F194436CF4E87B99DF3CE4A0C311